Privacy policy
Effective August 6, 2026.
Squall (“we”, “us”) builds a meeting HUD and operates squallapp.ai (the “website”). This policy describes what we collect, what stays on your device, and how we use information when you use the website or the Squall app.
Summary
- Meeting content stays local. Audio, transcripts, screenshots, calendar events, and provider credentials you configure in the app are stored on your device unless you export them or send them to a third-party service you choose.
- Account and telemetry sync to Squall cloud. Sign-in connects your account. The app sends redacted usage and diagnostic events — not meeting content.
- You control third-party AI and transcription. Requests to providers you configure (for example Speechmatics or an LLM) go from your device using credentials you supply. Some consumer subscription plans may use what you send to train their models — see AI and transcription providers.
Information we collect
Website
- Email sign-ups — if you join the mailing list on the homepage, we store your email address.
- Account data — when you create an account, we store identity information through our auth provider (email address, and profile details from Google or GitHub if you use those sign-in methods). You may opt in to product news and promotions at sign-up; that preference is stored on your profile.
- Access and download activity — we record access requests, account access status, and release download events tied to your account.
- Site analytics — aggregate traffic measurement on the website. We do not use advertising cookies.
Squall app
- Account identity — your signed-in email and sign-in method, to authenticate you and manage product access.
- Product telemetry — redacted usage events (for example audio seconds processed, token counts, job types). Live-agent names are hashed before upload.
- Diagnostics — redacted error and log lines to help us fix bugs.
- Meeting-detection audit — coarse signals that meeting detection ran. We do not upload window titles, meeting names, or transcript text.
What stays on your device
The app stores the following locally on your device:
- Transcripts and session metadata
- Session audio recordings and voice samples
- Credentials for the providers and calendars you configure
- Calendar events from the calendars you connect
- Screenshots, live-agent definitions, and other session files you create
Squall cloud does not receive your meeting audio, transcripts, screenshots, calendar data, or provider credentials. Providers you configure yourself are a different matter, and do receive some of this content — see AI and transcription providers for what each one gets.
Calendars
Squall reads your calendar so it can match a recording to the meeting you are in and pre-fill the session title and participants. It reads event titles, times, locations, and attendee names or email addresses. Calendar events and calendar credentials are stored on your device, and Squall cloud does not receive them.
If you enable meeting summaries, chat, or live agents, the matched meeting title and attendee names are sent to the AI provider you configured, together with the transcript. See AI and transcription providers below. To keep that content on your machine, use a local model or disconnect the calendar.
If you connect Google Calendar, Squall requests read-only access to list calendars and read events. We do not sell Google user data or use it for advertising. Disconnect in Settings → Calendars, or revoke at Google Account permissions. Our use of Google user data complies with the Google API Services User Data Policy, including Limited Use requirements.
AI and transcription providers
Squall does not operate its own AI service. When you configure a provider, the app connects to it directly from your device using credentials you supply, and that provider’s terms govern what happens to the data.
- Speechmatics — receives meeting audio for transcription and speaker identification. Required for recording.
- Anthropic, OpenAI, Fireworks AI — receive transcripts, meeting titles, participant names, and any screenshots you capture, for summaries, chat, and live agents. Optional.
- Ollama — the same content, processed by a model running on hardware you control.
- Langfuse — if you turn on tracing, receives prompts and responses.
- MCP servers you connect — receive whatever a tool call requires.
Models that may train on your content
The Anthropic and OpenAI API tiers do not train on data you send them. Consumer subscription plans — Claude Pro and Max, and ChatGPT — may use your conversations to improve their models unless you opt out in your account settings with that provider. If you sign in to Squall with a subscription instead of an API key, meeting content, including calendar-matched meeting titles and attendee names, may be used for training by that provider.
Local and self-hosted models
Ollama runs on your own device or on a server you control. Content processed this way stays on your infrastructure, is never transmitted to Ollama or any model provider, and is not used to train or improve any model or for any other purpose.
Service providers
We use service providers for authentication, cloud hosting, transactional email, and website analytics, including Google or GitHub when you choose those sign-in methods. They process data on our behalf under contractual terms.
How we use information
- Provide and improve Squall and the website
- Authenticate you and secure accounts
- Send service-related email (access decisions, password reset, release updates)
- Send optional marketing email if you opted in
- Measure product usage and diagnose reliability issues
- Comply with law and protect our rights and users
Recording and legal compliance
Squall can capture microphone audio, system audio, and on-screen meeting content. Recording laws vary by location and context. You are responsible for obtaining required consent, providing notice, and complying with applicable wiretapping, employment, healthcare, education, and privacy laws. Squall does not provide legal advice.
Retention
We keep account and telemetry data while your account is active and as needed for operations, security, and legal compliance. Local app data remains on your device until you delete it or uninstall the app. You may request deletion of your account using the contact information below.
Security
We use industry-standard measures to protect data in transit and at rest on our infrastructure. Provider credentials in the app are stored in secure credential storage on your device. No method of transmission or storage is completely secure.
Children
Squall is not directed at children under 13, and we do not knowingly collect their data.
International users
We operate from the United States. If you use Squall from elsewhere, your information may be processed in the U.S. and other countries where our providers operate.
Changes
We may update this policy. We will post the new version on this page and update the effective date. Material changes may also be communicated through the product or by email.
Contact
If you have questions about this policy or how we handle your information — including access, correction, or deletion requests — contact us at privacy@squallapp.ai.