Privacy Policy
Last Updated: 10 February 2026
1. Introduction
This Privacy Policy explains how we collect, use, store, and protect your information when you use our B2B application ("App"). We are committed to ensuring the privacy and security of your data in compliance with applicable data protection laws in the United Kingdom.
2. Information We Collect
- Authentication Information: We use Firebase Authentication to manage user accounts and login credentials.
- User Input Data: Any data you input into the App as part of its functionality.
2A. Google API and Google User Data
Google API Usage
The App integrates with Google APIs solely for the purpose of secure authentication and access management for authorised users. Emma AI's use of Google APIs is limited to what is strictly necessary to provide the App's core functionality.
Categories of Google User Data Accessed
Where a user elects to authenticate using Google services, the App may access the following categories of Google user data:
- Basic account information (including name, email address and profile image)
- Google Workspace authentication identifiers
- OAuth access tokens required to authenticate and authorise user sessions
The App does not access, read, store, or process:
- Google Drive files or file contents
- Gmail message content
- Google Calendar data
- Google Contacts
- Any other Google Workspace content or user-generated files
unless explicitly enabled by the user's organisation and clearly disclosed at the point of access.
2B. Use of Google User Data
Google user data accessed by the App is used exclusively for the following purposes:
- Authenticating users and verifying identity
- Managing secure access to the App within an organisation
- Maintaining session security, access controls, and audit logs
- Accessing calendar events for bot scheduling.
Google user data is not used for:
- Advertising or marketing purposes
- Profiling or behavioural analysis
- Sale or commercial exploitation
- Any purpose unrelated to the provision of the App
2C. Storage and Retention of Google User Data
Google user data is processed and stored in accordance with industry-standard security practices and the principle of data minimisation.
- Authentication data is processed via Google OAuth and Firebase Authentication
- OAuth tokens are encrypted both in transit and at rest
- Tokens are retained only for the duration required to provide access to the App
- Tokens are revoked promptly upon user logout, account deactivation, or organisational removal
Google user data is not retained beyond what is strictly necessary to operate the App.
2D. Sharing of Google User Data
Emma AI does not sell, rent, or otherwise disclose Google user data to third parties.
Google user data is shared only with:
- Google services, for the purposes of authentication and authorisation
- Firebase Authentication, acting as a data processor on behalf of Emma AI
Google user data is not shared with transcription providers, analytics platforms, or any third-party artificial intelligence systems.
2E. Artificial Intelligence and Machine Learning
Google user data is not used for the training, fine-tuning, or improvement of any artificial intelligence or machine learning models.
All artificial intelligence processing within the App operates on customer-provided organisational data under contractual controls and, where applicable, zero-data-retention arrangements with third-party processors.
2F. Compliance with Google API Services User Data Policy
Emma AI's access to and use of Google user data complies with:
- The Google API Services User Data Policy
- Google APIs Terms of Service
- Applicable data protection laws in the United Kingdom
Access to Google user data is limited to the minimum necessary to deliver the App's functionality and is subject to ongoing internal review.
3. How We Use Your Information
We use your information for the following purposes:
- To provide and maintain our App's services
- To authenticate users and manage access to the App
- To process and store data input by users for the intended functionality of the App
- To transcribe audio content via our third-party service provider (AssemblyAI)
4. Data Storage and Retention
- Local Storage: Your data is stored locally on your device for up to 7 days in the App's secure storage area.
- Database Storage: Your data is also stored in our secure database for access through both the mobile App and main online portal.
- Retention Period: Your organization can manage data retention periods through the main online portal.
5. Data Sharing and Third Parties
We share certain data with the following third parties:
- AssemblyAI: We use AssemblyAI for transcription services. Data is shared with them solely for processing purposes with zero data retention.
- ElevenLabs: We use ElevenLabs for transcription services. Data is shared with them solely for processing purposes with zero data retention.
- Open AI: We use OpenAI for foundational model capabilities. Data is shared with them solely for processing purposes with zero data retention.
- Google: We use Google for foundational model capabilities. Data is shared with them solely for processing purposes with zero data retention.
- Firebase: We use Firebase Authentication for user login and account management.
We do not sell your personal information to any third parties.
6. Data Security
We implement appropriate technical and organisational measures to protect your information, including:
- Encryption of data both at rest and in transit
- Implementation of security measures aligned with ISO 27001 best practices
- Regular security assessments and updates
7. Your Rights
As a user based in the UK, you have the right to:
- Access your personal data
- Request correction of inaccurate data
- Request deletion of your data
- Object to processing of your data
- Request restriction of processing
- Data portability
You can exercise these rights through your organization's access to the main online portal.
8. Children's Privacy
Our App is not intended for use by children under the age of 13, and we do not knowingly collect personal information from children under 13.
9. International Data Transfers
Our services are currently only available in the United Kingdom. We do not transfer your data outside the UK unless required to do so by law.
10. Data Breach Notification
In the event of a data breach that might compromise your personal information, we will notify your organization in accordance with our contractual agreements and applicable laws.
11. Changes to This Privacy Policy
Any changes to this privacy policy will be communicated to your organization's administrator.
12. Contact Information
If you have any questions or concerns about this Privacy Policy, please contact:
Privacy Contact: emmaAI
13. Legal Basis for Processing
We process your data based on:
- The performance of our contract with your organization
- Our legitimate interests in providing and improving our services
- Your consent, where applicable
Thank you for trusting us with your data.