Privacy Policy — SmartSpaces
Last updated: 4 October 2026
This policy covers everything in SmartSpaces: the web suite (Board, Slide, Write, Spread, Spaces and Meet), the Meeting Manager desktop application, and the SmartSpaces Meet Helper.
They are provided by Carla Berkers Consulting Limited ("we", "us", "the author"), which is the data controller for the information described here. Where your organisation arranged your access to the web suite, the content you create there also belongs to your organisation, which may have its own policies about it.
Registered in England and Wales, company number 12156763. Registered office: 11 Hazel Lane, Skelmersdale, Lancashire, England, WN8 6UN.
For anything in this policy, including a request to see, correct or delete what is held about you, contact mm@scott.hu.
In short: we use what we need to sign you in and to run the apps, nothing is sold, there is no advertising and no analytics, and Meeting Manager keeps your meeting data on your own device and in your own accounts.
Part 1 — The SmartSpaces web suite
Signing in
You sign in with Google. We ask Google only for openid, email and profile:
your name, email address and whether Google has verified it. Sign-in is refused
unless the address belongs to one of the organisations the suite is set up for.
We keep a session while you are signed in: your name, email address, the time you signed in, and the tokens Google returns (an ID token, and a refresh token used to renew it so the apps can confirm who you are). Sessions are held on the server, expire 12 hours after sign-in, and are deleted when you sign out.
Cookies. The suite sets one cookie, ss_sid, which identifies your session.
It is strictly necessary, lasts at most 12 hours, and is not used for tracking.
There are no advertising or analytics cookies.
Your documents
Boards, decks, documents, sheets, spaces, comments and uploaded files are stored so the apps can show them to you and to the people you share them with. They are kept either in a folder on your organisation's shared Google Drive, which the suite writes to through a service account, or on the server's own disk, depending on how the suite is set up. Documents being edited are also held in the server's memory while open.
Your name and email address are recorded alongside your work where it matters: as the owner of a board or space, in the list of people a private board is shared with, as the author of document versions and comments.
Named versions of a document are kept up to the most recent 40. Everything else is kept until it is deleted. Deleting is permanent: see the terms of use.
Links to your own Google Drive
If you open a private Google Drive file linked from a document, the suite asks
you, on a separate Google consent screen at that moment, for read-only access
to your Drive (drive.readonly), so it can show that file to you. It uses that
access only to open files you link to, on your behalf, and never changes or
deletes anything in your Drive. The tokens are kept in your session and expire
with it. You can withdraw the permission at any time at
myaccount.google.com/permissions.
When you import from a link, or paste a link to a picture or video, the server fetches that address to bring the content in.
The assistant
The assistant bar is optional and does nothing until you use it. When you do, your messages (the most recent 20), the name and outline of the document you are in, up to two pictures of the current slide, and whatever document content the assistant reads to answer you are sent to Anthropic (the Claude API), which produces the reply. In Meet, the names of the people in the meeting and whether they are muted or on video are included. The assistant acts with your permissions, through the same interface you use.
How the AI model provider handles this data is governed by the agreement between that provider and the holder of the API key used (your organisation, or you), not by this policy.
Meetings (Meet)
Meet joins and manages Zoom meetings for the facilitation view, using Zoom's Meeting SDK and the Zoom account you connect. Zoom processes the meeting under its own privacy statement. Meet's tasks, settings and the Zoom tokens it needs are stored on the server for the people who use it.
The Meet Helper, if you install it, joins the meeting as the host without a camera or microphone and takes instructions from Meet. It remembers the address and pairing code it was given, and keeps a log of what it did, on your own computer.
Fonts, logs, and what else leaves the server
- The apps' pages load typefaces from Google Fonts, so your browser contacts Google, which sees your IP address. No other third-party scripts are loaded.
- The server keeps technical logs (requests, errors, and which apps started), which can include your email address and document names, for running and fixing the service.
- Spelling dictionaries and thesaurus files are downloaded by the server from public sources; nothing about you is sent with those requests.
- There is no analytics, no advertising, no tracking and no error-reporting service.
Part 2 — Meeting Manager (desktop application)
Where your data lives
Your meeting data (recordings, transcripts, and the analysis made from them) resides on Zoom, on Google Drive, and on your own device. None of it is ever sent to us without your specific, proactive consent, for example pressing the button that sends an error report.
The application runs on the computer it is installed on. During normal use it contacts us for exactly one purpose: to check whether your subscription is active. That check carries nothing about your meetings.
What the app touches, and where it goes
| Data | Where it comes from | Where it goes |
|---|---|---|
| Zoom cloud recordings, transcripts, chat logs | Your Zoom account | Downloaded to your device, uploaded to your Google Drive |
| Meeting analysis (actions, decisions, segments) | Generated from your transcripts | Your Google Sheets, in your Drive |
| Transcript text for analysis | Your device | Sent to the Anthropic API to produce the analysis |
| Zoom access and refresh tokens | Zoom authorisation | Stored encrypted on your device only |
| Google access and refresh tokens | Google sign-in | Stored on your device only |
| Your Google sign-in (name, email) | Held in a local session on your device | |
| Anthropic API key | You | Stored encrypted on your device only |
| Your email address | Your Google sign-in | Sent to the licence server to check your subscription |
| Name, billing address, card details | You, at checkout | Held by Paddle, our payment provider. We never receive card details. |
Transcript text is sent to the AI model provider under your own API key, so how the provider handles it is governed by your agreement with that provider, not by this policy.
The licence check
What is sent: your email address, as verified by your Google sign-in, and the application version. As with any internet request, the server also sees your IP address and the time, and records them in its logs.
What is not sent: nothing about your meetings. No recordings, transcripts, titles, participant names, summaries or file names, and none of your Zoom, Google or Anthropic credentials.
When: when the app starts, and periodically while it runs. If the check cannot be reached, the app keeps working for a grace period.
The check is not analytics, but a request from your address does tell us that your account ran the app at that time. Licence-check logs are kept for 30 days and then deleted.
Payment
Payments are handled by Paddle, the merchant of record: the legal seller for your purchase. Your card details are entered on Paddle's checkout, not in the application. We never see, receive or store your card number; Paddle tells us that a subscription exists for your email address, and the country used for tax. Paddle's handling of payment data is governed by paddle.com/legal/privacy.
Zoom authorisation
Meeting Manager uses Zoom's public-client OAuth with PKCE and holds no Zoom client secret. Authorisation happens in your browser, directly between you and Zoom; the tokens are stored encrypted on your device and nowhere else. It asks for read-only access to your own cloud recordings and your basic profile:
user:read:user
cloud_recording:read:list_user_recordings
Google authorisation
| Scope | What it actually allows |
|---|---|
openid, userinfo.email |
Your email address, so the app knows who is signed in and can check your subscription |
drive.file |
See, edit, create and delete only files this app created, not the rest of your Drive |
tasks (only if you turn on Google Tasks) |
Create and manage your Google Tasks |
Google words drive.file as "see, edit, create, and delete", but it applies only
to files the app made: it cannot list, open, or touch anything else in your
Drive. The app does not request access to your whole Drive or to every
spreadsheet you own. tasks is requested only if you switch Google Tasks on in
Settings, on a separate consent screen; you can withdraw it at any time at
myaccount.google.com/permissions.
Error reports
The Send error report button in Settings does nothing until you press it. It then sends the app's recent log files, your account email, the app version, your platform, your subscription state and any note you type, by email to us. Recordings, transcripts and credentials are never included; meeting names may appear in the logs. Show report displays exactly what would be sent first.
Deleting Meeting Manager data
- Disconnect Zoom in Settings revokes the authorisation and deletes the tokens from your device.
- Uninstalling removes the program; run the uninstaller with
--purge, or delete the app's data folder, to remove settings, sign-ins and the local database too. - Files saved to your Google Drive are yours and stay until you delete them.
- Licence-check logs age out after 30 days; ask to have them removed sooner.
- Your subscription record is held by Paddle; ask to have it erased, subject to the transaction records Paddle must keep by law.
Part 3 — Everything
Who sees your information
Only the services named above, to do the job described: Google (sign-in, Drive, fonts), Anthropic (assistant and meeting analysis), Zoom (meetings and recordings), Paddle (Meeting Manager payments), and our hosting providers. We do not sell personal information or use it for advertising. Some of these providers process data outside the UK, under their own safeguards for international transfers.
Why we use it (legal basis)
To provide the apps you asked to use (contract, or our legitimate interest in running the service for your organisation); to check Meeting Manager subscriptions and keep payment records (contract and legal obligation); and to keep the service secure and fix problems (legitimate interest).
Your rights
Under UK data protection law you can ask to see the personal information we hold about you, to have it corrected or deleted, to restrict or object to how it is used, and to receive a copy. Email mm@scott.hu. You can also complain to the Information Commissioner's Office at ico.org.uk.
Security
Access to the web suite requires a verified sign-in from an allowed organisation, sessions are protected by an HTTP-only cookie, and tokens stored on devices are encrypted where the platform allows. No system is perfectly secure: keep your own copies of anything important (see the terms of use).
Children
SmartSpaces is not intended for children under 13.
Changes
This policy may change. The date at the top shows when it was last updated, and the current version is always the one published here.
© Carla Berkers Consulting Limited 2026