Legal
Privacy Policy
In short
- Upshot is a desktop application that runs on your own Windows computer. Your recordings, transcripts and summaries are stored there.
- AM Consulting, which makes Upshot, does not run a server that receives your data. We never receive your recordings, transcripts, summaries or Google data.
- Audio is transcribed on your computer and is never uploaded.
- To write a summary, the text of a meeting is sent to the AI provider you choose. If you choose a local model, nothing leaves your computer.
- If you connect Google Calendar, Upshot only reads your events, on your computer, to notice and name your meetings. It does not share calendar data with anyone, including AI providers.
1. Who we are
Upshot is made by AM Consulting (“AM Consulting”, “we”, “us”), based in Israel. This policy explains how the Upshot desktop application (“Upshot” or “the app”) and this website handle information. You can reach us at office@amconsultingai.com.
2. How Upshot works
Upshot records your meetings on your own computer, transcribes them there, and writes a summary. It runs entirely on your computer and has no account system: you do not sign up with us, and we do not operate any server that receives information from the app.
The app does not send usage statistics, analytics or crash reports to us or anyone else.
3. Information Upshot processes
All of the following is created and kept on your computer, in a data folder you choose:
- Audio recordings of your microphone and of the sound your computer plays during a meeting.
- Transcripts, produced on your computer by a speech-recognition model.
- Summaries, written by the AI provider you choose (see section 5).
- Meeting details such as the time, duration and title, and, if you connect Google Calendar, the event details described in section 4.
- Settings, including your choice of devices and providers. API keys, passwords and sign-in tokens you enter are stored in Windows Credential Manager, not in plain files.
- Meeting detection: to notice that a meeting has started, Upshot checks on your computer which application is using the microphone, the window title and whether the camera is on. This information stays on your computer.
4. Google user data
Upshot can optionally connect to your Google Calendar. This section describes exactly what happens if you do. If you do not connect a Google account, Upshot accesses no Google user data.
4.1 Data we access
Upshot requests one permission (OAuth scope):
https://www.googleapis.com/auth/calendar.events.readonly: read-only access to the events in your Google Calendar.
With it, Upshot reads, for each event: the title, start and end time, the organizer and attendees (names and email addresses), the description, the location and any video-conference link. Upshot cannot create, change or delete anything in your calendar, and it does not access your email, contacts, files or any other Google data.
4.2 How we use it
Upshot uses your calendar data only to provide these features to you, on your computer:
- to know when your meetings are scheduled, so it can get ready to record them;
- to give each recorded meeting its title and time; and
- to show who was invited, alongside the meeting, in your timeline.
Calendar data is not used for any other purpose.
4.3 How we store and protect it
Calendar data is fetched directly from Google to your computer. The sign-in token Google issues is stored in Windows Credential Manager. Event details are stored with the matching meeting in your local data folder. AM Consulting never receives your calendar data or your token.
4.4 How we share it
Upshot does not transfer or disclose your Google calendar data to AM Consulting or to any third party, including the AI providers that write summaries. It is not sold, and it is not used for advertising.
4.5 Retention and deletion
Event details stay with the meeting on your computer until you delete that meeting in Upshot. You can disconnect Google Calendar at any time in Upshot's settings, which deletes the stored token; Upshot then stops reading your calendar. You can also revoke Upshot's access in your Google Account at myaccount.google.com/permissions. Uninstalling Upshot and deleting its data folder removes everything it stored.
4.6 Limited Use
Upshot's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular:
- We use Google user data only to provide and improve the user-facing features described above.
- We do not transfer Google user data to others, except as needed to provide those features, to comply with applicable law, or as part of a merger, acquisition or sale of assets with notice to you. Because the data stays on your computer, none of these transfers happen today.
- We do not use or transfer Google user data to serve advertisements, including retargeting, personalized or interest-based advertising.
- We do not sell Google user data.
- No person at AM Consulting reads your Google user data. We would only do so with your explicit consent (for example, if you send it to us for support), for security purposes such as investigating abuse, to comply with applicable law, or where it has been aggregated and anonymized for internal operations.
- We do not use Google user data to develop, improve or train generalized or non-personalized artificial-intelligence or machine-learning models.
5. Services you choose to connect
Some features work by connecting, from your computer, to a service you choose. When you use one, that service receives the data described below directly from your computer, under your own account, and handles it according to its own terms and privacy policy. AM Consulting does not receive this data.
- AI summary providers. To write a summary, Upshot sends the meeting transcript and your summary instructions to the provider you select: Anthropic (Claude, through the API or through Claude Code on your own subscription), OpenAI or Google Gemini. If you select Ollama, the summary is written by a model running on your computer and nothing is sent. Audio is never sent to these providers.
- Email. If you set up email delivery, Upshot sends summaries through the email server and account you configure.
- Model downloads. On first use, Upshot downloads speech-recognition models from Hugging Face and, if you enable speaker separation, its models from Hugging Face and GitHub. These downloads send no meeting data; like any web request, they reveal your IP address to the host.
6. Storage, retention and deletion
Everything Upshot creates is stored in your data folder on your computer. By default, raw audio recordings are deleted automatically after 30 days, while transcripts and summaries are kept until you delete them. You can change these periods in Upshot's configuration, delete any meeting in the app at any time, or delete the data folder entirely.
7. Security
Upshot's interface runs only on your own computer (at 127.0.0.1) and requires a per-installation key before it shows anything. API keys, passwords and sign-in tokens are kept in Windows Credential Manager. Recordings and transcripts are regular files in your data folder, so they are protected by your computer's own security; we recommend turning on full-disk encryption such as BitLocker.
8. Your choices and rights
Because your data is on your computer, you control it directly: you can open, copy and delete it at any time, disconnect any connected service, and revoke Google access as described in section 4.5. We do not hold personal data about Upshot users, so there is normally nothing for us to access, correct or delete on your behalf. If you contact us, we use your message and email address only to reply, and you can ask us to delete them. Depending on where you live, you may have rights under data-protection laws such as the Israeli Privacy Protection Law or the GDPR; to exercise them, contact us.
9. Recording other people
Recordings include the voices of the other people in your meetings. The laws on recording conversations differ between countries and states, and some require everyone's consent. You are responsible for informing participants and obtaining any consent the law requires. See our Terms of Service.
10. Children
Upshot is not directed at children under 16, and we do not knowingly collect personal data from them.
11. This website
This website uses no cookies and no analytics. It remembers your language choice in your browser only. It is hosted by GitHub Pages and loads fonts from Google Fonts and style files from jsDelivr; like any website host, these services receive your IP address and browser details when you visit, under their own privacy policies.
12. Changes to this policy
If we change this policy, we will publish the new version on this page. If a change materially affects how Upshot handles your data, and in particular Google user data, we will describe it in the app before it takes effect.
13. Contact us
AM Consulting
Email: office@amconsultingai.com
Website: www.amconsultingai.com