Privacy Policy

Last updated: September 2, 2026

OffBook is a trade name of OB Labs LLC, a Delaware limited liability company.

Data we collect

We collect account details, profile information, transcripts, coaching cues, and debrief outputs to operate OffBook.

Google user data we access

If you choose "Continue with Google" to sign up or log in, OffBook accesses basic Google account identity data through Firebase Authentication, including your email address, profile name, profile photo URL (if available), Google account user ID/sub identifier, and authentication token metadata needed to validate your session.

OffBook does not request or access Gmail message content, Google Drive files, or Google Contacts as part of sign-in. If you separately connect Google Calendar in Settings, OffBook reads calendar event metadata (title, time, attendees, location, meeting links, and invite descriptions) to send pre-call reminders and prefill call setup. We do not read your inbox.

Calendar connections (optional)

When you connect Google Calendar or Microsoft Outlook, OffBook syncs upcoming meetings for the next several hours. We use event titles, times, attendee emails, locations, conferencing links, and invite body text to identify external meetings, send reminders, and prefill your call context. We do not access email inboxes or modify calendar events.

How we use Google user data

  • - Authenticate your account and create a secure OffBook session.
  • - Link your OffBook account to your verified Google identity to prevent unauthorized access.
  • - Prefill account identity fields (for example, email and display name) during onboarding and access control.
  • - Detect abuse and maintain account security using authentication metadata.
  • - When Google Calendar is connected: sync upcoming meetings, send optional pre-call reminders, and prefill call setup / pre-call brief context for you.

We do not sell Google user data and we do not use Google user data for advertising. Google user data is used only for the limited purposes described in this policy.

Google Workspace API Limited Use compliance

OffBook's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

Specifically:

  • - We do not use, transfer, or sell Google Workspace user data—including raw, aggregated, or derived data—to create, train, or improve foundational or generalized machine learning or artificial intelligence models.
  • - Calendar and other Workspace data are used only to provide or improve user-facing features in OffBook (for example, upcoming meetings, pre-call reminders, and call setup / brief context).
  • - When Workspace-derived data is sent to a third-party AI/ML provider for inference (for example, generating a pre-call brief), it is used only to deliver that feature for your account and is not used by OffBook or permitted to be used by providers to train foundational or generalized models.
  • - We do not allow humans to read Workspace user data except as permitted under Limited Use (for example, with your consent, for security, or to comply with law).

How we protect sensitive data

OffBook treats account credentials, OAuth tokens, calendar event metadata, transcripts, and related coaching artifacts as sensitive. We protect this data with the following mechanisms:

  • - Encryption in transit: data exchanged between your browser, OffBook services, and subprocessors is transmitted over TLS/HTTPS.
  • - Encryption at rest: application data is stored in managed databases and infrastructure that encrypt data at rest. Calendar OAuth access and refresh tokens are encrypted before storage using application-level encryption keys.
  • - Access controls: calendar connections and synced events are scoped to your authenticated OffBook account and profile. Administrative access to production systems is limited to authorized personnel and protected with strong authentication.
  • - Least privilege for Google scopes: Google Calendar connect requests read-only calendar event access (`calendar.events.readonly`) plus basic OpenID identity scopes. We do not request Gmail, Drive, or Contacts scopes.
  • - Vendor controls: we use subprocessors (including Anthropic, Deepgram, Vercel, Neon, Firebase, Stripe, and PostHog) under contractual and technical controls appropriate to their role. Additional detail is published on our Security page.
  • - Deletion: you can disconnect Google Calendar at any time in Settings, and permanently delete your account and associated workspace data from Settings → Call preferences → Delete account.

Storage, sharing, and retention

We use service providers including Anthropic, Deepgram, Vercel, Neon, Firebase, Stripe, and PostHog to deliver OffBook. Google sign-in identity data is processed by Firebase Authentication and stored in OffBook systems as needed to maintain your account and session history. Synced Google Calendar events are stored so we can show upcoming meetings and send reminders; they are refreshed on a rolling short window and removed from OffBook when they fall outside that window or when you disconnect or delete your account.

We retain transcript and coaching artifacts in your account until you delete them or delete your account. You can permanently delete your account and associated workspace data from Settings → Call preferences → Delete account. Stripe may retain billing and payment records separately under its own retention policies. Account identity data is retained while your account is active and for a limited period afterward as required for security, fraud prevention, legal compliance, and audit obligations.

Model and privacy boundaries

We do not train models on your customer audio or transcripts by default, and we do not permit our providers to use your customer audio or transcripts to train public models.

During a call, prompts and coaching are shown only to you. We do not transmit prompts or hidden coaching to the other party.

OffBook may update your own profile and model context from your usage history and generalized call outcomes (for example, whether a call felt positive or stalled). We do not use the other party's personal information as training data.

Where AI/ML features process Google Workspace-derived data (for example, calendar title, attendees, or invite text used to generate a pre-call brief), that processing is limited to providing the feature to you and is subject to the Limited Use compliance section above.

Your choices and requests

You are responsible for sharing only information you are authorized to process. You can delete your account and associated workspace data from Settings → Call preferences → Delete account. For data export or other privacy requests, contact [email protected].