Assistly
FeaturesIntegrationsPricingEnterpriseFAQBlogDownload
Sign inTry it free
FeaturesIntegrationsPricingEnterpriseFAQBlogDownloadTry it freeSign in

Legal

Privacy Policy

Last updated: September 25, 2026

This policy explains how Zigzag Technologies, a sole proprietorship based in British Columbia, Canada (“Assistly,” “we,” “us”), handles personal data when you use the Assistly desktop app for macOS and Windows, the iOS app, the web app at app.tryassistly.com, and this website (together, the “Service”). It is written to meet the EU General Data Protection Regulation (GDPR), the UK GDPR, and Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA).

1. Who we are

Zigzag Technologies is the controller of the personal data described here: we decide why and how it is processed. You can reach us about anything in this policy at support@tryassistly.com.

If you are in the EU or UK and want to contact us about data protection, email support@tryassistly.com with “Privacy” in the subject.

When a business uses Assistly for its team, that business is the controller of its team’s meeting content and we process it on its behalf under our Data Processing Addendum.

2. What we collect and where it comes from

From you

  • Account details: name, email, job title, company, and a hashed password. If you sign in with Google or Apple, we receive your name, email, and an account ID from them.
  • Files you upload: a persona or CV, and documents you attach to a Mode so answers can draw on them.
  • Meeting content: when a session is running, microphone and system audio is streamed to the cloud to be transcribed. We store the transcript, the questions you ask and the answers you get, recaps, summaries, action items, and speaker names. When you ask for help with your screen, we capture a screenshot and store it with the session.
  • Integrations you connect: calendar events from Google Calendar (read-only), messages from Slack channels you add the bot to, and the MCP servers you connect, including their access tokens, which are stored encrypted.
  • Payments: handled by Stripe, or by Apple or Google when you subscribe in their app stores. We receive your billing contact, plan, and payment status, never your full card number.
  • Support requests: what you write to us and any diagnostics you choose to attach.

Collected automatically

  • Usage data: which features are used and when, device and operating system details, and app version. On the website and web app this is collected with analytics cookies unless you switch them off (see Cookie Policy), and may include a session recording of clicks and page layout with form inputs masked (in the web app, all page text is masked as well, so meeting content is never recorded). The desktop app sends pseudonymous usage events, without screen recording or automatic capture of what you type or click, and you can switch them off with “Share usage analytics” in the app’s settings.
  • Server logs and error reports: IP address, request details, and errors. Error reports from our servers are sent to PostHog so we can fix bugs.
  • Email opens: our emails can contain a small image that tells us whether the email was opened.

Free transcription tool

Files uploaded to the free tool on this website are sent to our speech-to-text provider, and the file and the transcript are deleted there as soon as your browser has the text. We do not store them. Your IP address is used briefly to enforce usage limits.

3. Other people on your calls

When you run Assistly on a call, the voices of other participants are transcribed, and their names and what they said can appear in transcripts and recaps. We process this data only to provide the Service to the Assistly user, and for business customers on their behalf as their processor. If you use Assistly, you are responsible for telling the other participants and getting their consent where the law requires it.

If you took part in a call with an Assistly user and want to exercise your rights over that data, you can ask the user directly or email support@tryassistly.com. We will help, and where the data belongs to a business customer, we will pass your request to them.

4. Why we use it, and our legal basis

PurposeLegal basis
Run your account and the Service: sign-in, live transcription, answers, recaps, action items, search, and the integrations you connect.Contract (Art. 6(1)(b))
Take payments, manage subscriptions, and keep billing and tax records.Contract; legal obligation (Art. 6(1)(c))
Answer support requests and bug reports.Contract; legitimate interests (Art. 6(1)(f))
Keep the Service secure and working: server logs, rate limits, abuse and fraud prevention, debugging.Legitimate interests
Understand how the desktop app is used so we can improve it (pseudonymous usage events, which you can switch off in the app).Legitimate interests
Analytics cookies on tryassistly.com and app.tryassistly.com, which you can switch off at any time.Legitimate interests (Art. 6(1)(f))
Service emails: sign-in, receipts, and account or security notices.Contract
Product tips emails to account holders, and knowing whether an email was opened.Legitimate interests (or consent where the law requires it); unsubscribe at any time
Respond to lawful requests from authorities and enforce our Terms.Legal obligation; legitimate interests

Where we rely on legitimate interests, those interests are running a secure, reliable service and improving it, and we have weighed them against your rights. You can object at any time (see Section 12).

Meeting content and uploads can contain sensitive information. We do not ask for it and process it only to provide the features you use.

5. Do you have to give us this data?

An email address is needed to create an account, and payment details are needed for a paid plan. Meeting content is needed for the features that work on it. Everything else, such as a CV, Mode documents, integrations, and analytics cookies, is optional. Without it, the related features simply do not work.

6. AI processing

Answers, recaps, and summaries are generated by AI models running on Amazon Bedrock (including models from Anthropic, Amazon, Moonshot, and Alibaba, and Cohere for search embeddings). If an alternative model route is enabled, requests can instead go through OpenRouter to OpenAI models. To answer questions about recent events, a search query based on your question can be sent to Tavily. Only the content needed for the request is sent.

Your content is not used to train AI models, by us or by these providers. Answers are generated automatically and can be wrong. We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.

7. Google user data

Assistly offers Google sign-in and an optional, read-only Google Calendar connection. Through these, we access your basic Google account profile (name, email address) and — only if you connect your calendar — your calendar events, so the app can show your upcoming meetings, join scheduled sessions automatically, and answer your questions about your schedule. We request only the minimum scopes needed for these features, and calendar access is read-only: we never create, modify, or delete events.

Assistly’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

AI/ML and Limited Use. When you ask the assistant about your schedule, your upcoming calendar events may be included in the request sent to our AI provider, Amazon Bedrock, solely to generate your answer in that moment. Amazon Bedrock does not store this content or make it available to model providers, and it is not used to train or improve any machine-learning or artificial-intelligence models. We do not use, transfer, or sell raw, aggregated, or derived Google user data to create, train, or improve foundational or generalized AI/ML models, and we do not transfer Google user data to any third-party AI service that would do so. Google user data is never used for advertising, never sold, and never transferred to data brokers or for creditworthiness or lending purposes. You can disconnect Google Calendar at any time from the app, which deletes the stored tokens.

8. Slack data

Assistly offers an optional Slack connection. When you connect it, we store a bot token for your workspace and the Slack member ID of the person who connected. The bot can post to channels you choose, answer questions when you mention or message it, and read the channels you add it to. It does not read the rest of your workspace.

What we collect. Messages from channels you have added the bot to, including their author, time, and a link to the message; the questions you ask the bot in Slack; and the recaps and answers the bot posts. Messages in a channel or thread where the bot is asked a question are read at that moment to answer it and are not stored. The bot’s own posts are never recorded.

How we use it. Channel messages are indexed so that you can ask about them, in Slack or in the Assistly app, and get an answer that cites the message it came from. A channel can be searched only by people who are members of that channel and have connected Assistly. Nothing is shared between accounts.

AI processing. To answer a question, the relevant excerpts are sent to our AI provider, Amazon Bedrock, to generate the answer in that moment. Bedrock does not store this content or make it available to model providers, and Slack data is never used to train or improve any AI model. Answers are generated by an AI model and can be wrong; each one links to its source so you can check it.

Retention and deletion. Indexed channel content is kept for up to 180 days. Removing the bot from a channel deletes everything indexed from that channel. You can stop reading a channel, or disconnect Slack entirely, from Integrations in the app; disconnecting deletes the stored token and removes you from every channel you followed.

9. Who we share it with

We do not sell personal data or share it for advertising. We share it only with:

  • Service providers that process it for us under written agreements: hosting, database, speech-to-text, AI models, web search, payments, analytics, email, and support. Each one, what it receives, and where it runs is listed on our sub-processors page.
  • Services you connect, such as Slack, Google Calendar, or an MCP server, when you ask Assistly to use them.
  • Authorities or other parties when the law requires it, or to protect our users, the public, or our rights.
  • A buyer or successor if the business is sold or merged, under this same policy.

10. International transfers

We are based in Canada, which the European Commission and the UK recognise as giving adequate protection to personal data. Our servers run on Amazon Web Services in the United States (us-east-1) and our database on Supabase, also in the United States (us-east-2), and several of our providers are in the United States.

When personal data from the EU, EEA, or UK goes to a provider outside those countries, we rely on the EU-US Data Privacy Framework (and its UK Extension) where the provider is certified, and otherwise on the European Commission’s Standard Contractual Clauses, with the UK International Data Transfer Addendum for UK data. You can ask us for a copy of the relevant safeguards.

11. How long we keep it

DataHow long
Account detailsUntil your account is deleted.
Meeting content: transcripts, questions and answers, recaps, action items, speaker names, screenshots, and uploaded documentsUntil you delete it, or your account is deleted.
Live meeting audioNot stored by us. It is streamed to our speech-to-text provider for transcription and not kept after it is transcribed.
Indexed Slack channel messagesUp to 180 days, or until the bot is removed from the channel.
Integration tokens (Google Calendar, Slack, MCP servers)Until you disconnect the integration or your account is deleted.
Server logs30 days.
Product analytics events and session recordings30 days.
Support ticketsUp to 3 years after the ticket is closed.
Billing and tax recordsAs long as tax and accounting law requires. These are mostly held by Stripe, Apple, or Google.
BackupsWhen your account is deleted, your data is removed from live systems straight away and from backups within 30 days.

12. Your rights

Depending on where you live, you have the right to:

  • access the personal data we hold about you and get a copy of it;
  • have it corrected if it is wrong or incomplete;
  • have it deleted;
  • restrict how we use it;
  • receive it in a machine-readable format and have it sent to another service;
  • object to processing based on legitimate interests, including emails;
  • withdraw consent at any time, without affecting what was done before;
  • not be subject to decisions based solely on automated processing that have legal or similarly significant effects (we do not make any).

Do it yourself. To get a copy of your data, go to Settings → Your data → Download my data in the web app, desktop app, or iOS app. To delete your account, use Settings → Your data → Delete account in the iOS app, or ask us as below. You can also edit your profile and delete any session in the app.

Or ask us. Email support@tryassistly.com, from the address on your account if you can, for any of these, including deleting your account. We may need to confirm your identity first. We reply within one month, and tell you if a complex request needs up to two more months.

Complaints. You can complain to a data protection authority: in the EU, the authority in the country where you live or work (list of EU authorities); in the UK, the Information Commissioner’s Office; in Canada, the Office of the Privacy Commissioner. We would appreciate the chance to sort it out with you first.

13. Security and breaches

Data is encrypted in transit (TLS 1.2 or higher) and at rest, access to production systems is limited to the people who need it, and secrets are kept in a managed secrets store. More detail is on our Security page. No system is perfectly secure.

If a personal data breach is likely to put your rights at risk, we notify the relevant supervisory authority within 72 hours of becoming aware of it where the law requires, and tell affected users without undue delay.

14. Cookies and analytics

The website and web app set analytics cookies from your first visit, and you can switch them off at any time. Details are in our Cookie Policy.

15. Emails

We send service emails that are part of running your account. We also send account holders occasional emails with product tips. Every one of those has an unsubscribe link, and unsubscribing does not affect service emails.

16. Children

The Service is not intended for anyone under 16, and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.

17. Changes to this policy

When we change this policy, we update the date at the top. If a change is significant, we tell account holders by email or in the app before it takes effect.

18. Contact us

Zigzag Technologies, Canada · support@tryassistly.com

Assistly

Real-time AI for your live conversations

Our modelMeet Cue →

Product

  • Download
  • Features
  • Integrations
  • Pricing
  • Enterprise
  • FAQ

Compare

  • vs Cluely
  • vs Interview Coder
  • vs Granola
  • vs Fathom
  • vs InterviewMan
  • All comparisons

Resources

  • Free meeting transcription
  • What is a live meeting assistant?
  • Meeting AI without the bot
  • AI for meetings & sales
  • Best AI meeting assistants
  • Read the blog

Company

  • Support
  • Security
  • Privacy
  • Terms
  • Cookies
  • Refund Policy

© 2026 Assistly, operated by Zigzag Technologies. Use responsibly and in accordance with the rules of any meeting, call, or interview you take part in.

  • Data Processing Addendum
  • Sub-processors