1. Scope and who we are
Said & Done is a product of Scaile Agency LLC. In this policy, “Said & Done,” “we,” “us,” and “our” refer to Scaile Agency LLC as the operator of the Said & Done service, website, applications, integrations, and related services (collectively, the “Service”).
This policy applies to account holders, invited client-portal users, people whose information is provided by a customer, meeting participants, email correspondents, and visitors to our website or shared links. A business customer may separately act as the controller or business responsible for information it submits to the Service; in that situation, we process the information on its behalf as its service provider or processor.
2. Information we collect
Account and organization information
We collect account identifiers and profile information such as name, email address, authentication details, account type, organization relationships, portal memberships, preferences, and integration status. We also process the client, contact, project, engagement, repository, and delivery information that users enter into the Service.
Google Gmail information
If you connect Gmail, the Service requests the restricted, functionally read-only gmail.readonlypermission. This permission allows the Service to view Gmail messages and settings; it does not allow Said & Done to send, modify, or delete messages in your Gmail account.
- We store the connected Google account address and encrypted OAuth access and refresh tokens.
- We search recent and ongoing mail for messages involving client contacts and relevant non-consumer email domains configured in the Service.
- For candidate client messages, we temporarily retrieve message content for analysis. We retain message bodies, HTML, headers, subject, sender, recipients, timestamps, thread identifiers, and labels only when the analysis produces client-delivery value such as a request, commitment, completion, risk, decision, blocker, or other material event.
- For messages that are not matched to a client or produce no client-delivery value, we retain only opaque Gmail message and thread identifiers, the responsible connection, and a rejection reason so the same message is not repeatedly processed. We do not retain its subject, sender, snippet, labels, or body in that rejection marker.
- We analyze matched content to identify and reconcile requests, commitments, action items, risks, follow-ups, and other client-delivery signals visible in the Service.
Google Calendar information
If you connect Google Calendar, the Service requests read-only access to calendar events and your Google account email address. We exchange the authorization code and securely provide the resulting Calendar credential to Recall.ai, our meeting-capture processor, so it can synchronize eligible calendar events and schedule the Said & Done Notetaker. We store connection identifiers, status, event details, meeting URLs, titles, times, attendee-related event information, scheduling state, and imported meeting records.
Meetings, recordings, and transcripts
When a connected calendar makes an eligible future video meeting available, a visible Said & Done Notetaker may be scheduled to attend. If admitted, it records and transcribes the meeting. We process calendar and meeting metadata, participant and speaker information, mixed audio and video, transcripts, captions, summaries, sentiment, decisions, action items, risks, and other derived client-delivery information. Recall.ai retains recording media for up to one year. Said & Done stores the transcript, identifiers, meeting metadata, and derived information until deleted or no longer needed as described below.
Client delivery, files, and communications
We process information submitted or generated through client portals, reports, public or recipient-specific share links, walkthrough videos, attachments, comments, inbound and outbound email, implementation briefs, GitHub activity, time-tracking signals, and other integrations selected by a user. Shared-link activity may include the time of access, IP address, approximate location derived from the request, browser or device information, referrer, and link status.
Usage, device, and diagnostic information
We and our hosting, security, and diagnostics providers may collect IP address, browser and device information, session and authentication events, request metadata, application performance, errors, logs, and interaction data. We use this information to operate, secure, troubleshoot, and improve the Service—not for third-party advertising.
3. How we use information
We use information to:
- provide, personalize, maintain, and secure the Service;
- authenticate users and administer accounts, memberships, and permissions;
- connect authorized integrations and synchronize relevant calendar, email, meeting, repository, and delivery information;
- record and transcribe meetings and create user-facing summaries, action items, reports, account-health signals, drafts, recommendations, and implementation workflows;
- publish or send information to recipients, portals, and third-party systems when a user directs us to do so;
- provide support, respond to requests, and communicate about the Service;
- detect abuse, protect accounts, debug errors, and enforce our terms;
- comply with law and protect the rights and safety of users and others; and
- understand and improve the Service using operational metrics and aggregated or de-identified information where appropriate.
4. Google API data and Limited Use
Said & Done uses Google user data only to provide or improve the Gmail and Calendar features that the authorizing user chooses and that are visible in the Service. Said & Done’s use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
We do not use Google Workspace API data to:
- sell personal information or Google user data;
- serve advertising, retargeting, or personalized advertising;
- determine creditworthiness or for lending purposes; or
- train or improve a generalized artificial-intelligence or machine-learning model.
We do not permit personnel or contractors to read Google Workspace content except when the user gives explicit permission for specific content in order to receive support, when access is necessary to investigate a security or abuse incident, or when access is required by law. We share Google data only as necessary to provide user-requested, user-facing features; for security; to comply with law; or with the user’s direction and consent.
5. AI processing
Said & Done uses the AI provider and model selected by the account user to generate user-facing analysis and drafts. Content sent for processing may include meeting transcripts, matched client email content, contact and project context, existing action items, reports, and user instructions. Depending on the user’s configuration, the provider may include OpenAI, Anthropic, Google, OpenRouter, or another supported provider.
The selected provider processes information under its own terms and data practices. Users should configure a provider account and retention settings appropriate for the data they submit. Said & Done does not use Google Workspace data to train generalized models, and we require any processing of Google data through a provider to be limited to delivering the user-requested feature.
6. How we disclose information
We may disclose information to:
- Service providers. Providers that support hosting, databases, authentication, storage, background processing, error monitoring, email delivery, meeting capture, transcription, and AI processing. These include Vercel, Supabase, Inngest, Sentry, Resend, Recall.ai, and the AI provider selected by the user.
- User-selected integrations. Google, Microsoft, GitHub, and other systems a user connects or instructs the Service to update.
- Authorized recipients. Organization users, invited client-portal members, meeting attendees, email recipients, and people who receive a report, meeting, or walkthrough share link at a user’s direction.
- Legal and safety recipients. Authorities or other parties when reasonably necessary to comply with law, respond to legal process, enforce our terms, protect rights and safety, or investigate fraud, security, or abuse.
- Business transaction participants. Advisers and counterparties in a financing, merger, acquisition, reorganization, or sale, subject to appropriate safeguards. Google user data will not be transferred as part of such a transaction without the prior consent required by Google’s Limited Use requirements.
We do not sell personal information or share it for cross-context behavioral advertising.
7. Retention and deletion
We retain information for as long as reasonably necessary to provide the Service, fulfill the purposes described in this policy, maintain security and business records, resolve disputes, and comply with law. Retention depends on the type of information and account configuration.
- Recall.ai meeting audio and video are retained for up to one year.
- Transcripts, retained client-value emails, reports, client records, portal data, and derived content may remain until a user deletes the applicable record, the account ends, or the data is no longer needed.
- Time-tracking raw signals and browser payloads follow the retention settings available to the account; older payload detail may be redacted or compacted while accounting records remain.
- Diagnostic, security, webhook, and workflow records are retained according to operational need and provider settings.
- Deleted information may remain temporarily in backups, fraud-prevention records, and logs until those systems rotate, unless longer retention is legally required.
Disconnecting Gmail revokes the Google authorization on a best-effort basis and removes stored Gmail OAuth tokens. A minimal connection record may remain to preserve the source relationship for previously imported email. Disconnecting Calendar removes the connection and instructs Recall.ai to remove the connected calendar and future scheduled notetakers. Disconnecting does not automatically delete information that was previously imported or generated. Users may delete supported records in the Service or request deletion of account or imported data using the contact information below.
8. Security
We use administrative, technical, and organizational safeguards designed to protect information. OAuth tokens, API keys, and similar credentials stored by Said & Done are encrypted using authenticated encryption and are decrypted server-side only when needed. We also use transport encryption, scoped session and OAuth cookies, access controls, row-level database policies, signed or hashed share credentials, webhook verification, and monitoring.
No method of transmission or storage is completely secure. Users are responsible for protecting credentials, limiting access to their accounts and share links, and notifying us promptly of suspected unauthorized access.
9. Cookies and similar technology
We use cookies and similar technology that are necessary for authentication, session continuity, security, OAuth state validation, preferences, and core Service operation. We also use diagnostic technology to understand errors and performance. We do not currently use personal information collected through the Service for third-party behavioral advertising.
10. Your choices and privacy rights
Depending on your relationship with us and applicable law, you may be able to:
- review and update account or client information;
- disconnect Gmail, Google Calendar, Microsoft Calendar, and other integrations;
- remove or revoke certain meetings, reports, walkthroughs, memberships, and share links;
- export supported reports or records using available Service features; and
- request access, correction, deletion, portability, restriction, objection, or an appeal concerning personal information, as provided by applicable law.
We may need to verify identity and authority before completing a request. If information was submitted by one of our business customers, please direct the request to that customer first; we will assist it as required by our agreement and applicable law.
11. International processing
Said & Done and its providers may process information in the United States and other countries where they operate. Those locations may have different privacy laws. Where required, we use contractual and other safeguards intended to protect transferred information.
12. Children
The Service is designed for business use and is not directed to children under 18. We do not knowingly collect personal information from children through the Service. If you believe a child has provided personal information, contact us so we can take appropriate action.
13. Changes to this policy
We may update this policy as the Service, our practices, or legal requirements change. We will post the updated policy at this URL and change the “Last updated” date. When required, we will provide additional notice or request consent before using information for a materially different purpose.
14. Contact us
Privacy questions and requests may be sent to privacy@saidanddone.ai. For general questions, use our contact form. Authenticated customers can find the product support address inside Said & Done.
Scaile Agency LLC
Said & Done