Privacy Policy
Last updated: July 7, 2026
This Privacy Policy explains how OpenBlock (“OpenBlock”, “we”, “us”, or “our”), a scheduling and meeting-assistant product operated by OAra Labs LLC, collects, uses, and shares information when you use our websites at openblock.me and app.openblock.me, our desktop application, and our related services (the “Service”).
1. Who this policy covers
This policy applies to three groups of people:
- Account holders — people who create an OpenBlock account to manage availability, share booking links, and use the meeting assistant.
- Invitees — people who book a meeting through an account holder’s booking page.
- Meeting participants & contacts — people who appear in an account holder’s calendar events, meetings, recordings, transcripts, or memory pages, whether or not they use OpenBlock.
For invitees and meeting participants, the account holder is also a controller of your information and uses OpenBlock to process it on their behalf.
2. Information we collect
Information you give us
- Account & profile: your name, email address, username, profile photo, job title, company name, brand color/logo, and time zone.
- Scheduling configuration: event types, availability rules, schedules, and any custom booking questions you create.
Information from accounts you connect
- Calendar & identity providers (Microsoft 365 / Google): when you sign in or connect a calendar, we receive your basic profile (name, email) and an OAuth access/refresh token. Depending on the scopes you grant, this lets us read your calendar and its events (including event titles and attendee names and email addresses), create or update events, and — for the assistant — draft or send email from your connected mailbox. We request only the scopes needed for the features you use.
- Connected mailbox (assistant, optional): if you connect your mailbox to the assistant, we read message envelopes and content on a forward-only basis (we do not backfill your history) to give the assistant context. Raw email is treated as short-lived (see Retention).
- Video providers (Microsoft Teams, Google Meet, Zoom): we generate meeting links for your bookings using the provider you select.
Meeting recordings & assistant content
- When you use the OpenBlock desktop app to record a meeting, we process the meeting audio you capture, the transcript we generate from it, any notes you type, and the summaries, follow-up email drafts, and memory pages the assistant derives from them. Recording is initiated by you, on a per-meeting basis. See Section 4 for how the assistant works and your consent responsibilities, and Section 5 for the memory feature.
Information from invitees
- Booking details: an invitee’s name, email address, selected time, time zone, any notes, and answers to the account holder’s custom questions. This is stored as a booking and, as a record of the person, as a contact for the account holder.
Payment information
- Paid bookings (where enabled): payments are processed by Stripe. We do not collect or store full card numbers; Stripe handles payment data under its own terms and privacy policy.
Information we collect automatically
- Log & device data: IP address, browser type, pages viewed, and timestamps, used to operate and secure the Service.
- Local storage: we store an authentication token in your browser’s local storage to keep you signed in. The desktop app stores your in-progress recordings on your own device until they upload. We do not currently use third-party advertising or tracking cookies.
3. How we use information
- To provide the Service — show real availability, create calendar events, generate meeting links, and send confirmations, reschedules, and cancellations from your connected mailbox.
- To provide the meeting assistant — transcribe recordings, generate summaries and follow-up email drafts, and build and maintain your memory pages.
- To maintain account holders’ records of their bookings, contacts, meetings, and memory.
- To process payments for paid bookings (via Stripe), where enabled.
- To secure, maintain, debug, and improve the Service.
- To communicate with you about your account, security, and service-related matters.
- To comply with legal obligations and enforce our Terms.
Where required by law (for example, in the EEA/UK), we rely on the following legal bases: performance of a contract, your consent (including for optional recording and assistant features), our legitimate interests in operating and securing the Service, and compliance with legal obligations.
4. Recording, transcription & the AI assistant
The assistant is an optional feature you turn on and control.
Processed on our own infrastructure
Transcription and the language model that produces summaries, drafts, and memory pages run on hardware operated by OAra Labs LLC. We do not send your meeting audio, transcripts, calendar content, or mailbox content to third-party AI or large-language-model providers, and we do not use your content to train third-party models.
Drafts, not sends
The assistant creates follow-up emails as drafts for you to review; it does not send email on your behalf. (Separately, when you enable scheduling, OpenBlock sends booking confirmations, reschedules, and cancellations from your connected mailbox — those are transactional messages you initiate by using the booking feature.)
Your responsibility to obtain consent
Recording conversations is regulated, and many jurisdictions require the consent of some or all participants before a call or meeting may be recorded. You are responsible for knowing and complying with the laws that apply to you and your participants, and for obtaining any required notice or consent before you record. OpenBlock provides the recording tool; you decide when and whom to record. See our Terms of Service.
5. Your memory (the “Brain”) & people you meet with
The assistant can maintain private memory pages for the account holder — for example, a page about a person you meet with, assembled from your meetings with them. These pages are keyed to a contact’s email address and are visible only to the account holder whose account created them.
This means OpenBlock may hold information about people who are not OpenBlock users and who did not themselves provide it to us — for instance, a meeting participant’s name, email, and notes derived from a meeting. We process this on behalf of the account holder, who is responsible for having a lawful basis to do so and for honoring applicable rights. If you are a meeting participant and want to know what is held about you or have it removed, see Section 9.
6. How we share information
We do not sell your personal information. We share it only as described here:
- Between account holders and invitees: a booking is shared with the account holder you book with (and the host’s details are shown to the invitee).
- Connected providers you authorize: Microsoft, Google, and Zoom, to read calendars/mail and create meetings, as scoped by your grant.
- Integrations & webhooks you enable: if you connect OpenBlock to another system (for example via an API key or webhook), booking data is sent to that system at your direction.
- Service providers (sub-processors) who help us run the Service, listed below.
- Legal & safety: where required by law, to enforce our Terms, or to protect rights, property, and safety.
- Business transfers: in connection with a merger, acquisition, or sale of assets, subject to this policy.
Sub-processors
| Provider | Purpose |
|---|---|
| Microsoft (Microsoft 365 / Graph) | Sign-in, calendar, mailbox (assistant), Teams meeting links |
| Sign-in, Google Calendar, Google Meet links | |
| Zoom | Video meeting links (where selected) |
| Stripe | Payment processing for paid bookings |
| Supabase | Database and encrypted storage of meeting audio |
| Railway | Application hosting |
| Vercel | Marketing website hosting (openblock.me) |
Google API disclosure. OpenBlock’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Our use of information received from Microsoft APIs likewise complies with Microsoft’s APIs Terms of Use.
Account holders are responsible for having an appropriate legal basis to invite people to book, record meetings, and build memory, and for informing invitees and participants about how their information is used.
7. Data retention
We keep account and booking information for as long as your account is active and as needed to provide the Service. For the assistant:
- Meeting audio is retained for up to 90 days and then deleted from our storage.
- Raw mailbox messages synced for assistant context are short-lived and retained for up to 90 days.
- Derived content — transcripts, summaries, follow-up drafts, and memory pages — is kept until you delete it or close your account, because it is the working record you rely on.
You can delete individual meetings, contacts, and memory pages in the app, and disconnect the mailbox at any time. We retain information longer only where required to comply with legal obligations, resolve disputes, or enforce agreements.
8. Security
We use technical and organizational measures to protect your information, including encryption in transit, hashed credentials, scoped access tokens, and processing of assistant content on infrastructure we operate. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
9. Your rights & choices
Depending on where you live, you may have the right to access, correct, delete, export, or restrict the processing of your personal information, and to object to certain processing or withdraw consent. Account holders can edit or delete much of their data directly in the app — including meetings, recordings, contacts, and memory pages — or disconnect a calendar or mailbox at any time. To make a request, contact us at support@oara.ai.
If you are an invitee or a meeting participant and want to access or remove information held about you, please contact the account holder you interacted with, or reach us at support@oara.ai and we will help route your request to the responsible account holder.
We will not discriminate against you for exercising these rights. If you are in the EEA/UK, you also have the right to lodge a complaint with your local data protection authority.
10. International data transfers
We and our sub-processors may process information in countries other than your own, including the United States. Where required, we use appropriate safeguards (such as standard contractual clauses) for international transfers.
11. Children’s privacy
The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.
12. Third-party services
The Service links to and integrates with third-party services (such as Microsoft, Google, Zoom, and Stripe). Their handling of your information is governed by their own privacy policies, not this one.
13. Changes to this policy
We may update this policy from time to time. We will revise the “Last updated” date above and, for material changes, provide additional notice where appropriate. Your continued use of the Service after changes take effect constitutes acceptance.
14. Contact us
Questions or requests about this policy or your information? Contact us at support@oara.ai.