Overview
Reline is an AI note-taking product. We record audio on your device, transcribe it, generate summaries with large language models, and store the result so you can search, share, and collaborate on it.
This policy describes what we collect, why we collect it, who has access, and how to remove it. We've kept it short on purpose. If something is unclear, email privacy@reline.so.
Who is responsible for what. Reline AI, Inc. ("Reline") is the independent data controller for your account, billing, marketing-communication, security and product-telemetry data. For workspace content (notes, recordings, transcripts, summaries and the personal data of the people who appear in them) your organisation, or you on a personal plan, is the controller, and Reline processes that content only on your instructions as a processor under our Data Processing Addendum. If you took part in a meeting that someone else recorded with Reline, read the notice for meeting participants.
You can reach our privacy team at privacy@reline.so; our registered postal address is available on request.
What we collect
Account data. Name, email, profile image, and the identifier your sign-in provider assigns to you (Google, Microsoft Entra ID, or Apple, which may also give us a relay email address). If you sign in with email, we store a salted hash of your password (never the password itself) and the short-lived, single-use codes behind magic links and verification emails.
Workspace content. Notes, transcripts, recordings, summaries, action items, Lenses, chat threads and other AI outputs, uploaded files, and the version history of each note, whether you created them or they were shared with you.
Speaker events. If you install the browser extension, the participant display names and "who is speaking" events it reads from Google Meet, Microsoft Teams or Zoom. Raw events are kept for 24 hours and then deleted; only the resulting speaker labels in your transcript remain.
Calendar metadata. If you connect Google or Microsoft, we receive each event's title, description, start and end time, all-day flag, location, attendee list (email, name, and RSVP status), organizer, conference/meeting link, and recurring-series identifier — used to show your meetings, attach notes to them, and build your private contacts directory. You can switch the contacts derivation off in Settings → Calendar. See the Google API Services section for the full Google Calendar disclosure.
Integration credentials. Encrypted OAuth tokens and the identifiers needed to talk to services you connect (Slack, Notion, Linear), the signing secrets of outbound webhooks and Zapier connections, API keys you create, and the authorisations you grant to MCP clients. See Integrations you connect.
Billing data. Your plan, seat count, invoices and the customer identifier of our merchant of record. Card numbers are entered directly with Lemon Squeezy and never reach our servers.
First-touch attribution. When you first land on our website, the campaign parameters in the URL (utm tags, gclid, li_fat_id) and the referring page are stored in your browser's localStorage. If you later create an account, that first-touch record is stamped onto it once so we know which channel brought you here. We rely on our legitimate interest in measuring our own marketing for this; the record is deleted with your account and you can object at any time by emailing privacy@reline.so.
Feedback and support. Messages you send through Get help or the feedback form, together with your email address and basic app diagnostics, are stored in our support intake and routed to an internal Slack channel that only Reline staff can read.
Operational telemetry. Crash reports and product-usage metrics — which features are used and where errors happen — used for capacity planning and bug-fixing. When you are signed in and have consented, these events are associated with your account (your user ID, email, and name) so we can support you and understand real usage; you can opt out at any time. Our product-usage events do not contain note, transcript, or recording content. If you consent to analytics, session recordings may additionally capture your on-screen activity — including note and transcript content visible while you use Reline — to help us reproduce and fix issues; password fields are always masked and we do not record network payloads. You can decline or withdraw consent at any time. See our cookie policy for the specifics.
Security and server logs. Sign-in and sign-out events (provider and platform, never your IP address), request logs and error traces needed to run and secure the service. Logs are pruned after 90 days.
How we use it
- To provide the product (record, transcribe, summarize, search, sync, share).
- To enforce per-plan quotas (free plan: 1 hour per note, 10 hours per user per month).
- To investigate bugs, abuse, and security incidents.
- To process payments and manage your subscription.
- To send you onboarding tips and product news, which you can stop at any time (see Marketing communications).
- To measure which marketing channels bring people to Reline (first-touch attribution).
- With your consent, to measure product usage so we can improve Reline.
Legal bases (GDPR Art. 6). Where the GDPR applies, we rely on: performance of a contract (Art. 6(1)(b)) to deliver the service you sign up for, including recording, transcription, summarization, sync, and billing; our legitimate interests (Art. 6(1)(f)) in keeping the service secure, preventing abuse, fixing bugs, measuring our own marketing, and telling our users about the product they use, balanced against your rights; your consent (Art. 6(1)(a)) for optional product analytics and any non-essential cookies, which you can withdraw at any time; and compliance with a legal obligation (Art. 6(1)(c)) where the law requires us to retain or disclose data.
What we never do. We do not sell your data. We do not use your audio, transcripts or notes to train AI models, and the providers we use are bound by API terms that prohibit training on your content. Other than the sub-processors that operate Reline (listed below), the integrations you connect yourself, and, where you consent, the session-recording analytics described above, we do not share workspace content with anyone outside your workspace, except under your explicit instruction or legally required disclosure.
Marketing communications
When you create an account we tell you, at sign-up, that we will send a short series of onboarding tips and occasional product news to the address you registered with. We send these on the basis of our legitimate interest in helping new users get value from the product they signed up for, and we never send them to people who have not created an account.
Your right to object. Every one of these emails has a one-click unsubscribe link, and you can switch product emails off in Settings → Notifications. Either action takes effect immediately and is an objection under GDPR Art. 21 that we honour without asking why. Transactional messages that the service needs to send (sign-in links, invitations you accept, billing receipts, security notices) are not affected.
Google API Services
If you connect a Google account, Reline requests three read-only scopes: the Google Calendar events scope (https://www.googleapis.com/auth/calendar.events.readonly), to read events from your primary calendar, plus userinfo.email and userinfo.profile, to identify your account at sign-in. Using the calendar scope, Reline reads metadata from your primary calendar only: each event's title, description, start and end time, all-day flag, status, location, conference/meeting link (Zoom, Google Meet, or Microsoft Teams), the organizer (name and email), the attendee list (each attendee's email, display name, and RSVP response status), and the recurring-series identifier. We read only your primary calendar and never create, modify, delete, or share calendar events.
We use this data only to (1) display your upcoming meetings inside Reline, (2) attach notes and transcripts to the correct meeting, (3) surface attendee context, and (4) build a private directory of the contacts and companies you meet with — their name, email, and the company inferred from their email domain, plus how often and when you last met — so you can find and search related notes by person or company. These derived contact and company records are visible only to you, and you can turn the derivation off in Settings → Calendar.
Calendar metadata is stored in our managed database (Convex), which encrypts data at rest, and is transmitted only over TLS 1.2 or higher; the OAuth tokens that connect your account are additionally encrypted by Reline using AES-256-GCM. We never sell Google user data, never use it for advertising, and never use it to train or improve any AI or machine-learning model — neither our own nor any third party's. When you use Reline's AI features (such as asking questions about your notes, or preparing for an upcoming meeting), the contact and company labels derived from your calendar, including attendee email addresses, may be passed to our model providers solely to generate the answer you requested. Those providers process it only to return your result; under their API terms they do not use it to train models, and retention is limited to what each provider's policy specifies. No Reline employee accesses your Google data except where you ask us to (for example, a support request), where strictly necessary for security, or where required by law.
Reline keeps only a rolling window of your calendar — roughly the past few hours through the next 30 days — and a daily job automatically deletes any synced event more than 7 days past. You can disconnect at any time from Settings → Calendar in Reline. Disconnecting revokes Reline's access with Google, deletes the stored access and refresh tokens, and purges your cached calendar events together with the contacts and companies derived from them. You can also remove Reline's access directly from your Google Account permissions.
Reline's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Slack integration
Connecting Slack is optional. If you connect a Slack workspace (from Settings → Integrations), Reline uses Slack's standard OAuth flow and requests four bot scopes: channels:read and groups:read, to list the public and private channels you can post to; and chat:write and chat:write.public, to post the summaries you choose to send. Reline does not request access to your Slack message history and never reads your Slack messages.
What we receive and store. From Slack we receive and store — encrypted — an OAuth access token and your Slack workspace (team) ID, so Reline can post on your behalf. When you set a default Slack channel for a workspace or a folder, we store that channel's ID so future pushes can default to it. The list of your channels is fetched from Slack on demand each time you choose a destination and is held only briefly in memory to populate the channel picker — it is not stored on our servers.
How we use it. Reline posts to Slack in two cases: when you click Push to Slack on a note, and automatically when an admin has enabled auto-post for a folder, a teamspace or the workspace HQ, in which case the summary of each new note in that scope is posted to the configured channel as soon as it is ready. Either way we post a message containing the note's title, a short intro, and the note's summary (as threaded replies), plus a link back to the note in Reline. We never post your raw transcript or recording. Auto-post is off by default and can be switched off by an admin at any time.
Data we receive but do not retain. When Reline posts to Slack, Slack's API returns the posted message's timestamp and channel; Reline uses the timestamp only to attach the summary as a reply in the same thread during that request, and does not store it. Reline receives no inbound data from Slack — there are no Slack events, slash commands, or webhooks delivered to Reline.
Storage, security, retention, and deletion. Your Slack OAuth token is encrypted by Reline using AES-256-GCM and stored in our managed database (Convex); the channel IDs you select are stored alongside your workspace and folder settings. We keep these only while the connection is active. You can disconnect at any time from Settings → Integrations; disconnecting immediately deletes the stored Slack token and the channel selections derived from it. You can also remove Reline from the Slack side via your Slack workspace's Manage apps settings. For any access or deletion request, email privacy@reline.so and we respond within 30 days.
Integrations you connect
The services below receive data only because you, or an admin in your workspace, connected them and told Reline what to send. They are recipients acting for you, not Reline sub-processors: what they do with the data is governed by your agreement with them. Disconnecting an integration stops further transfers but does not remove what was already delivered.
- Slack. Note title, intro and summary, on demand or through admin-enabled auto-post, as described in the Slack integration section.
- Notion. When you sync a note or folder to a Notion database, Reline writes the note content and sets database properties that include the meeting's attendee email addresses and the note creator's email, so pages can be filtered by person in Notion.
- Linear. Action items you choose to send become Linear issues with the item text and a link back to the note.
- Zapier and outbound webhooks. For each event you subscribe to, Reline delivers the note's title, its URL, the summary as markdown and the action items to the endpoint you configured. Deliveries are signed so the receiver can verify they came from Reline.
- MCP clients. If you authorise an AI assistant (ChatGPT, Claude or another MCP-compatible client) to connect to Reline, it can read and search the notes and transcripts you have access to, and create notes, on your behalf while the authorisation lasts. You can revoke it in Settings → Integrations; workspace admins can disable MCP access for everyone.
Browser extension
Reline's optional browser extension for Google Meet, Microsoft Teams and Zoom (listed on the Chrome Web Store as Reline) is not required to use Reline. If you install it, it reads two things from Google Meet, Microsoft Teams and Zoom tabs you have open: the participant display names the meeting page is already showing you, and which participant is currently speaking. It reads nothing until you have pressed Turn on speaker names on the consent page the extension opens when it is installed, and you can turn it off again from that same page at any time.
It passes both to Reline running on the same computer, either to the desktop app over a loopback connection to your own machine (127.0.0.1) or to a Reline tab open in the same browser using the browser's built-in extension messaging. Neither path leaves your device. The extension itself sends nothing to Reline's servers and nothing to any third party.
Because a meeting has more than one person in it, the display names it reads include the names of the other participants in your call, as shown on your own screen. They are used for one purpose: labelling who said what in your transcript. The raw speaker events are deleted from our servers after 24 hours.
Reline's use and transfer of information received from Google APIs to any other app adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
The extension does not access your microphone, does not record or process audio, and does not run on any site other than Google Meet, Microsoft Teams and Zoom's in-browser meeting pages. It keeps a cached copy of its own configuration, your consent choice, and any speaker data it has not yet delivered, in your browser's extension storage; uninstalling the extension removes that storage. Speaker names that reach Reline become part of your transcript and are then handled exactly like the rest of your note content, as described above.
Recording other people
A meeting recording contains other people's voices, names and, through your calendar, email addresses. For that content you, or the organisation you record for, are the data controller and Reline is your processor. You decide whether to record, what to keep, whom to share with and when to delete, and you are responsible for informing participants and, where the law requires it, obtaining their consent before recording (see the terms of service).
To help you meet that duty, Reline publishes a plain-language notice for meeting participants that you can share, and includes it, with a one-click objection link, in every recap or invitation email sent to someone who is not a Reline user. People who use that link are added to a suppression list and receive no further email from Reline on anyone's behalf.
If a participant objects or asks for erasure, the quickest route is for you to delete or edit the note yourself. If they write to privacy@reline.so instead, we log the request, forward it to you as the controller, assist you in fulfilling it, and answer the person within one month.
Sub-processors
We use a small set of vetted vendors to operate Reline. The authoritative list, with locations, transfer mechanisms and a dated change log, is at reline.so/subprocessors. In summary:
- Convex (USA) — primary database, authentication, and realtime sync. Your account data, calendar metadata, notes, transcripts and summaries are stored here, encrypted at rest.
- Cloudflare R2 (USA) — object storage for your audio recordings, uploaded files and complete data-export bundles.
- Speech-to-text provider (USA) — real-time transcription. Audio is streamed during a recording session using a temporary, session-scoped key. The provider is named in the sub-processor annex provided with the DPA on request.
- Vercel (USA) — hosting for the web application, the AI Gateway through which every language-model request is routed, and cookieless Web Analytics and Speed Insights.
- OpenAI (USA) — embeddings of your notes, transcripts and summaries (which power search and chat), meeting-prep intelligence that includes attendee email addresses from your calendar, chat titles and some generations.
- Z.ai GLM models, served by Baseten (USA) and DeepInfra (USA) — summaries, chat answers and other generations. The model is Z.ai's; inference runs on Baseten and DeepInfra, reached through the Vercel AI Gateway.
- WorkOS (USA) — enterprise SSO and directory sign-in, when your organization enables it.
- Lemon Squeezy (USA, a Stripe company) — merchant of record and payment processing. It receives your billing details to process payments.
- Resend (USA) — transactional and product email (sign-in links, invitations, recaps, onboarding tips).
- PostHog (USA) — first-party product analytics and session replay, only when you have consented.
Language-model providers process content only to return the result you asked for; under their API terms they do not use it to train models, and retention is limited to what each provider's policy specifies (for example a short abuse-monitoring window). Each sub-processor receives only the minimum data required for its function, under a data processing agreement. We announce additions and replacements on the sub-processor page and by email to workspace owners at least 30 days in advance.
Retention & deletion
Workspace content (notes, transcripts, recordings, summaries) is retained for as long as the workspace exists. When a note is deleted, it goes to trash and is permanently removed after 30 days, together with its transcript, recording, chat history and every AI output generated from it. Deleting a workspace removes all its content.
- Chat history and AI outputs live with their note and are deleted with it.
- Version history keeps the last 50 versions of each note; older versions are dropped as new ones are saved.
- Speaker events from the browser extension are deleted after 24 hours.
- Calendar data follows the separate retention described in the Google API Services section: only a rolling window of recent and upcoming events is kept, events more than 7 days past are deleted daily, and all cached calendar data — including the contacts and companies derived from it — is purged immediately when you disconnect.
- Logs (request, error and security logs) are pruned after 90 days.
- Complete data exports are available for download for 7 days, after which the bundle is deleted from storage.
- Audit and billing ledgers (who shared or deleted what, data-subject requests we handled, invoices and subscription events) are kept after account deletion in pseudonymised form, without your name or email, for accountability and tax purposes.
- Backups. Our database platform keeps backups for up to 30 days, used only for disaster recovery. Deleted data ages out of backups on that cycle and is never restored for any other purpose.
Export. From Settings → Profile you can download an instant partial export of your account and notes at any time, and request a complete export: a JSON archive of everything we hold for you, including transcripts, recordings and files as expiring download links, delivered by email within a few days.
Account deletion. You can delete your account yourself from Settings → Profile. Your identity (sign-in, sessions, profile, memberships) is removed immediately; the teardown of the content you own completes within hours. If you are the sole owner of a workspace with other members, transfer ownership first so the workspace can outlive your account. Prefer email? Write to privacy@reline.so and we respond within 30 days.
Security
Encryption in transit (TLS 1.2+) and at rest. SSO via Google or Microsoft Entra ID (Okta and generic SAML are on the enterprise roadmap). Granular per-note permissions, signed outbound webhooks and an append-only audit log. See our security page for the full posture matrix.
Your rights
If you're in the EEA, UK, or California, you have the right to:
- Access the data we hold about you.
- Correct inaccurate data.
- Delete your account and content (restriction and erasure).
- Export your content in a machine-readable format (portability).
- Object to, or request restriction of, processing for legitimate-interest purposes, including product emails and first-touch attribution.
- Withdraw consent for analytics or non-essential cookies at any time, without affecting prior processing.
You can exercise access, export, and deletion yourself from Settings → Profile, or email privacy@reline.so for any request. We do not charge for these, we log every request we receive, and we respond within 30 days. Requests that concern content controlled by another Reline user or their organisation are forwarded to that controller, and we help them fulfil it.
International transfers. Reline and its sub-processors are located in the United States. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on the EU Standard Contractual Clauses, the UK Addendum, and equivalent safeguards, as described in our Data Processing Addendum.
Complaints. You have the right to lodge a complaint with your local data protection supervisory authority (for example, your national authority in the EEA, the UK Information Commissioner's Office, or the relevant Swiss authority). We'd appreciate the chance to address your concern first at privacy@reline.so.
Children
Reline is not directed to children under 16. We do not knowingly collect data from children under 16.
Changes to this policy
We update this page when our practices change. Material changes will be communicated by email and announced in the changelog. The effective date at the top of this page always reflects the current version.
Fragen? E-Mail an legal@reline.so.