← Back to Cadenva

Privacy Policy

Your data stays yours.

Effective: September 2026

Recordings deleted after processing

Your recording is deleted from our servers as soon as processing finishes, whether it succeeded or failed.

We never train on your data

Your meeting content is never used to train any AI model — ours or anyone else's.

Nothing scheduled without you

Every action requires your explicit approval before it reaches your calendar.

Delete your data anytime

Email hello@cadenva.com and we will remove everything we hold, confirmed within 48 hours.

What we collect

When you upload a recording or paste a transcript, we process the audio or text to extract action items, owners, and deadlines. We store the actions you review and the calendar events you approve. Raw recordings are deleted once processing finishes.

How long we keep it

Your recording is deleted as soon as processing finishes, whether it succeeded or failed. The transcript, the actions extracted from it and the approvals you make are kept in your workspace so they are still there when you come back — they are not cleared at the end of a session. To have them removed, email hello@cadenva.com and we will confirm and complete deletion within 48 hours.

We do not train on your data

Your meeting content is never used to train any AI model — ours or anyone else's. We do not sell or license your data and we do not use it for advertising. The only parties that receive it are the service providers listed below, and only so they can run Cadenva.

Third-party processors

We use the following services to operate Cadenva. Each receives only what it needs to do its job — none receive your meeting data beyond what is necessary for processing.

OpenAITranscribes the recordings and notes you submit and extracts action items from them. Processes data under a DPA that prohibits training on API-submitted content. Cadenva does not use Google Calendar event data to train or improve artificial intelligence models.
GoogleReads your upcoming events so we can show what is coming next, and creates the events you approve. See “Google Workspace API data” below.
RailwayRuns the Cadenva backend and hosts its database, so it holds everything we store — including encrypted Google credentials and the calendar identifiers we keep.
Backblaze B2Stores off-site backups of that database. Backups contain the same encrypted credentials and identifiers.
VercelHosts the web application and serves web traffic. Does not process meeting content.
SentryReceives error diagnostics when something fails. Reports carry error types and request identifiers, not credentials or meeting content.
StripeHandles payments. Stripe receives no meeting content, recordings, action data, or Google data.

Google Workspace API data

What we access

If you connect Google Calendar, Cadenva asks for three permissions: access to your calendar events, and your Google account email and basic profile. The calendar permission covers both reading and writing events — it is a single permission Google does not split.

Why we use it

We read your upcoming events so the app can show what meeting is next and let you start a capture from it. We create, update and delete calendar events only for actions you have explicitly approved. We use your email and profile to show which Google account is connected. We do not use Google data for advertising, and we do not sell or license it.

What we store

We store your Google credentials, the email and name of the connected account, and the event identifier and link for events Cadenva created so it can update or remove them later. If you start a capture from a meeting, we store that meeting's title and event identifier alongside it. We do not keep a copy of your calendar: events we read to show your next meeting are fetched when you open the app and are not written to our database.

How it is protected

Google credentials are encrypted by the application before they are written to the database, and the service refuses to start in production without its encryption key configured. All traffic runs over HTTPS. Google data is reachable only through the workspace it belongs to: every request is checked against the workspace the caller is authenticated for, so one workspace cannot read or write another's calendar data. Credentials are held in server-side configuration rather than in our source code, and our logs and error reports record error types and identifiers rather than tokens, calendar contents or account emails.

Who else receives it

Google data is not sold, and it is not shared for advertising. It is disclosed only to the service providers listed above that run Cadenva — Railway, which hosts the backend and database, and Backblaze B2, which stores encrypted off-site backups of that database — and to Sentry if an error report is generated. Cadenva does not use Google Calendar event data to train or improve artificial intelligence models. We may also disclose data where we are legally required to.

Your control

You can disconnect Google from within Cadenva, which deletes the stored credentials, and you can revoke access at any time in your Google Account settings. Events Cadenva already created stay in your calendar and are yours to keep or delete. To have the remaining records we hold removed, email hello@cadenva.com.

Limited Use

The use and transfer of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Your rights

You can request deletion of all your data at any time by emailing hello@cadenva.com. We will confirm and complete deletion within 48 hours. You may also ask what data we hold, request a copy, or ask us to correct anything inaccurate.

Contact

Questions? Email hello@cadenva.com. We respond within one business day.