Privacy Policy — SmartSpaces

Last updated: 4 October 2026

This policy covers everything in SmartSpaces: the web suite (Board, Slide, Write, Spread, Spaces and Meet), the Meeting Manager desktop application, and the SmartSpaces Meet Helper.

They are provided by Carla Berkers Consulting Limited ("we", "us", "the author"), which is the data controller for the information described here. Where your organisation arranged your access to the web suite, the content you create there also belongs to your organisation, which may have its own policies about it.

Registered in England and Wales, company number 12156763. Registered office: 11 Hazel Lane, Skelmersdale, Lancashire, England, WN8 6UN.

For anything in this policy, including a request to see, correct or delete what is held about you, contact mm@scott.hu.

In short: we use what we need to sign you in and to run the apps, nothing is sold, there is no advertising and no analytics, and Meeting Manager keeps your meeting data on your own device and in your own accounts.


Part 1 — The SmartSpaces web suite

Signing in

You sign in with Google. We ask Google only for openid, email and profile: your name, email address and whether Google has verified it. Sign-in is refused unless the address belongs to one of the organisations the suite is set up for.

We keep a session while you are signed in: your name, email address, the time you signed in, and the tokens Google returns (an ID token, and a refresh token used to renew it so the apps can confirm who you are). Sessions are held on the server, expire 12 hours after sign-in, and are deleted when you sign out.

Cookies. The suite sets one cookie, ss_sid, which identifies your session. It is strictly necessary, lasts at most 12 hours, and is not used for tracking. There are no advertising or analytics cookies.

Your documents

Boards, decks, documents, sheets, spaces, comments and uploaded files are stored so the apps can show them to you and to the people you share them with. They are kept either in a folder on your organisation's shared Google Drive, which the suite writes to through a service account, or on the server's own disk, depending on how the suite is set up. Documents being edited are also held in the server's memory while open.

Your name and email address are recorded alongside your work where it matters: as the owner of a board or space, in the list of people a private board is shared with, as the author of document versions and comments.

Named versions of a document are kept up to the most recent 40. Everything else is kept until it is deleted. Deleting is permanent: see the terms of use.

Links to your own Google Drive

If you open a private Google Drive file linked from a document, the suite asks you, on a separate Google consent screen at that moment, for read-only access to your Drive (drive.readonly), so it can show that file to you. It uses that access only to open files you link to, on your behalf, and never changes or deletes anything in your Drive. The tokens are kept in your session and expire with it. You can withdraw the permission at any time at myaccount.google.com/permissions.

When you import from a link, or paste a link to a picture or video, the server fetches that address to bring the content in.

The assistant

The assistant bar is optional and does nothing until you use it. When you do, your messages (the most recent 20), the name and outline of the document you are in, up to two pictures of the current slide, and whatever document content the assistant reads to answer you are sent to Anthropic (the Claude API), which produces the reply. In Meet, the names of the people in the meeting and whether they are muted or on video are included. The assistant acts with your permissions, through the same interface you use.

How the AI model provider handles this data is governed by the agreement between that provider and the holder of the API key used (your organisation, or you), not by this policy.

Meetings (Meet)

Meet joins and manages Zoom meetings for the facilitation view, using Zoom's Meeting SDK and the Zoom account you connect. Zoom processes the meeting under its own privacy statement. Meet's tasks, settings and the Zoom tokens it needs are stored on the server for the people who use it.

The Meet Helper, if you install it, joins the meeting as the host without a camera or microphone and takes instructions from Meet. It remembers the address and pairing code it was given, and keeps a log of what it did, on your own computer.

Fonts, logs, and what else leaves the server


Part 2 — Meeting Manager (desktop application)

Where your data lives

Your meeting data (recordings, transcripts, and the analysis made from them) resides on Zoom, on Google Drive, and on your own device. None of it is ever sent to us without your specific, proactive consent, for example pressing the button that sends an error report.

The application runs on the computer it is installed on. During normal use it contacts us for exactly one purpose: to check whether your subscription is active. That check carries nothing about your meetings.

What the app touches, and where it goes

Data Where it comes from Where it goes
Zoom cloud recordings, transcripts, chat logs Your Zoom account Downloaded to your device, uploaded to your Google Drive
Meeting analysis (actions, decisions, segments) Generated from your transcripts Your Google Sheets, in your Drive
Transcript text for analysis Your device Sent to the Anthropic API to produce the analysis
Zoom access and refresh tokens Zoom authorisation Stored encrypted on your device only
Google access and refresh tokens Google sign-in Stored on your device only
Your Google sign-in (name, email) Google Held in a local session on your device
Anthropic API key You Stored encrypted on your device only
Your email address Your Google sign-in Sent to the licence server to check your subscription
Name, billing address, card details You, at checkout Held by Paddle, our payment provider. We never receive card details.

Transcript text is sent to the AI model provider under your own API key, so how the provider handles it is governed by your agreement with that provider, not by this policy.

The licence check

What is sent: your email address, as verified by your Google sign-in, and the application version. As with any internet request, the server also sees your IP address and the time, and records them in its logs.

What is not sent: nothing about your meetings. No recordings, transcripts, titles, participant names, summaries or file names, and none of your Zoom, Google or Anthropic credentials.

When: when the app starts, and periodically while it runs. If the check cannot be reached, the app keeps working for a grace period.

The check is not analytics, but a request from your address does tell us that your account ran the app at that time. Licence-check logs are kept for 30 days and then deleted.

Payment

Payments are handled by Paddle, the merchant of record: the legal seller for your purchase. Your card details are entered on Paddle's checkout, not in the application. We never see, receive or store your card number; Paddle tells us that a subscription exists for your email address, and the country used for tax. Paddle's handling of payment data is governed by paddle.com/legal/privacy.

Zoom authorisation

Meeting Manager uses Zoom's public-client OAuth with PKCE and holds no Zoom client secret. Authorisation happens in your browser, directly between you and Zoom; the tokens are stored encrypted on your device and nowhere else. It asks for read-only access to your own cloud recordings and your basic profile:

user:read:user
cloud_recording:read:list_user_recordings

Google authorisation

Scope What it actually allows
openid, userinfo.email Your email address, so the app knows who is signed in and can check your subscription
drive.file See, edit, create and delete only files this app created, not the rest of your Drive
tasks (only if you turn on Google Tasks) Create and manage your Google Tasks

Google words drive.file as "see, edit, create, and delete", but it applies only to files the app made: it cannot list, open, or touch anything else in your Drive. The app does not request access to your whole Drive or to every spreadsheet you own. tasks is requested only if you switch Google Tasks on in Settings, on a separate consent screen; you can withdraw it at any time at myaccount.google.com/permissions.

Error reports

The Send error report button in Settings does nothing until you press it. It then sends the app's recent log files, your account email, the app version, your platform, your subscription state and any note you type, by email to us. Recordings, transcripts and credentials are never included; meeting names may appear in the logs. Show report displays exactly what would be sent first.

Deleting Meeting Manager data


Part 3 — Everything

Who sees your information

Only the services named above, to do the job described: Google (sign-in, Drive, fonts), Anthropic (assistant and meeting analysis), Zoom (meetings and recordings), Paddle (Meeting Manager payments), and our hosting providers. We do not sell personal information or use it for advertising. Some of these providers process data outside the UK, under their own safeguards for international transfers.

Why we use it (legal basis)

To provide the apps you asked to use (contract, or our legitimate interest in running the service for your organisation); to check Meeting Manager subscriptions and keep payment records (contract and legal obligation); and to keep the service secure and fix problems (legitimate interest).

Your rights

Under UK data protection law you can ask to see the personal information we hold about you, to have it corrected or deleted, to restrict or object to how it is used, and to receive a copy. Email mm@scott.hu. You can also complain to the Information Commissioner's Office at ico.org.uk.

Security

Access to the web suite requires a verified sign-in from an allowed organisation, sessions are protected by an HTTP-only cookie, and tokens stored on devices are encrypted where the platform allows. No system is perfectly secure: keep your own copies of anything important (see the terms of use).

Children

SmartSpaces is not intended for children under 13.

Changes

This policy may change. The date at the top shows when it was last updated, and the current version is always the one published here.


© Carla Berkers Consulting Limited 2026