Privacy policy
Gappd privacy policy
Gappd is local-first. Its default configuration processes and stores meeting content on your Mac. The current public version does not request Google Calendar access. Calendar-enabled versions make access optional and user-initiated.
1. Who operates Gappd
Gappd is operated by Kristian Gosvig. Send questions and privacy requests to leasemobil@gmail.com.
2. Data processed on your Mac
When you choose to record a meeting, Gappd can process microphone audio, system audio, transcript text, speaker information, meeting titles, summaries, and action items. It also stores app settings and local model configuration.
The default Local AI provider processes transcript text on your Mac. Meeting content and settings are stored in local app files and a local SQLite database.
3. Optional Installed Codex provider
If you select Installed Codex as the summary provider, Gappd sends transcript text through the Codex command-line tool and account already configured on your Mac. Recorded audio remains local. Your provider agreement and configuration govern that processing.
4. macOS permissions
Gappd requests microphone, screen and system audio recording, and speech recognition permissions for recording and transcription. You can revoke these permissions in macOS System Settings at any time.
5. Network connections
Gappd can use the network to check for and download app updates, download local model files, open support links, and use an optional provider that you configure. Calendar-enabled versions connect to Google and Gappd’s isolated authorization relay only after you choose to connect an account. The current app and website do not include advertising or behavioral analytics. The website loads font files from Google.
6. Optional Google Calendar
Google Calendar is not available in the current public version. In a Calendar-enabled version, you can independently connect one or more Google accounts. Connecting opens Google in your system browser. Gappd requests the https://www.googleapis.com/auth/calendar.events.owned.readonly scope and reads only each connected account’s primary calendar. Calendar access never starts a recording; recording remains a separate action you initiate.
Gappd processes the connected Google account identifier and email address plus event identifiers, titles, start and end times, all-day status, event status, and location. It uses this data only to show your Calendar agenda and maintain the selected account connection.
Google authorization tokens and cached Calendar data are encrypted and stored in Gappd’s local app data on your Mac. They are not exposed to the renderer. The static website service does not receive Google tokens, Calendar data, or meeting content.
Gappd uses a separate authorization relay hosted by Railway to add Gappd’s Google credential during token exchange and refresh. Authorization codes, PKCE verifiers, and Google tokens pass through the relay transiently and are not stored there. Private Redis state is limited to installation public keys, revocation state, expiring replay protection, and rate counters. Railway acts as an infrastructure processor for this transient operation.
Gappd’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google data is not sold, used for advertising, or used to train a generalized artificial intelligence model.
7. Sharing and sale
Gappd does not sell meeting or Google user data or use it for advertising. Gappd does not share meeting content with the operator in the default local configuration. Data reaches Google or Railway only for the optional Calendar operations described above, reaches another provider when you choose and configure that provider, or is disclosed when required by law.
8. Retention and deletion
Local meeting data remains on your Mac until you delete the meeting or remove the app data. Deleting a meeting in Gappd removes its local summary, transcript, segments, and associated audio files. Copies in device backups are controlled by your backup provider and settings.
Google tokens, account details, and cached events remain encrypted on your Mac while the account is connected. Disconnecting an account attempts to revoke its Google authorization and removes that account’s tokens and Calendar cache from Gappd. It does not delete recorded meetings. Expiring relay replay and rate-limit records are removed automatically; installation public keys remain until revoked or operationally deleted.
9. Security
Gappd limits processing to the permissions and providers needed for selected features. Google tokens and Calendar caches use macOS-backed encrypted storage with no plaintext fallback. Relay requests use installation-specific signing keys, timestamps, one-time nonces, rate limits, and Demonstrating Proof of Possession. You are responsible for protecting access to your Mac, local backups, and any optional provider account.
10. Your choices and requests
You can stop recording, delete meetings, disconnect a Google account, revoke Gappd in your Google Account permissions, change the summary provider, revoke macOS permissions, or uninstall Gappd. Contact leasemobil@gmail.com with privacy questions or requests.
11. Children
Gappd is a professional productivity tool and is not directed to children under 13.
12. Changes to this policy
This policy will be updated when Gappd’s data practices change. The effective date identifies the current version. Material changes will be disclosed before new data use begins.