Weaver-AI
Privacy Policy
Weaver AI works with professional material: questions, documents, calendar events, meetings, and API requests. This page explains what we collect, how we use it, how long we keep it, and what we do not do with it.
Last updated 3 September 2026
The short version
Who we are
Weaver AI is a secure workspace and professional assistant owned, managed, and operated by RedBlue Cyber LLC. If you have a question about this policy or about data we hold, contact us at the address on your account or through the support address in your console.
What Weaver collects
Weaver collects the information needed to run the features you turn on, protect the workspace, and bill API credits. The table below is the practical version.
| Area | What Weaver collects | Why Weaver uses it |
|---|---|---|
| Account and sign-in | Email address, name, organization, workspace, and sign-in method. If you use Google, Microsoft, or GitHub, Weaver receives the account details that provider shares for sign-in. | To identify you, route you to the right workspace, and protect account access. |
| Questions and answers | Prompts, answers, evidence, confidence signals, and review metadata when your workspace allows content retention. | To answer your request, show how the answer was produced, and support audit or review. |
| Trusted knowledge | Documents you add, source details, document metadata, and searchable chunks created from those documents. | To let Weaver retrieve approved information instead of relying on loose memory or public web context. |
| Calendar access | Event time, title, organizer, attendees when available, and joining links from a connected Google or Outlook calendar. | To show meetings with join links and let you choose which meetings Weaver may attend. |
| Meeting invitations | Meeting title, time, organizer, sender, and joining details from invitations sent or forwarded to Weaver. | To decide whether the sender is allowed and whether Weaver should join the meeting. |
| Meeting attendance | Speech transcript and screen descriptions when screen content is shared. Weaver does not retain meeting audio or video. | To produce notes, decisions, owners, deadlines, and an attendance record. |
| API requests | Request body, account and workspace IDs, API key ID, timing, status, usage records, and audit metadata. | To answer API requests, secure the service, troubleshoot failures, and bill metered API credits. |
| Operational records | Logs, timing, request status, and audit entries recording what Weaver did and why. | To monitor reliability, investigate issues, detect abuse, and keep a defensible audit trail. |
How Weaver uses Google data
If you sign in with Google, Weaver uses your Google profile email and name to identify your account and route you to the right workspace.
If you connect Google Calendar, Weaver uses read-only calendar access to show upcoming meetings and help you choose which ones Weaver may attend. Weaver reads event time, title, organizer, attendees when available, and joining links. Weaver does not create, edit, or delete Google Calendar events.
We do not sell Google user data, use it for advertising, or use it to train models. We use it only to provide the features you turned on. Weaver’s use and transfer of Google user data follows the Google API Services User Data Policy, including Limited Use requirements.
You can disconnect Google Calendar in Weaver under Meetings → Assistant settings, or revoke access from your Google Account permissions.
How long we keep it
| What | Kept for | Then |
|---|---|---|
| Meeting transcripts | 30 days | Deleted, or sooner once notes are produced from them |
| Meeting audio and video | Never stored | Speech is transcribed and discarded as it arrives |
| Meeting notes | 90 days by default | Your account sets anything from 1 day to 15 years, with a legal hold where an obligation has no end |
| Held invitations | 30 days | Expires if you have not approved the sender |
| Conversation content | Your choice, or not at all | Off, 1 day, 1 week, 1 month, 3 months, 6 months or a year |
| Meeting joining links | Until the meeting ends | Encrypted throughout, never readable, then erased |
| The invitation email itself | Not stored | Weaver keeps the meeting details it extracted, not the message |
Meeting transcripts: 30 days. The transcript of a meeting Weaver attended is retained for thirty days so you can decide whether you want it written up, and is deleted when notes are produced from it. Weaver does not retain meeting audio or video at any point; speech is transcribed and the audio discarded, and a shared screen is described and the image discarded.
Meeting notes: 90 days by default. An account owner sets this, anywhere between 1 day and 15 years, and can turn on a legal hold where an obligation has no end date. When the period runs out the content, the evidence and the citations are cleared. The record of the meeting having happened stays, so the audit trail outlives the material it describes.
Held invitations: 30 days. An invitation from a sender you have not approved is held for thirty days and then expires.
Conversation content: your choice. Your workspace controls whether the content of questions and answers is retained at all, and for how long — one day, one week, one month, three months, six months or a year. Turning retention off scrubs content already held.
What Weaver does not keep
Meeting joining links are never stored in readable form. A joining link admits its holder to your meeting, so it is encrypted, bound to a single scheduled join, never returned to any caller, and erased once the meeting is over.
The original invitation email is not stored. Weaver reads it, extracts the meeting details, and keeps only those.
Calendar credentials are encrypted and revocable. The token that lets Weaver read your calendar is encrypted with the same protection as a meeting joining link. Disconnecting a calendar deletes that credential rather than marking it inactive.
Who else sees your content
Weaver sends your material to third-party language model providers to produce answers, summaries and descriptions. Those providers process it to return a result and are contractually bound not to train their models on it where those commitments are available to us. We do not train any model on your content, and we do not sell it, rent it, or share it for advertising.
Content is isolated per account. Weaver does not use one customer’s material to answer another customer’s question.
You can keep specific names from those providers. Masking replaces the names you list before your text leaves Weaver and puts them back before you read the answer, so the provider never receives them. It covers chat and meeting notes. It is off unless you turn it on, and it removes the names you listed rather than everything that could identify somebody. See the masking guide for what it reaches and what it does not.
Your list of names is stored on your account and is never sent to a model provider. Documents you add to Knowledge are indexed on Weaver’s own machines and are not sent to a provider to be indexed.
Sensitive and regulated data
Weaver is built for professional work, but some data requires special contracts or approvals. Do not submit protected health information, student education records, payment-card data, legal privileged material, or other regulated data unless your account, contract, and own policies permit that use.
If your organization needs a business associate agreement, data processing addendum, enterprise security review, or other written arrangement before using Weaver with regulated data, complete that process before using the service for that data.
When Weaver attends a meeting
Weaver joins openly, under a name that identifies it, and every set of notes states whether it attended or only read a transcript afterwards. It never joins silently and never presents itself as a person.
It joins only when invited by an address you have approved. An invitation from an unknown sender is held for your review, and a passing email-authentication check is not treated as your approval.
Recording laws differ by jurisdiction, and in several places every participant must consent before a meeting is recorded or transcribed. Meeting Weaver’s disclosure obligations to your participants is your responsibility, not ours.
Your rights
You can export or delete your meeting notes from the console, change or disable content retention for your workspace, disconnect a calendar at any time, and close your account. Deleting notes is permanent: the transcript is not kept, so the notes are the only record the meeting produced.
Depending on where you live you may have additional rights to access, correct, export or erase your personal data. Contact us and we will act on a verified request.
Security
Credentials, meeting joining links and calendar tokens are encrypted at rest. Access to production data is limited to personnel who need it. Weaver records what it did for each request so that its actions can be audited afterwards.
No system is perfectly secure. If we become aware of a breach affecting your data, we will tell you.
Changes
We will update this page when the product changes and revise the date at the top. Material changes to how we handle your content will be notified to account owners rather than only posted here.