Privacy Policy
Кратко по-русски. ProductHub Drive Sync — служебная интеграция ProductHub, которая сохраняет расшифровки звонков из Granola в папку на Google Drive, принадлежащую ProductHub. Приложение обращается к Google Drive только для того, чтобы создавать markdown-файлы в одной папке, проверять её на дубли и обновлять один индексный файл. Данные из Google не передаются третьим лицам, не продаются, не используются для рекламы и обучения моделей. Доступ можно отозвать в любой момент в настройках Google-аккаунта.
This Privacy Policy describes how ProductHub (“we”, “us”) handles information in connection with ProductHub Drive Sync (the “Integration”), an internal tool that uses Google APIs. The Integration is operated for ProductHub's own team and connects to a Google account owned by ProductHub. It is not offered to the general public.
1. What the Integration does
The Integration receives webhook notifications from Granola (a meeting note-taking service) when a meeting recorded by a ProductHub team member ends. It then retrieves the meeting's summary and transcript from Granola's API, formats them as a Markdown document, and stores that document in a designated folder of ProductHub's Google Drive. It also maintains an index file in the same folder.
2. Google user data we access
The Integration uses the Google Drive API with the https://www.googleapis.com/auth/drive scope on behalf of ProductHub's own Google account. In practice it performs only the following operations:
- creates Markdown files in one designated folder (“Product Hub Core / Meeting notes”);
- searches that folder and file metadata (name, application properties) to detect duplicates;
- reads and updates one index file in that folder.
It does not read, modify, share or delete any other files in the account, does not access Google contacts, email, calendar or profile information, and does not download Drive content to any external destination.
3. Other information we process
To produce the transcript files, the Integration processes data received from Granola: meeting title, date and time, participant names and email addresses as recorded in the calendar event, the AI-generated summary and the transcript text. This information is written to the Google Drive file described above. For troubleshooting, the Integration keeps an operational log (webhook payloads, note identifiers, processing status and error messages) in a database operated by ProductHub on Supabase.
4. How we use the information
The information is used solely to create and maintain the ProductHub team's internal archive of meeting transcripts, so that team members and the AI assistants they use can find and read those transcripts. We do not use Google user data for advertising, for profiling, for training machine-learning or AI models, or for any purpose unrelated to the function described above.
5. Sharing and disclosure
We do not sell, rent or otherwise transfer Google user data to third parties. Data is processed by the infrastructure providers that run the Integration (Supabase for the server function and log database, Google for Drive storage) under their respective terms. Data may be disclosed if required by law.
6. Google API Services User Data Policy — Limited Use
ProductHub Drive Sync's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7. Storage, security and retention
Transcript files are stored in ProductHub's Google Drive and remain under ProductHub's control there. Authorization credentials (OAuth client secret and refresh token) are stored as encrypted secrets in Supabase and are never exposed in client-side code or shared with third parties. All communication with Google and Granola uses TLS. Operational logs are retained for troubleshooting and may be deleted periodically; Drive files are retained until ProductHub removes them.
8. Revoking access and deletion
Access granted to the Integration can be revoked at any time from the Google account's permissions page at myaccount.google.com/permissions. Revoking access immediately stops the Integration from writing to Google Drive. Files already created remain in the Drive folder and can be deleted there. Meeting participants who wish to have a transcript or log entry that mentions them removed can contact us at the address below.
9. Changes to this policy
We may update this Privacy Policy from time to time. The current version is always available at this address, together with its effective date.
10. Contact
ProductHub · producthub.ru · hey@thisnikita.com