Your information
in Arlen.
Arlen is a Mac meeting assistant with hosted account, scheduling and meeting services. This policy explains what Arlen processes and keeps during beta.
Audio is saved during beta. Arlen retains incoming meeting audio and assistant audio for replay and debugging, along with transcripts, outputs and meeting context. There is currently no automatic expiry. Retention and user controls will be revisited before broader launch.
Information we use
Accounts and setup
We use your name, email, verification status, optional account image, provider account identifiers and workspace membership for sign-in and access control. Setup includes your role, company and preferences. Login records can include your IP address and user agent.
Meetings and included context
Arlen processes meeting links, participant and speaker information, conversations, chat, transcripts and any context you include. It generates answers and summaries, and keeps source results, feedback and diagnostic events. Shared-screen images can be processed when available in a hosted call.
Customer Notion and Circleback connections retrieve information through your permissions using read-only tools. Retrieved results and their source references can become part of a meeting's saved evidence and AI context.
Google Calendar is a separate connection
Google sign-in does not itself connect your calendar. With your separate permission, Arlen reads visible calendars and events to display upcoming meetings and follow changes or cancellations. Arlen schedules meetings you select individually or allow through your meeting defaults. You can turn off automatic joining or exclude individual meetings.
Arlen stores calendar and event identifiers, titles, times, Google Meet links, recurring-event identifiers, your response and organizer status, selections and synchronization state. The calendar importer does not save event descriptions, full attendee lists or attachments. Its read-only permissions do not allow Arlen to edit Google events.
Hosted scheduling continues while your Mac is asleep. In-person microphone participation requires your Mac to remain connected.
Storage and access
Your Mac stores its sign-in token in macOS Keychain. Account-scoped settings, included context and meeting/review records are also kept in local application-support files. Hosted records are stored in PlanetScale PostgreSQL and Railway meeting storage; Vercel hosts the account service and website.
The application encrypts Google Calendar, Notion and Circleback grant credentials before database storage. Private meeting and connection access is checked against the initiating account and its workspace membership. Workspace membership alone does not expose another member's private meetings or connections.
Authorized operators can access hosted systems. Private meeting records are not end-to-end encrypted with keys only you control.
Services involved in providing Arlen
The recipients depend on the feature you use. This table does not mean that every service receives every category of information.
| Service | Role |
|---|---|
| Account login and the optional calendar connection. | |
| Resend | Delivery of sign-in email codes. |
| OpenAI | Live audio interaction and model tasks using meeting context. |
| Anthropic | Meeting reasoning and summarization. Shared-screen images may be included in supplied context. |
| Recall.ai / Deepgram | Hosted Google Meet participation, transcription and relevant meeting media and events. |
| Notion / Circleback | Search and read operations through your authorized connections. |
| Exa | Web searches used to answer meeting questions. Search queries may include contextual terms. |
| Vercel / Railway / PlanetScale | Website, account and meeting hosting, data storage and operational backups. |
Arlen sends information to AI services to generate responses and perform the meeting features described above. Provider data practices depend on the service and its applicable terms; the provider links above explain their policies.
What we keep during beta
Raw meeting audio is retained for replay and debugging. Transcripts, assistant outputs, saved context and meeting evidence are retained too. There is no automatic deletion schedule for these records during beta.
Backups and retained migration copies can contain earlier data. Existing recordings are retained. We will revisit retention and user controls before broader launch.
Your current controls
You can sign out, disconnect a provider, deselect a scheduled occurrence and end a meeting. You can also revoke provider access from that provider's account settings.
- Disconnecting Notion or Circleback removes Arlen's saved grant and stops subsequent retrieval. Arlen attempts Notion-side revocation; Circleback currently offers no advertised revocation endpoint in its OAuth setup.
- Disconnecting Google Calendar removes Arlen's stored calendar grant and disables selected occurrences. Cached event metadata remains. It does not revoke the shared Google sign-in client's entire authorization.
- Disconnecting or signing out does not delete past meetings, recordings or retrieved evidence. Removing context on your Mac does not erase copies already saved with a meeting.
Self-service account and meeting deletion are not currently implemented. Privacy and deletion requests can be directed to david@youlearn.ai for individual handling. This policy does not promise an automatic deletion deadline or immediate removal from backups.
Google API data use
Arlen will handle information received through Google APIs according to the Google API Services User Data Policy, including its Limited Use requirements.
This limits Google API data use to providing or improving the disclosed user-facing features and permits transfers only under the policy’s conditions. Human access to covered data must also meet those conditions, such as your affirmative agreement to inspect specific data or a necessary security investigation. Keeping beta recordings does not grant unrestricted human access to Google API data.
Questions or requests
Contact YouLearn Inc. at david@youlearn.ai for privacy questions, access requests or deletion requests.