DayMarshal
Data protection & retention
Last updated: 21 July 2026
This policy sets out how long DayMarshal keeps each kind of data, how that data is protected, and which third parties process it. It complements our privacy policy.
Principles
- Collect what the service needs, and no more.
- Your content stays until you remove it — we do not keep meeting or message content beyond what you have chosen to store.
- Delete temporary audio when text becomes durable — online-notetaker recordings are removed from our provider once the transcript has been taken, and temporary microphone-recording segments are removed after DayMarshal assembles the durable transcript.
Retention schedule
| Data | Kept for |
|---|---|
| Account information (name, email, hashed password, role) | While your account is active; removed when your account is closed. |
| Connected Google tokens (calendar / mailbox) | Until you disconnect the account, at which point they are deleted. |
| Selected calendar names and encrypted identifiers | Until you disconnect that Google account. Event details are read on demand and are not retained as calendar records. |
| Meeting recordings captured by the notetaker | Deleted from our meeting-bot provider as soon as the transcript has been retrieved. |
| Meeting transcripts and AI summaries | Until you delete the meeting or close your account. |
| Uploaded recordings | Stored on an access-controlled private disk until you delete the meeting. |
| In-person recording segments | Uploaded to access-controlled private storage during recording and deleted after the durable transcript is assembled. If transcription fails, the necessary temporary audio is retained so you can retry. Discarding or deleting the meeting removes any remaining segments. |
| Physical-meeting translations | Retained with the original transcript until you delete the meeting. |
| Synchronized Gmail messages | Message headers, snippets, and bodies are retained until you disconnect the mailbox or close your account. Across all of a user's mailboxes, DayMarshal automatically retains the newest 500 pending or failed, unlinked messages; older records in that pool are pruned. Analyzed messages and messages linked to tasks remain until disconnect so their retained intelligence and source references continue to work. |
| Gmail attachment metadata and content | Attachment names, types, sizes, and provider identifiers are retained with the message. Attachment content is streamed from Google only when requested and is not stored as a DayMarshal file. |
| Chat excerpts and linked-channel messages | Until you delete them or close your account. |
| Server and security logs | A limited operational period, then discarded. Logs never contain meeting, email, or chat content. |
Deletion
You can delete individual meetings yourself from within the app, and disconnect any connected account at any time. To close your account and have its associated data deleted, contact us at privacy@daymarshal.com. We action verified deletion requests within a reasonable period, except where we are required to retain certain records by law.
How data is protected
- In transit: all traffic, and all calls to third-party providers, use HTTPS/TLS.
- At rest: connected-account tokens and remote calendar identifiers are encrypted by the application. Production database storage, private file volumes, and backups containing Google user data are required to use provider-managed or equivalent encryption at rest. Recordings and transcripts are held on access-controlled private storage.
- Isolation: each organization’s data is separated from every other organization’s by a tenant boundary enforced throughout the application.
- Access control: access is role-based (owner, administrator, member, viewer) and checked on every action. Connected mailboxes and calendars remain personal even inside shared workspaces. Message and meeting content is never written to application logs. Human access is limited to authorized personnel for user-requested support, security or abuse investigation, or legal obligations.
- Least privilege: Google access is read-only. Zoom requests only basic user identity and on-behalf-of token access so the visible notetaker can be attributed to the authorizing user; it cannot manage meetings or read cloud recordings. Meet and Teams require no account connection.
- Untrusted-content isolation: source email, chat, and transcript content is identified as untrusted data in AI requests. Models are instructed never to follow embedded commands, open links, execute code, disclose instructions, or take actions, and structured outputs are validated before use.
Subprocessors
We use the following third parties to process data on our behalf:
| Provider | Purpose | Data processed |
|---|---|---|
| Attendee | Meeting notetaker & transcription | Meeting audio (transient) and transcripts |
| OpenAI | Transcription, optional translation, summaries, and analysis | Meeting audio and transcript, bounded Gmail message content, and chat text you process. API data is not used for training by default; default abuse-monitoring logs may be kept up to 30 days unless an approved stricter control applies. |
| Source of connected calendar / mailbox data | Read-only calendar and email, if you connect it | |
| Hosting & infrastructure providers | Running the application and databases | All stored application data |
Security incidents
If we become aware of a security incident affecting your personal data, we will investigate promptly, take steps to contain and remediate it, and notify affected users, relevant authorities, and Google where applicable and required by the Google API Services User Data Policy.
Contact
Questions about data protection or retention? Email us at privacy@daymarshal.com.