Privacy Policy
Last updated: August 3, 2026
Pondros (“Pondros,” “we,” “us”) is a product of Herd. This policy explains what we collect when you use the Pondros website and desktop app, how we use it, and the choices you have. We've tried to keep it plain.
What we collect
- Your email address, when you request a download or sign up, so we can send your download link and occasional product updates.
- Meeting audio you choose to transcribe. When you start transcription in the app, microphone and (optionally) system audio are captured, converted to text, and the audio is discarded. We never store a recording.
- Transcripts, notes, and tasks generated from your meetings, plus the workspace and roster information you provide.
- Basic account identifiers needed to connect the app to your workspace.
- Google Calendar data: only if you connect it. If you choose to connect Google Calendar, we read your upcoming events (titles, start and end times, attendee email addresses, and any meeting link) so Pondros can prepare you before a meeting and remind you when one is about to start. Access is read-only and we never create, edit, or delete anything on your calendar.
- Gmail data: only if you connect it. Sending is used only to deliver an email you have reviewed and approved. Reading is a separate, opt-in feature: if you turn on email follow-ups, we read threads from the last 7 days in your own Inbox and Sent mail to find tasks and requests, and place them in your review queue. See Google user data & Limited Use below for exactly what we keep.
- Google Drive files that Pondros itself creates. When you ask Pondros to produce a document, sheet, or deck, it creates that file in your Drive and can update it later. Pondros cannot see, open, or modify any other file in your Drive.
Where your data lives
Transcripts and notes are stored locally on your device by default. When you approve syncing a meeting's tasks to your Pondros board, the finalized transcript segments and the items you approve are sent to our backend so your workspace stays up to date. We do not transcribe meetings in the background. Capture happens only during sessions you start.
Service providers (sub-processors)
We share the minimum data necessary with vendors that help us run the product. Each is bound by its own data-protection terms:
- Deepgram converts meeting audio to text (speech-to-text).
- Anthropic turns transcripts and notes into structured tasks and summaries (AI processing).
- Vercel hosts this website.
- Fly.io and Supabase host our application backend and database.
- Resend sends our transactional and update emails.
We do not sell your personal information, and we do not use your meeting content to train our own models.
Google user data & Limited Use
Every Google connection is optional, granted by you, and revocable by you. When you connect, Pondros receives an OAuth token that we store encrypted on our backend, never placed on your device, never shared with third parties. Disconnecting from Settings deletes the stored token and revokes our access. You can also revoke it directly from your Google Account security settings.
Here is every category of Google data Pondros requests, and what each one is for:
- Calendar, read-only (
calendar.readonly) reads your upcoming events to build your pre-meeting brief and meeting reminders. Pondros never creates, edits, or deletes calendar entries. - Gmail, send (
gmail.send) sends a message from your connected account only when you press send on a draft you have reviewed. Pondros never sends email on its own initiative, and this permission cannot read your mailbox. - Gmail, read-only (
gmail.readonly) powers email follow-ups, which is off unless you turn it on. Each poll reads threads from the last 7 days in your own Inbox and Sent mail, skipping Promotions and Social, to identify tasks and requests. Pondros reads only the mailbox of the person who authorized it, using that person's own token. We store the follow-ups we surface to you and the message identifiers needed to avoid showing the same one twice. We do not keep copies of your mailbox. - Drive, per-file (
drive.file) creates and updates only the files Pondros itself creates for you. This permission grants no visibility into the rest of your Drive.
Pondros's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, for Google Calendar, Gmail, and Google Drive data: we do not use it for advertising; we do not sell it; we do not transfer it except as necessary to provide or improve user-facing features that are prominent in the Pondros interface, to comply with applicable law, or as part of a merger or acquisition after obtaining your explicit consent; we do not use it to develop, improve, or train generalized artificial-intelligence or machine-learning models; and we do not allow humans to read it, except with your affirmative agreement for specific messages, where necessary for security purposes such as investigating abuse, to comply with applicable law, or for internal operations on data that has been aggregated and de-identified.
How AI is used on Google data. To turn mail into follow-ups and to draft replies for you, message content is sent to our AI provider, Anthropic, for the sole purpose of producing that result for you. Anthropic does not train its models on the content of API requests, and Pondros does not use your Google data to train any model of its own.
How we use your data
- To provide transcription, notes, tasks, and your board.
- To send your download link and product updates (you can opt out).
- To operate, secure, debug, and improve the service.
- To comply with legal obligations.
Transcription & consent
You are responsible for complying with the recording and consent laws that apply to you. Some jurisdictions require that everyone in a conversation consents before their audio is captured. Please obtain consent where required before transcribing a meeting.
Your choices & rights
You can request access to, correction of, or deletion of your personal data, and you can unsubscribe from update emails at any time. Depending on where you live (for example, the EU/UK under GDPR or California under the CCPA/CPRA), you may have additional rights. To exercise any of these, email hey@pondros.com.
Data retention & security
We keep personal data only as long as needed to provide the service or as required by law, then delete or anonymize it. We use encryption in transit, and credentials in the desktop app are stored encrypted in your operating system's keychain. See our Security page for more.
Children
Pondros is not intended for anyone under 16.
Changes
We may update this policy as the product evolves. Material changes will be reflected by the “Last updated” date above.
Contact
Herd: hey@pondros.com