Privacy policy
The short version
- Your recordings, transcripts and notes stay on your computer.
- When you make a summary or use chat, the text it needs goes to an AI model to write the answer.
- While you record, audio streams through the Upshot proxy, which stores nothing, to Deepgram for transcription. On an Apple Silicon Mac you can switch to on-device transcription, so audio never leaves your Mac.
- Upshot AI and Upshot transcription need a free account: you sign in with Google or Microsoft. Notes, folders and search work without one. For Pro, Stripe handles your card.
- No ads, no analytics, no tracking. We don't sell or share your personal information.
Who we are
Upshot is a meeting-notes app for Mac, Windows and Linux, published by Website Formula. Website Formula decides how the data on this page is used (the "data controller" in GDPR terms). Upshot is based on Anarlog, an open-source app.
Contact: email adam@websiteformula.co.
What stays on your computer
These never leave your computer unless you send them somewhere yourself:
- Meeting audio, kept until the retention setting in Settings › Meetings removes it.
- Transcripts. Upshot sends the audio to Deepgram to make them (see Transcription below) and saves them on your computer. On an Apple Silicon Mac you can pick on-device transcription (Apple Speech or Parakeet) instead; Apple Speech may download its language files from Apple.
- Notes, summaries, folders, templates, contacts and settings.
- Calendar events (Mac only), which Upshot reads from the calendar accounts on your Mac, such as Google, Outlook and iCloud.
All of this lives in the anarlog folder: ~/Library/Application Support/anarlog/ on a Mac, %APPDATA%\anarlog\ on Windows, ~/.local/share/anarlog/ on Linux. Upshot has no cloud sync.
What leaves your computer, and who gets it
AI summaries and chat. When you generate a summary or send a chat message, Upshot sends the text the AI needs:
- For a summary: the note, the transcript, the meeting title and time, and the names and job titles of the people in the meeting.
- For chat: your question, the conversation so far, and the notes, transcripts, calendar events (title, time, location) and contacts (name, email, phone, role, company) that chat looks up to answer it.
This goes through the Upshot AI proxy, a Cloudflare Worker we run. The proxy passes your request on and doesn't store or log what you send; Its logging is turned off. It checks that you're signed in, and uses your IP address and account ID only to limit how many requests one address or account can make per minute. From the proxy, the text goes to OpenRouter, which sends it to the company that runs the model: Anthropic for Auto, or Anthropic, OpenAI or Google (or a cloud provider that hosts their models) for a model a Pro user picks. They process it to write the answer, under their own privacy policies.
A locked note is never sent to chat, connected tools or webhooks until you unlock it.
Transcription. While you record, Upshot streams the meeting audio through the Upshot transcription proxy, a Cloudflare Worker we run, to Deepgram, which turns the audio into text and sends the transcript back. The proxy passes the audio on and doesn't store or log it. It checks that you're signed in, and uses your IP address and account ID only for the per-minute limits. Upshot asks Deepgram to opt the audio out of its model improvement program, so Deepgram keeps it only as long as it needs to process it. On an Apple Silicon Mac you can pick on-device transcription in Settings › Transcription; then audio never leaves your Mac.
Your account. When you sign in with Google or Microsoft:
- Google or Microsoft tells us your email address, name and profile picture link. Upshot never sees your Google or Microsoft password.
- Supabase stores that email, name and picture link, and, if you get Pro, your plan: status, billing period, renewal date, and your Stripe customer and subscription IDs. The app keeps your sign-in session in your computer's credential store (the Keychain on a Mac).
- Stripe handles payment on Stripe Checkout. Your card and billing details go only to Stripe, never to Upshot. Stripe tells us whether your subscription is active.
Your calendar, if you connect it. When you click Connect Google Calendar or Connect Outlook calendar, Google or Microsoft gives Upshot read-only access to your calendars:
- Upshot's Cloudflare Worker keeps a refresh token from Google or Microsoft, encrypted, in Supabase, so your calendar keeps syncing. Upshot never receives your Google or Microsoft password.
- When Upshot syncs, the Worker fetches your calendars and events and passes them to the app. The Worker doesn't store or log them. Events are saved only on your computer, to name your notes, list attendees and remind you before meetings.
- Upshot never changes, creates or deletes calendar events, and never shares calendar data with anyone else or uses it for ads or to train AI models.
- Upshot's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- To disconnect, remove Upshot at myaccount.google.com/connections or account.live.com/consent/Manage, or delete your Upshot account. The stored token is deleted with your account.
What you set up yourself. A webhook (Settings › Connectors › Webhooks) sends finished notes to the address you choose. The Glaido and MCP connection runs only on your computer.
Model list. Upshot downloads public model catalogs from models.dev and OpenRouter. It sends no data about you, just a normal web request.
Hosting. The proxy and this page run on Cloudflare, which handles the network traffic.
What we don't do
- No analytics, telemetry or crash reports. The released app ships with none turned on.
- No ads, and we don't sell or share your personal information.
- No cookies on this page or the checkout pages we serve. Stripe Checkout sets its own cookies on stripe.com.
- We don't use your notes to train AI models.
Why we use your data
- To write summaries and chat answers you ask for.
- To transcribe your meetings.
- To run your account, Pro and billing, which is our contract with you.
- To stop abuse of the AI proxy with the per-minute limit, which is our legitimate interest in keeping it running.
How long we keep it
- Notes, transcripts and audio: on your computer until you delete them.
- AI requests: the proxy keeps nothing once the answer is sent.
- Transcription audio: the proxy keeps nothing. Deepgram keeps it only as long as it needs to process it, under its own privacy policy.
- A calendar connection: until you delete your account, or until Google or Microsoft tells Upshot the access was removed.
- Your account: until you delete it. Stripe may keep payment records it must keep by law.
Your choices and rights
- See and change your data. Your notes are in the app, where you can edit them. Your account email and plan show in Settings › Plan. To correct your email, contact us.
- Delete your notes. Delete a note in the app, or quit Upshot and delete the folder above.
- Delete your account. Go to Settings › Profile › Delete account. This cancels your subscription, deletes your Stripe customer record and deletes your Supabase account and plan.
- Take your data with you. Export a note as PDF, text or Markdown from the note's Share menu (Export…).
- Don't send anything. Recording and transcription work without an AI summary, and you can lock a note to keep it out of chat.
Depending on where you live (for example California, the EU or the UK), you may have the right to access, correct, delete or port your data, and to object to how it is used. Contact us to use these rights. We don't treat you differently for using them. In the EU or UK you can also complain to your data protection authority.
Do Not Track
Upshot doesn't track you across websites or apps, and lets no third party do so. Because there is no tracking to turn off, it works the same whether or not your browser sends a Do Not Track signal.
Where your data is processed
Cloudflare, OpenRouter, the model companies, Deepgram, Supabase and Stripe may process data in the United States and other countries.
Children
Upshot is not meant for children under 13, and we don't knowingly collect their information.
Changes to this policy
We post every change on this page and update the effective date at the top. If a change affects how we use data we already have, we say so at the top of this page and in the release notes for that version of Upshot before it takes effect.