Privacy Policy
How Loka Note accesses, uses, stores, shares, and deletes your data — including the Google user data you choose to connect.
Effective 13 July 2026 · Last updated 13 July 2026
Who we are
Loka Note is an AI meeting-notes product. You record or upload a meeting, and Loka transcribes it and generates a summary, action items, and notes you can search and share.
This policy explains what data Loka collects, how we use it, who we share it with, how long we keep it, and how you can delete it. It covers lokanote.com, the Loka web dashboard, our desktop and mobile apps, and our browser extension.
Google user data and Limited Use
Connecting your Google account to Loka is optional. If you connect it, Loka’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We use Google user data for one purpose only: to provide and improve the user-facing features of Loka that you have chosen to use. We never use it for anything else. Specifically, Loka does not:
- use Google user data for advertising of any kind, including personalised, targeted, retargeted, or interest-based advertising;
- sell, rent, or transfer Google user data to data brokers, information resellers, or any other party for advertising purposes;
- use Google user data to develop, train, improve, or fine-tune any generalised or foundation AI or machine-learning model, whether ours or a third party’s;
- use Google user data to determine credit-worthiness or for lending purposes;
- use Google user data for any purpose other than providing or improving the Loka features you actively use.
Human access. No one at Loka reads your Google user data, with four narrow exceptions permitted under the Limited Use requirements: (a) you have given us your explicit consent to view specific data, for example when you send it to us to debug a problem; (b) it is necessary for security purposes, such as investigating abuse or a suspected security incident; (c) it is required to comply with applicable law; or (d) the data has been aggregated and anonymised so that it no longer identifies you, and is used for internal operations.
What Google data we access, and why
Loka requests the minimum set of scopes needed for the features it offers. Each one, and what it is used for:
userinfo.emailReads the email address of the Google account you connect, so Loka can show you which account is linked and keep the connection attached to the right Loka account.calendar.eventsReads your calendar events so Loka can show your upcoming meetings, and creates or removes calendar events that you schedule from inside Loka — including attaching a Google Meet link. Loka only creates or removes an event when you explicitly ask it to.meetings.space.createdCreates a Google Meet space when you start or schedule a meeting in Loka, and afterwards reads the participant list for those meetings so Loka can label the speakers in your notes. This scope only ever returns data for Meet spaces that Loka itself created; it gives Loka no access to any of your other meetings.
What Loka deliberately does not request. We do not request Google Drive access, so Loka cannot read your files or any Meet recordings and transcripts stored in your Drive. We do not request Gmail access, so Loka cannot read your email. We do not request read access to meeting spaces Loka did not create.
What Google data we store
We store:
- the email address of the Google account you connected;
- your Google OAuth access and refresh tokens, encrypted at rest with AES-256-GCM and used only to call Google APIs on your behalf;
- for Meet spaces Loka creates at your request: the meeting code and link;
- for those meetings: the display names of the participants, which become the speaker roster on your own meeting note.
We do not store:
- your calendar events. When you open a view that shows your upcoming meetings, Loka fetches them from Google live and renders them for you. They are not written to our database.
- your Google password — Loka never sees it;
- any Drive file, Gmail message, or Google Meet recording.
Deleting Google data and revoking access
You can cut off Loka’s access to your Google account at any time:
- Disconnect inside Loka. In Settings, disconnect your Google account. Loka immediately revokes the tokens with Google and deletes them from our database.
- Revoke from Google. You can remove Loka’s access at any time from your Google Account permissions page.
- Delete your account. Deleting your Loka account revokes your Google tokens with Google and permanently deletes your data, including any Meet spaces and participant rosters. This is a hard delete, not a hide.
Other information we collect
Account data. Your name, email address, and authentication details, so we can create and secure your account.
Meeting content. The audio you record or upload, and the transcripts, summaries, action items, titles, and notes generated from it. This is your content — you decide what to bring into Loka.
Usage and device data. Basic product-usage events, device and browser information, and server logs. We use these to keep the service running, secure, and reliable, and to understand which features are used. We do not send your transcripts, note titles, or chat content to our analytics provider.
How we use information
We use the information above only to provide and improve the user-facing features of Loka. In practice that means: authenticating you, transcribing your meetings, generating summaries and action items, powering search and chat across your own notes, saving your settings, processing payments, keeping the service secure and available, preventing abuse, fixing bugs, and sending you service-related messages such as a receipt or a summary of a meeting you recorded.
We do not use your data for advertising, we do not profile you, and we do not sell it.
AI processing and model training
Generating a summary means sending your meeting content to an AI model for inference. Loka uses Google Cloud Vertex AI (Gemini) for summarisation and chat, and self-hosted or Google Cloud speech-to-text for transcription. Content is sent over TLS, used to produce your result, and not retained by the model provider for training.
Your content is never used to train AI models — not ours, not our providers’. Our AI processors are contractually bound not to train on the data we send them. This applies to all of your content, and it applies without exception to Google user data.
Service providers
We share data with a short list of vendors strictly so they can help us run Loka, each bound by a written agreement limiting what they may do with it: Supabase (database, authentication, storage), Vercel (application hosting), Google Cloud (audio storage, speech-to-text, and the Vertex AI models), Polar (payments — card details go directly to Polar and never reach our servers), Apple (in-app purchases on iOS, handled entirely by the App Store), Meta (only if you contact our support on Messenger), Expo (mobile push notifications — never your meeting content), our email provider (transactional email), Sentry (error monitoring, with personal data scrubbed), and PostHog (product analytics, which never receives your meeting content).
The current list is maintained on our Data Processing Agreement page.
Sharing and disclosure
We do not sell your personal information or your Google user data, and we do not share it with third parties for their own purposes. Beyond the service providers above, we disclose data only when you ask us to — for example, when you share a note or send a summary by email — or when we are legally required to, such as to comply with a valid legal request, enforce our terms, or investigate abuse or a security incident.
If Loka is ever involved in a merger, acquisition, or sale of assets, we will give you advance notice and honour the commitments in this policy, including the Limited Use requirements that govern Google user data.
Security
Data is encrypted in transit with TLS and at rest. Google OAuth tokens are additionally encrypted with AES-256-GCM before they are stored. Every account is isolated at the database level with row-level security, so one user cannot read another’s data. Logs and error reports are scrubbed of secrets and personal data before they leave our systems. Access to production is limited to the people who need it.
No system is perfectly secure, but you can read more about how we approach this on our Security page.
How long we keep data
- Notes and transcripts are kept until you delete them. A note you move to Trash is permanently deleted after 30 days.
- Audio recordings are deleted after 180 days by default; the transcript and summary remain.
- Google tokens are deleted the moment you disconnect your Google account.
- Your account and its data are permanently deleted when you close your account.
After you close your account we retain only what the law requires us to keep, such as billing and tax records.
Your rights and choices
You can access and export your data, correct your account details, delete individual notes, disconnect your Google account, and delete your account entirely — all from inside the product, without asking us.
Depending on where you live, you may also have the right to object to or restrict certain processing, or to lodge a complaint with your data protection authority. Write to us and we will help.
International transfers
Loka is operated with infrastructure hosted primarily in the United States. If you use Loka from outside the US, your data will be transferred and processed there under the safeguards described in this policy and in our Data Processing Agreement.
Children
Loka is a workplace product and is not directed to children. We do not knowingly collect data from anyone under 16. If you believe a child has given us data, contact us and we will delete it.
Changes to this policy
We may update this policy as the product changes. If we make a material change to how we handle your data — in particular, any change to how Loka uses Google user data — we will update the effective date above and notify you before the change takes effect. Continuing to use Loka after that means you accept the updated policy.
Contact
For any privacy question, or to exercise any of the rights above, contact support@lokanote.com. We answer privacy requests within 30 days.