Harlyn joins video meetings you invite it to (or that appear on a calendar you connect), transcribes them, answers questions, captures action items and commitments, and sends you recaps. It only joins meetings you direct it to; it appears as a named, visible participant.
Meeting content. Audio, transcripts, and recordings of meetings Harlyn attends, processed through Recall.ai and stored so you can review summaries, transcripts, and playback.
Calendar data. If you connect Google Calendar or Outlook, we read your upcoming events (read-only) to schedule Harlyn. The OAuth refresh token is held by Recall.ai for syncing; we store only the resulting calendar id and your calendar email address.
Connected tools. Tokens you provide for tools like HubSpot, Linear, Asana, Jira, Slack, and others are encrypted at rest and used only to perform the actions you ask for (looking up CRM records, creating tasks, delivering recaps).
Account data. Your name and email, via Supabase authentication.
Solely to provide the product: transcription, in-meeting answers, recaps, task creation, and the dashboards you see. AI processing uses Anthropic and xAI models under their API terms. We do not sell your data or use it for advertising.
Harlyn's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Calendar data is used only to list your upcoming meetings, schedule Harlyn to join them, and prepare your pre-meeting briefings — never for advertising, never sold, and never used to train AI models.
We never sell your data. We share it only with the service providers (data processors) that run Harlyn, each bound by data-processing terms, and only as needed to provide the product:
Recall.ai — meeting-bot and calendar-sync infrastructure. Holds your calendar OAuth
token and performs the calendar sync; processes meeting audio, transcripts, and recordings.
Supabase — our database and authentication provider. Stores your account, meeting records,
your calendar email address, and calendar id.
Railway — application hosting, where our servers run.
Anthropic and xAI — AI model providers, under their API terms. Process meeting transcripts
and, for briefings, calendar event details (title, time, attendees) solely to generate your
summaries, answers, and briefings.
Resend — email delivery, if you have email recaps on.
Slack and your connected tools (HubSpot, Salesforce, Linear, and similar) — receive only
what you direct there: recaps to your own workspace, and the specific actions you approve.
Beyond these providers, we disclose data only if required by law, or at your explicit direction (for example, a share link you create). Google user data specifically (your calendar events and calendar email) is shared only with Recall.ai, Supabase, Railway, and — for briefing generation — Anthropic and xAI, as described above; it is never shared with advertisers or data brokers.
Encryption in transit. All connections — your browser to Harlyn, and Harlyn to Google,
Recall.ai, and every connected tool — use TLS (HTTPS).
Encryption at rest. OAuth tokens and connected-tool credentials are encrypted at rest with
symmetric encryption; the encryption key lives in server configuration, separate from the
database that stores the encrypted values.
Data minimization. We request read-only calendar access, and our servers store only your
calendar id and calendar email — the Google OAuth refresh token is held by Recall.ai for syncing,
not stored on our servers.
Access controls. The dashboard requires authentication, and each account can see only its
own meetings and connections. Share links are unlisted, read-only, and signed.
Revocation and deletion. Disconnecting a tool or calendar deletes its token immediately.
You can also revoke Harlyn's access from your
Google account permissions at any time,
and request deletion of your data at harlyn@harlyn.ai.
Meeting data is visible to the account that dispatched Harlyn and to other Harlyn users the meeting served. Share links you create are read-only and unlisted. Data is retained until you delete it or ask us to; disconnecting a tool removes its token immediately.
Questions or deletion requests: harlyn@harlyn.ai.