Privacy Policy
Last Updated: October 2, 2026
This Privacy Policy explains how Ready Sparkles, Inc., a Delaware corporation operating Ready ("Ready," "we," "us") collects, uses, shares, and protects personal information in connection with the Ready application, the website at ready.app, and all related services, features, AI agents, automations, and integrations (collectively, the "Service").
Ready is currently in beta. Our Terms of Use govern use of the Service. This Privacy Policy explains our data practices; it is not a request for consent. Where consent is required, we obtain it separately.
If you have questions, contact us at info@ready.app.
1. Scope and Roles
This Privacy Policy applies to:
- Account holders - people who sign up for and use Ready ("Users").
- Meeting participants - people who join meetings hosted by Users that include the Ready AI assistant.
- Visitors - people who browse ready.app.
For meeting content (recordings, transcripts, AI outputs), Users act as the controller of that content for their meetings, and we process it on Users' behalf in order to provide the Service. Users are responsible for the lawfulness of the meetings they host and for obtaining any consents required from meeting participants (see our Terms of Use, Section 5). Where required by law, we will enter into a data processing agreement with Users.
For account information, billing data (where applicable), service operations, and security, Ready Sparkles, Inc. is the controller.
2. Information We Collect
2.1 Information You Provide
- Account information. When you sign up using Google or Microsoft OAuth, we receive your name, email address, profile image, and the unique account identifier from the provider, along with the OAuth scopes you authorize.
- Profile and configuration data. Settings, preferences, AI agent configurations, automation workflows, and any custom prompts or instructions you provide.
- Communications. Messages you send us (e.g., support emails, beta feedback).
- Billing information. If you purchase a paid plan or credits, we process customer and billing contact details, subscription and transaction records, invoices, and payment status. Payments are handled through Stripe.
2.2 Information from Connected Integrations
When you authorize Ready to connect to third-party services - including Google (Google Calendar and Gmail), Microsoft (Outlook Calendar and Outlook Mail), Linear, or other tools you connect - we access only the data and capabilities you grant via that service's OAuth consent flow, and only as needed to provide the features you use.
2.3 Meeting Content
Every Ready meeting is automatically recorded, transcribed, and processed by AI as a core function of the Service. As a result, we process:
- Audio and video captured from meetings the Service joins;
- Transcripts generated from that audio;
- Meeting metadata such as participant names, email addresses, timestamps, calendar event details, and meeting titles;
- AI outputs such as summaries, notes, tasks, extracted entities, coaching feedback, and other generated content;
- Files and content shared in the meeting if processed by the Service.
We process meeting content to provide the AI assistant during the meeting, generate transcripts and summaries, run post-meeting workflows you configure, and otherwise deliver the Service.
Meeting Memory and People Profiles
Ready can save details derived from meetings in a participant's private memory, including People profiles that bring together information about people they have met across conversations. These may include names, name variants, meeting history, and facts or summaries supported by meeting content. Each memory belongs to its account holder within their workspace; it is not a public directory or shared automatically with everyone in that workspace. Access remains subject to the holder's permissions to the underlying meeting content.
Memory uses meeting content on the account holder's behalf. The account holder is responsible for an appropriate lawful basis and any required participant permissions. This notice does not itself obtain consent to recording or memory processing. Memory content can be forgotten using the memory controls. Deleting underlying meeting content removes or invalidates the memories supported by it. We retain remaining memory and profile information for as long as needed to provide the feature, subject to deletion requests and applicable retention obligations. Participants can contact the meeting host or info@ready.app to request access, correction, deletion, or exercise applicable rights described in Section 10.
Optional Guest Browser Recognition
Where available, guests may choose “Remember me next time” before asking to join. If you opt in, Ready stores a first-party recognition cookie containing a random identifier and records your choice, its wording version, timestamp, and guest identity on our servers. We use it to associate future guest visits from that browser with one person in each relevant participant's private memory. Your last-used name is filled in when you return and can be edited. Entered names are retained as aliases; the cookie grants no access to earlier meetings. If you link a verified guest session to an account, existing private profiles can use your account name and photo and connect future meetings to the same person.
The cookie expires one year after consent and is not extended by subsequent visits. Recognition applies to everyone using the same browser, even when they enter different names, so only enable it on a personal browser. You can join without enabling it. Turn it off before joining by unchecking “Remember me next time”; this revokes the identifier and removes the cookie. Clearing cookies also prevents that browser from presenting the identifier. Turning recognition off stops future recognition; it does not automatically delete original meeting records or historical profile associations. You can separately request deletion or correction as described above. Material changes to this recognition purpose require a new choice.
2.4 Usage, Device, and Log Information
- Device and technical information such as IP address, browser type, operating system, device identifiers, and language settings.
- Usage data such as features used, pages viewed, actions taken, and timestamps.
- Log and diagnostic data for security, debugging, abuse prevention, and reliability.
Analytics and advertising measurement
If you allow analytics, we use Google Analytics to measure visits, account creation, first completed meetings, and confirmed purchases, and connect these events to Google Ads campaigns. We send a pseudonymous account identifier, campaign information, and purchase amounts, not your name, email, meeting content, or private page URLs. Advertising personalization is disabled. Google also processes browser and device information as described in its privacy policy.
We retain first-visit and latest campaign information in a first-party cookie for up to 90 days. At signup, we attach this information to your account so we can understand which campaigns lead to active and paying customers. You can change your choice using Analytics preferences on this page. Opting out stops future analytics delivery; it does not remove billing records or information already collected. We honor Global Privacy Control for this optional analytics collection.
2.5 Cookies and Similar Technologies
We use cookies and similar technologies to keep you signed in, remember preferences, secure the Service, and understand usage. Where available, we also offer optional guest recognition as described above, enabled only after your opt-in. We do not sell your data for advertising. You can control cookies through your browser settings, though some features may not work without them.
3. How We Use Information
We use the information described above to:
- Provide the core Service, including hosting meetings, recording, transcribing, generating summaries, running AI agents, and executing automated workflows;
- Authenticate Users and secure accounts;
- Maintain, debug, monitor, and improve the Service (including aggregate, de-identified usage analysis, prompt and reliability tuning, UX improvements, and safety measures);
- Communicate with you about the Service, including beta updates, bug responses, and important notices;
- Detect, investigate, and prevent fraud, abuse, security incidents, and violations of our Terms of Use;
- Comply with legal obligations, respond to lawful requests, and enforce our agreements.
We do not use customer meeting audio, video, transcripts, prompts, files, or AI outputs to train our own general-purpose AI models. We also configure our AI providers, where available, so that data sent via their APIs is not used to train their models.
We may use aggregate or de-identified data, logs, and feedback to improve the Service, refine prompts, improve reliability and UX, and improve safety - but not to train foundation models on user meeting content.
4. Legal Bases for Processing (EEA / UK Users)
If you are in the European Economic Area or United Kingdom, we rely on the following legal bases under the GDPR / UK GDPR:
- Performance of a contract - to provide the Service you requested under our Terms of Use.
- Legitimate interests - to operate, secure, and improve the Service; prevent fraud and abuse; and communicate with Users about the Service. We balance these interests against your rights and freedoms.
- Consent - where required (for example, certain optional features or specific data uses). You may withdraw consent at any time.
- Legal obligation - where processing is required by applicable law.
For meeting content processed on a User's behalf, the User is responsible for establishing the legal basis for processing under applicable law, including obtaining any required consents from meeting participants.
5. Sub-processors and Third Parties We Share With
We use the following providers to operate the Service. Providers acting as processors or sub-processors handle personal data on our instructions under applicable data processing, confidentiality, and security terms. Payment, authentication, and connected service providers may also act as independent controllers for their own purposes, such as fraud prevention or legal compliance, as described in their privacy policies.
| Provider | Purpose | Location |
|---|---|---|
| Stripe | Payment processing, checkout, subscription billing, and invoices | United States / global infrastructure |
| Railway | Application hosting and Postgres database | United States |
| LiveKit Cloud | Real-time meeting infrastructure, media transport, room services, and LiveKit Inference transcription | United States |
| OpenAI | AI processing for summaries, extraction, Tasks, mail classification and summaries, meeting briefs, assistant workflows, and related generated outputs | United States |
| Parallel | Meeting preparation and web research enrichment where enabled | United States |
| Ably | Realtime event delivery for app updates and browser sessions | United States / global infrastructure |
| OAuth authentication and authorized Google Calendar and Gmail integrations | United States / global infrastructure | |
| Microsoft | OAuth authentication and authorized Outlook Calendar and Outlook Mail integrations | United States / global infrastructure |
| Linear | User-authorized issue and task integration | United States / global infrastructure |
We may also share information:
- At your direction - for example, when you authorize an automated workflow to send an email, create a calendar event, or update a record in a connected service.
- With law enforcement or in response to legal process - where required by valid legal process or to protect rights, safety, property, or to comply with applicable law.
- In the event of a business transfer - if we transition the Service to another operator or transfer the Service, information may be transferred as part of that transaction, subject to confidentiality, applicable law, and the privacy commitments made when the information was collected. We will provide required notices and obtain any required consent. Google user data remains subject to Section 6 below.
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.
This sub-processor list may change as the Service evolves. We will update this policy when we add or replace material sub-processors.
6. Google API Services User Data Policy and Limited Use
Ready's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We use Google user data only to provide or improve user-facing features of Ready that are prominent and requested by the User.
- We do not transfer Google user data to third parties except as necessary to provide or improve those user-facing features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with the User's consent.
- We do not use Google user data for serving advertisements.
- We do not allow humans to read Google user data, except (a) with the User's affirmative agreement for specific messages, (b) as necessary for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) where the data has been aggregated and de-identified for internal operations consistent with the User Data Policy.
The same principles apply to our handling of Microsoft user data.
7. International Transfers
We are based in the United States, and our sub-processors primarily process data in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States and other countries that may have different data-protection laws than your country.
For transfers of personal data from the EEA, UK, or Switzerland, we rely on appropriate safeguards permitted by applicable law, such as the European Commission's Standard Contractual Clauses (SCCs), the UK Addendum, or equivalent mechanisms offered by our sub-processors. You may request more information about these safeguards by contacting us.
8. Data Retention
We retain personal information only as long as needed for the purposes described in this policy, then delete or de-identify it. Specifically:
- Temporary audio and recording segments - retained only as long as needed to generate and improve transcripts, then automatically deleted. In any event, raw audio is deleted within 30 days.
- Transcripts, notes, Tasks, AI outputs, and meeting metadata - retained until the User deletes the meeting, deletes the workspace, deletes their account, or requests deletion. Users can delete this content at any time.
- Account information - retained while the account is active and deleted (or de-identified) within a reasonable period after account deletion, except where retention is required by law.
- Logs and diagnostic data - retained for up to 90 days for security, debugging, abuse prevention, and reliability.
- Backups - automated backups may persist for a limited additional period before standard deletion cycles complete; deleted data is not actively retrieved from backups but is overwritten in the normal course.
We may retain limited information longer where required by law, to resolve disputes, or to enforce our agreements.
9. Security
We use reasonable administrative, technical, and organizational measures to protect personal information, including encryption in transit (TLS), encryption at rest where supported by our sub-processors, access controls, OAuth-based authentication, and monitoring.
However, no system is perfectly secure. You should not transmit highly sensitive data (such as protected health information, regulated financial data, or government-classified information) through the Service. If you become aware of any security issue, please contact us at info@ready.app.
10. Your Rights
10.1 Rights in the EEA, UK, and Switzerland
If you are in the EEA or UK, you may have the following rights under the GDPR or UK GDPR, subject to applicable limits. Residents of Switzerland may have similar rights under Swiss data protection law:
- Access - request a copy of personal data we hold about you.
- Rectification - correct inaccurate or incomplete data.
- Erasure - request deletion of your data ("right to be forgotten").
- Restriction - limit how we process your data in certain circumstances.
- Portability - receive your data in a structured, commonly used, machine-readable format.
- Objection - object to processing based on legitimate interests.
- Withdraw consent - where processing is based on consent, withdraw it at any time without affecting prior lawful processing.
- Lodge a complaint - with your local data protection authority (e.g., the UK ICO, the Irish DPC, or the authority in your country of residence).
To exercise these rights, contact us at info@ready.app. We may need to verify your identity before responding.
10.2 Rights Under California Law (CCPA / CPRA)
If you are a California resident, you have the following rights, subject to applicable limits:
- Right to know what personal information we collect, use, disclose, and (if applicable) sell or share.
- Right to access and portability - request a copy of your personal information.
- Right to delete personal information we hold about you.
- Right to correct inaccurate personal information.
- Right to limit use of sensitive personal information in certain circumstances.
- Right to opt out of "sale" or "sharing" of personal information for cross-context behavioral advertising. We do not sell or share personal information for cross-context behavioral advertising.
- Right to non-discrimination for exercising your rights.
You may exercise these rights by contacting us at info@ready.app. You may also designate an authorized agent to act on your behalf.
10.3 Rights for Other Jurisdictions
Residents of other jurisdictions (such as Virginia, Colorado, Connecticut, Texas, Brazil, and Canada) may have similar rights under applicable law. Contact us to exercise any rights you have.
10.4 Meeting Participants
If you are a meeting participant (not a Ready User) and want to exercise rights regarding meeting content, please contact the meeting host first, as they are the controller of that content. You may also contact us, and we will assist where required by law and where we can identify your data.
11. Children
The Service is not directed to, and we do not knowingly collect personal information from, anyone under 18 years of age. If you believe a child has provided personal information through the Service, contact us and we will delete it.
12. Automated Decision-Making and AI
The Service uses AI to generate transcripts, summaries, Tasks, suggestions, drafted communications, and other outputs. These outputs are intended to assist you and are not solely automated decisions producing legal or similarly significant effects on you within the meaning of GDPR Article 22. AI output may be inaccurate, incomplete, or biased - you are responsible for reviewing it before relying on it. See our Terms of Use, Section 7.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top and provide email or in-app notice as required by law, in advance where required. We will obtain any consent required before using personal information for a new purpose or in a way that is materially inconsistent with the commitments made when it was collected. Continued use of the Service does not substitute for that consent or waive your privacy rights.
14. Contact
For questions, concerns, or to exercise any rights described in this policy:
Email: info@ready.app
Operator: Ready Sparkles, Inc.
Thank you for trying Ready during beta. Your trust matters, and we'll handle your data accordingly.