Legal
Privacy Policy
Last updated August 5, 2026
This is a draft template, not legal advice. It describes what Rika's codebase actually stores and sends today, but has not been reviewed by a lawyer for compliance with GDPR, CCPA, India's DPDP Act, or any other regime that may apply to your users. Have it reviewed before relying on it with real users.
This Privacy Policy explains what data Rika ("the Service"), operated by Abhijeet Kadam, collects, why, and how you can control it.
1. Data we collect
From you, the account holder
- Account info: email address, authentication identity (via Clerk).
- Calendar data, if you connect one: event titles, times, attendees, and meeting links from Google Calendar or Microsoft Outlook/Graph.
- Meeting metadata: platform, join/leave timestamps, category labels, and any chat messages you send Rika.
From meetings Rika joins
- Audio and video recordings of the call, hosted by our meeting-bot provider.
- A speaker-attributed transcript of the call, including participant names as they appear in the meeting platform.
- Vector embeddings of transcript text, used to power search and chat over meeting content.
- Messages sent to "@Rika" in the live meeting chat, and Rika's replies.
Meetings routinely include people who are not Rika account holders — other call participants. Their voice, video, and spoken words become part of the recording and transcript under the account holder's control, as described in Section 2 of the Terms of Service.
2. How we use data
- To join meetings, produce transcripts, and generate summaries, action items, and highlights.
- To answer your questions about past meetings, grounded in the transcript (retrieval-augmented generation).
- To auto-schedule recording bots for calendar events, if you enable auto-record.
- To operate, secure, and improve the Service — including rate-limiting abuse and diagnosing errors.
We do not sell your data, and we do not use your meeting content to train third-party foundation models beyond the ordinary inference calls described below.
3. Who we share data with (sub-processors)
Rika is built on top of several third-party infrastructure and AI providers. Each processes a slice of your data solely to perform its function:
| Provider | Role | What it sees |
|---|---|---|
| Recall.ai | Meeting bot, recording, transcription | Meeting audio/video, transcript |
| Clerk | Authentication | Email, login/session data |
| Neon | Primary database (Postgres) | Account, meeting metadata, transcript text |
| Qdrant Cloud | Vector search database | Transcript embeddings + excerpt text |
| Google (Gemini API) | Transcript embeddings | Transcript text, sent per query/chunk |
| DeepSeek | Chat answers, summaries, classification | Transcript excerpts + your questions |
| Google Calendar API / Microsoft Graph | Calendar sync (if connected) | Calendar events, attendee lists |
| Vercel | Application hosting | All request traffic, application logs |
We may also disclose data if required by law, or to protect the rights, property, or safety of Rika, our users, or others.
4. Data retention
We retain meeting recordings, transcripts, and related data until you delete the meeting or your account — there is currently no automatic expiry. Deleting a meeting removes its transcript, embeddings, participant records, and chat history from our database and vector store. Recordings hosted by Recall.ai follow that provider's own retention timing, which may briefly lag behind deletion in Rika.
5. Your rights
You can, at any time:
- Delete any individual meeting from the Meetings page.
- Disconnect a calendar connection to stop future calendar access.
- Request a copy of your data, or full account deletion, by emailing kadamabhi1881@gmail.com.
If you are located in the EU/UK, India, California, or another jurisdiction with statutory data-subject rights (access, correction, portability, erasure), those requests can also be sent to the same address.
6. Security
We use industry-standard measures to protect your data, including encrypted connections (TLS), signed webhook verification for events from our meeting-bot provider, and resource-level authorization checks on every account's data. No system is perfectly secure, and we can't guarantee absolute security.
7. Children
Rika is not directed at, and should not be used by, anyone under 18.
8. Changes to this policy
We may update this policy as the Service changes. We'll update the "last updated" date above when we do.
9. Contact
Questions about this policy or your data: kadamabhi1881@gmail.com.