EARNY · TRUST & TRANSPARENCY
Privacy Policy
How ShiftScript by Earny handles account details, meeting content, Google access and your privacy choices.
Last updated:
1. Who operates ShiftScript
ShiftScript is a meeting and task management service operated by Earny in South Africa. This policy applies to shiftscript.earny.co.za. For privacy questions, access requests, corrections or deletion requests, contact meetings@earny.co.za.
Earny manages the service and account information. Your organisation or workspace owner may also determine why meeting information is collected and which colleagues can access it. Contact both your workspace owner and Earny where a request concerns a shared meeting.
2. Information we collect
- Accounts and profiles: email address, account identifier, name, optional profile picture and nicknames, email verification status, and notification preferences. Firebase Authentication manages account credentials.
- Workspace content: membership and roles, invitation email addresses, projects, agendas, drafts, transcripts, speaker labels, source references, summaries, decisions, follow-ups, tasks, owners, deadlines, schedules, checklists, notes and change history.
- Audio: recordings you choose to upload or record for transcription. The current app sends audio to Gemini during the request and does not save the original recording in its meeting database; the resulting transcript can be saved.
- Connected Google data: accessible meeting records and references to their generated transcripts or notes; the text of the source you select; document identifiers, titles and source links; connection status and OAuth tokens.
- Service records: email recipient addresses and send status, invitation and reminder records, quota counters and technical request information. Hosting and service providers may keep operational logs such as IP addresses, timestamps and error details.
Account details are needed to use authenticated workspaces. Google connection, audio upload, profile photos and daily reminder emails are optional. Without Google access, you can still use permitted transcript input; without AI processing, no live AI summary is generated.
3. Why we use information
We use information to authenticate users, provide shared workspaces, transcribe audio, generate meeting summaries and proposed actions, let users review tasks, track progress, prepare Calendar event drafts, deliver requested emails and reminders, prevent abuse and respond to support requests. We do not sell meeting content or use it for advertising. Earny does not train its own general-purpose AI models on your meetings.
We process information to provide the service you request, on your instructions or consent where relevant, and for legitimate service administration and applicable legal obligations. Workspace owners must have an appropriate basis and any required participant permission before recording, importing or sharing a meeting.
4. Google Meet and Google Docs access
Connecting Google is a separate, optional permission flow.
ShiftScript requests meetings.space.readonly to
retrieve accessible meeting information and generated artifact
references, and documents.readonly to read the notes
or transcript document you select. The Docs permission covers
documents you can access; ShiftScript uses it to fetch the
selected meeting source rather than to scan your documents in
bulk.
The connection does not join calls, record Google Meet automatically, or guarantee that a meeting has a transcript. Google account permissions and meeting eligibility determine which sources are available. ShiftScript lets you preview a selected source before processing it. Processing sends that text and relevant meeting metadata to Gemini, then stores the source text, references and generated results in the selected workspace.
Google access and refresh tokens are stored separately from shared workspace data, encrypted on the server, and are not exposed to workspace members. Import previews become unavailable after 15 minutes. Use Meet → Disconnect to clear ShiftScript's saved connection and previews. You can also revoke access through your Google account connections. Disconnecting does not delete already imported meetings, remove Google documents or recall emails.
The current Calendar feature opens a prefilled Google Calendar event draft that you choose to save. It sends event details to Google when you open the draft; it does not request Calendar API write access or automatically keep events synchronised.
5. AI processing and provider data use
When you request analysis, selected transcript or notes text and meeting metadata are sent to Google's Gemini API. Audio transcription sends the recording to Gemini. AI-generated summaries and proposed tasks return to ShiftScript for review. Names and personal details in the source may be included in that processing.
The treatment differs for the Gemini API paid service: Google states that prompts and responses are not used to improve its products, although processing and limited retention for abuse monitoring can still apply. A Google AI Pro consumer subscription does not by itself establish the API project's data handling. Contact meetings@earny.co.za to confirm the deployed processing arrangement before submitting real private meetings. See Gemini API terms and Google's privacy policy.
AI can misidentify speakers or miss commitments. Review summaries, owners and deadlines before approving tasks or sending a recap. Processing is not a substitute for professional advice.
7. Storage, security and retention
The hosted deployment uses Firebase for account and workspace data. Local development can instead store data on the developer's computer. Account access, workspace membership checks and server-side integration token encryption help protect information; no system is completely risk-free.
Meeting and task records remain until removed through an available control or an authorised deletion request. The current app does not apply an automatic expiry to every meeting or account. Activity history and operational records have feature-specific limits. Provider logs, backups and previously delivered emails follow their respective retention arrangements and cannot all be erased instantly by ShiftScript.
Necessary browser storage remembers sign-in state, your selected workspace and recoverable meeting drafts. A shared device may retain draft text until you discard it or clear its site data. The current app does not initialise Google Analytics or include advertising trackers. Google authentication uses a short-lived security cookie during the connection flow.
8. Your choices and privacy requests
You can edit your profile, disable daily reminder emails, disconnect Google, and use available task and draft controls. To request access to personal information, correction, objection to processing, account closure or deletion, email meetings@earny.co.za. See our Data Deletion page for the request process.
We may verify identity and authority before disclosing or deleting information, especially when shared workspace records include other people's information. We will explain any legal or operational reason a request cannot be fully completed and respond within the applicable requirements. You may also raise a privacy concern with South Africa's Information Regulator.
9. Age and policy changes
ShiftScript is intended for professional use by adults aged 18 or older. Do not upload children's personal information or use the service on behalf of children.
We will update the date on this page when practices change. Material changes to how Google data is used require appropriate notice and any renewed consent before that new use. Contact meetings@earny.co.za with any questions about this policy.