Privacy Policy

Last updated: July 14, 2026

Pondros ("Pondros," "we," "us") is a product of Herd. This policy explains what we collect when you use Pondros, how we use it, and the choices you have. We've tried to keep it plain.

What we collect

  • Your email address and basic account identifiers, so we can sign you in and connect the app to your workspace.
  • Meeting audio you choose to transcribe. When you start transcription, microphone and (optionally) system audio are captured, converted to text, and the audio is discarded — we never store a recording.
  • Transcripts, notes, and tasks generated from your meetings, plus the workspace and roster information you provide.
  • Google Calendar data — only if you connect it. If you choose to connect Google Calendar, we read your upcoming events (titles, start and end times, attendee email addresses, and any meeting link) so Pondros can prepare you before a meeting and remind you when one is about to start. Access is read-only — we never create, edit, or delete anything on your calendar.
  • OAuth tokens for any integration you connect, required to keep it alive between sessions. Tokens are stored encrypted on our backend and are never placed on your device or shared with third parties.
  • Usage analytics: basic page-view counts, request latency, and error reports to keep the service running.

How we use your data

  • To provide transcription, notes, tasks, and your board.
  • To show your upcoming meetings and prepare pre-meeting briefs when you connect Google Calendar.
  • To operate, secure, debug, and improve the service.
  • To comply with legal obligations.

We do not sell your personal information, we do not share it with advertisers, and we do not use your meeting content to train our own models.

Service providers (sub-processors)

We share the minimum data necessary with vendors that help us run the product. Each is bound by its own data-protection terms:

  • Deepgram — converts meeting audio to text (speech-to-text).
  • Anthropic — turns transcripts and notes into structured tasks and summaries (AI processing). Anthropic does not train on the content of API requests.
  • Fly.io and Supabase — host our application backend and database (US region).
  • Resend — sends our transactional and update emails.

Google Calendar data & Limited Use

Connecting Google Calendar is optional and read-only. When you connect it, Pondros receives an OAuth token that we store encrypted on our backend (never shared with third parties and never placed on your device) and use only to read your upcoming events for your pre-meeting brief and meeting reminders. You can disconnect at any time from the app's settings, which deletes the stored token and revokes our access.

Pondros's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, we do not use Google Calendar data for advertising, we do not sell it, we do not use it to develop, improve, or train AI or other models, and no human reads it except where needed for security, to comply with the law, or to support you at your explicit request.

Where your data lives

Data is stored in a PostgreSQL database hosted on Supabase (US region), and the application runs on Fly.io (US). We use encryption in transit, and OAuth tokens are stored encrypted at rest.

Transcription & consent

You are responsible for complying with the recording and consent laws that apply to you. Some jurisdictions require that everyone in a conversation consents before their audio is captured. Please obtain consent where required before transcribing a meeting.

Your rights

  • Access: request a copy of your workspace data anytime via support.
  • Correction: edit or delete records directly through the app.
  • Deletion: ask us to wipe your account; we'll delete it within 30 days, except backup retention up to 90 days.
  • Disconnection: revoke any third-party integration from Settings at any time. Tokens are deleted from our database on disconnect.

Data retention & security

We keep personal data only as long as needed to provide the service or as required by law, then delete or anonymize it. We use encryption in transit and encrypt OAuth tokens at rest.

Children

Pondros is not intended for anyone under 16.

Changes

We may update this policy as the product evolves. Material changes will be reflected by the "Last updated" date above and notified in-app.

Contact

Questions, data requests, or deletion: hey@pondros.com.

See also: Terms of Service