Privacy Policy
Effective October 2, 2026 · Last updated October 2, 2026
- Your audio is transcribed as you talk and never saved.
- Your meetings live on your Mac. They reach our cloud only if you turn on sync or share them.
- We don’t sell or share your personal information for advertising, and we don’t use your meetings to train AI models.
- Cereal tells voices apart within a meeting but never identifies people by voice or keeps voiceprints.
- You can delete any meeting, or your whole account, from inside Cereal.
1. Who we are and what this covers
Pinto Labs Incorporated (“Pinto Labs”, “we”, “us”), based in San Francisco, California, makes Cereal: a Mac app that takes notes during your meetings, the Cereal service it connects to, and this website (together, “Cereal”). This policy explains how we collect, use and disclose personal information through Cereal, and your choices and rights. Our Terms of Service also apply.
If your organization gives you access to Cereal under a separate agreement with us, that agreement may also govern how we handle your information, and your organization may have its own policies.
2. Information we collect
Account information
You sign in with Google. We receive your Google account’s email address, name, profile photo and a Google account identifier, and create a Cereal account with an internal ID. We also keep your Cereal settings (such as appearance and privacy choices) with your account.
Meeting content
- Audio. When you record, audio from your microphone and, on calls, from your Mac’s sound is streamed over an encrypted connection to our service to be transcribed as the meeting happens. It’s processed in memory and never saved by us. Our transcription provider is configured not to keep it or use it for training.
- Transcripts, notes and recaps are created as you talk and saved on your Mac. To write and update notes, name the meeting and edit its recap, recent lines and notes are sent to AI services through our service. Notes you write on a calendar meeting’s page before it starts are saved on your Mac and go with the meeting once it’s recorded.
- People in a meeting. A meeting’s people are its calendar event’s attendees, if it has one, and anyone you add to it (by name, or picked from your teams). So their names are heard and written correctly, their names and company, never their email addresses, go to AI services with that meeting’s audio and notes, along with your own name. They’re never part of a web or image search.
- Lookups. When a topic comes up, recent lines and notes go to AI services that decide whether to show an explanation or a picture. Only a short public search phrase built from the topic, never your meeting’s words, is sent to web and image search. Explanations and pictures are saved with the meeting, as are pictures you add yourself.
- Sync. If you turn on “Sync transcripts and notes to the cloud”, finished meetings are stored in your Cereal account, encrypted with a key only the Cereal service can use, so you can restore them on another Mac.
Google Calendar (optional)
If you connect Google Calendar, Cereal reads the timed events on your primary calendar, read-only, to show your upcoming meetings. Events go from Google straight to your Mac and stay in its memory. The connection itself (your Google account and a token to read your calendar) is kept on your Mac. When you record a calendar meeting, its title, time, attendees and their company stay with that recording in your library, and in your synced copy if sync is on. To transcribe that meeting and write its notes and title accurately, its event title and its attendees’ names and company, never their email addresses, go through our service to AI services, as described in AI services; nothing else from your calendar does. Attendees and their company are never included when you share a meeting. To show attendees’ photos, Cereal sends our service a one-way hash of their email addresses, never the addresses themselves. Company logos are fetched from a public icon service using only the company’s web domain.
Sharing, invitations and teams
- A share link publishes a read-only copy of a meeting’s notes, and its transcript only if you add it, plus its pictures.
- Invitations: we store the email addresses you invite, their access level and responses, and send them an email naming you and the meeting’s date, never its title or content.
- Teams: we store members’ addresses and roles, the team’s name and logo, and a company domain that a member’s Google Workspace account proves.
- Faces: to show someone’s photo, Cereal sends our service a one-way hash of an email address it already has. The service answers only with the profile photo of someone who uses Cereal, never a name or an address, and keeps no record of the request.
Usage, diagnostics and device information
- We count what each account uses (note updates, audio minutes, lookups, invitations) to enforce fair-use limits. The counts contain no meeting content.
- If you turn on “Help improve Cereal”, the app sends timings, counts and fixed labels about how notes performed, under a random ID rather than your account, never meeting text, titles, names or hashes of text.
- Our systems record technical information needed to run and secure the service, such as IP address, app version, request times and error codes. Service logs don’t contain audio, transcripts, notes or credentials.
This website
When you sign in on the download page, we receive the same Google account information, to check whether you have beta access or to add you to the waitlist. We count page views on the home and download pages with analytics that don’t use cookies or track you across sites. Shared meeting pages and invitation pages have no analytics. We don’t use advertising cookies or trackers.
Communications
If you email us, we keep the message and your contact details to respond and keep records.
3. Voices and biometrics
In a room, Cereal tells voices apart within a meeting so the transcript can show who spoke when, marked by color. On a call, it only distinguishes you from the other side. Cereal doesn’t identify people by their voice, doesn’t name speakers, and doesn’t create, keep or use voiceprints or any other biometric identifier, and voices aren’t matched across meetings. Audio is used only to transcribe the meeting and tell its turns apart.
4. How we use information
- to provide Cereal: transcribe, write notes and recaps, sync, share, show your calendar and teams, and support you;
- to keep Cereal secure, prevent fraud and abuse, and enforce usage limits and our Terms;
- to understand and improve how well Cereal works, using diagnostic analytics you opted into and aggregated, de-identified information;
- to communicate with you about your account, the beta, security and changes, and, with your permission where required, about new features;
- to comply with law, respond to lawful requests, and establish or defend legal claims.
We don’t sell personal information, don’t share it for cross-context behavioral advertising, don’t use it for advertising, and don’t make decisions about you based solely on automated processing that have legal or similarly significant effects.
5. AI services
Cereal uses AI service providers to transcribe audio, write and update notes, name meetings, edit recaps and choose lookups. They receive only what each task needs (for a recorded meeting, that includes the names of the people in it, any notes you wrote on its page before it started and, for a calendar meeting, its event title), process it on our behalf under contract, and are configured not to store your content or use it to train their models wherever the provider offers that setting; lookup requests go only to providers’ zero-retention services. We don’t use your meetings to train AI models. Business customers can request a list of our AI service providers.
6. How we disclose information
- Service providers that process information on our behalf and under contract: cloud infrastructure and hosting, Google for sign-in and account services, email delivery, AI services, and web and image search (which receive only public search phrases).
- People you choose. Anyone with a share link can read what it contains; people you invite and your teams see what you share with them, and their invitation shows your email address. Your photo is shown to people who use Cereal and meet or share with you.
- Your organization, if you use Cereal under its account or team, as your settings and our agreement with it allow.
- Legal and safety. When we believe in good faith it’s required by law or legal process, or needed to protect the rights, property or safety of Pinto Labs, our users or others.
- Business transfers, as part of a merger, acquisition, financing or sale of assets, subject to this policy’s protections.
- With your consent or at your direction.
7. Google user data
Cereal’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google account and calendar data only to provide and improve the user-facing features described in this policy. We don’t transfer it except as needed to provide those features (a recorded meeting’s event title and attendees’ names and company go to AI services only to transcribe that meeting and write its notes), to comply with law, or as part of a merger or acquisition; don’t use it for advertising; don’t sell it; and don’t use it to develop, improve or train generalized AI or machine-learning models, or to generate images or other AI content. People at Pinto Labs don’t read it unless you ask us to for support, it’s needed for security or to comply with law, or it has been aggregated and made anonymous.
8. How long we keep information
| Information | How long |
|---|---|
| Audio | Not stored. Processed in memory while it’s transcribed. |
| Meetings on your Mac | Until you delete them. |
| Synced meetings | Until you delete the meeting, turn off sync (meetings you’ve shared stay until you stop sharing), or delete your account. |
| Share links and their pictures | Until you stop sharing, delete the meeting, or delete your account. |
| Invitations | Until accepted, declined, removed or expired (14 days), or the meeting is deleted. |
| Account information and settings | While your account exists. |
| Diagnostic analytics (opt-in) | Up to 18 months. |
| Service logs | 30 days. |
| Security audit records (no meeting content) | About 13 months. |
| Usage counts, and records of blocked accounts | Kept after an account is deleted, keyed to a one-way hash, so deleting can’t reset limits or undo a block. |
| Waitlist sign-ins and support emails | Until you ask us to delete them, or as long as needed to respond and keep records. |
We may keep information longer where the law requires it, or to resolve disputes and enforce our agreements.
9. Deleting and managing your data
- Delete Meeting removes a meeting, its share link and its synced copy.
- Settings → Your data → Delete all meetings does that for every meeting.
- Settings → Account → Delete account erases your account and everything our service holds for it (meetings, links, invitations, access to others’ meetings, settings, photo and your sign-in account), then your meetings on that Mac.
- Settings → Privacy turns sync and diagnostic analytics on or off. Disconnect Google Calendar in Settings → Connectors.
- You can also remove Cereal’s access to your Google account in your Google account settings, or email support@pintolabs.ai to ask us to delete your data.
We can’t delete Markdown files you exported, copies other people saved from what you shared, or your Mac’s own backups, such as Time Machine.
10. Security
We use administrative, technical and physical safeguards designed to protect personal information. Data is encrypted in transit. Synced meetings are encrypted at rest with a key only the Cereal service can use; our own staff can’t read them, and access to them is audited. On your Mac, meetings are protected by your Mac’s account and disk encryption. No method of storage or transmission is completely secure, and we can’t guarantee absolute security. If we learn of a breach affecting your personal information, we’ll notify you as the law requires.
11. Other people in your meetings
When a Cereal user records a meeting, we process the voices and words of the other people in it on that user’s behalf. The user decides what to record and share, and is responsible for giving any notice and getting any consent the law requires. If you were in a meeting someone recorded with Cereal, contact that person first; you can also email support@pintolabs.ai, and we’ll help where we can.
12. Children and teens
Cereal isn’t for children under 13, and we don’t knowingly collect personal information from them. If we learn we have, we’ll delete it. Teens under 18 may use Cereal only with a parent or guardian’s permission. If you’re a California resident under 18, you can remove content you shared publicly by stopping sharing or deleting the meeting in Cereal, or by emailing support@pintolabs.ai; removal doesn’t guarantee complete erasure of copies others made.
13. Your privacy rights
Depending on where you live, you may have the right to know what personal information we hold about you and how we use it, to get a copy (in a portable format), to correct it, to delete it, to opt out of its sale, sharing for targeted advertising or certain profiling (we don’t do these), and to not be discriminated against for using your rights. Residents of states including California, Colorado, Connecticut, Virginia, Utah, Texas and Oregon have these rights under their state laws.
- Most of this is built into Cereal. For anything else, email support@pintolabs.ai.
- We’ll verify your request, usually by confirming it came from the email address on your account, and respond within the time the law requires.
- You may use an authorized agent; we may ask for proof of their authority and confirm your identity with you.
- If we deny your request, you may appeal by replying to our decision. If we deny your appeal, you may contact your state’s attorney general.
14. California privacy notice
This section is for California residents and supplements this policy under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”). In the last 12 months, we collected the following categories of personal information:
| Category | Examples | Disclosed for business purposes to |
|---|---|---|
| Identifiers | Name, email address, account IDs, IP address | Service providers; people you share with |
| Customer records | Name, email address, profile photo | Service providers; people you share with |
| Audio and electronic information | Meeting audio (processed, not stored), transcripts, notes, pictures | Service providers (hosting, AI services); people you share with |
| Internet or network activity | App and service usage, diagnostic analytics, logs, website page views | Service providers |
| Professional information | Company domain and team; anything you say about work in a meeting | Service providers; your teams |
| Sensitive personal information | Contents of your meetings and calendar, which are communications | Service providers, only to provide Cereal |
- Sources: you and your devices; Google, when you sign in or connect Calendar; and people who share meetings or invite you.
- Purposes: as described in “How we use information”. Retention periods are described in “How long we keep information”.
- No sale or sharing. We don’t sell personal information or share it for cross-context behavioral advertising, and haven’t in the last 12 months, including of consumers under 16.
- Sensitive personal information is used only to provide Cereal and for other purposes the CCPA permits, not to infer characteristics about you, so no right to limit applies.
- Your rights: to know, access, correct and delete your personal information, to opt out of sale or sharing, and not to be discriminated against for exercising your rights. Exercise them as described in “Your privacy rights”; we’ll respond within 45 days, extendable once by 45 days with notice.
- Do Not Track and Global Privacy Control. Cereal doesn’t track you across other sites or apps. We treat a Global Privacy Control signal as a request to opt out of sale and sharing, which we don’t do anyway. We don’t respond differently to browser Do Not Track signals.
- Shine the Light. We don’t disclose personal information to third parties for their own direct marketing purposes (California Civil Code § 1798.83).
15. International users
We’re based in the United States, and we and our service providers process information in the United States and other countries whose data protection laws may differ from yours. Where the law requires, we use appropriate safeguards, such as standard contractual clauses, for transfers.
If you’re in the European Economic Area, the United Kingdom or Switzerland, we process your personal information to perform our contract with you (providing Cereal), for our legitimate interests (keeping Cereal secure, preventing abuse and improving it, balanced against your rights), with your consent (for example, optional sync, diagnostic analytics and Calendar, which you can withdraw at any time), and to comply with law. You have the rights described above, plus the right to restrict or object to processing and to lodge a complaint with your data protection authority.
16. Changes to this policy
We may update this policy. We’ll post the new version here with a new effective date and, for material changes, notify you in the app or by email before they take effect. Where the law requires your consent to a change, we’ll ask for it.
17. Contact
Pinto Labs Incorporated · San Francisco, California · support@pintolabs.ai