Privacy Policy — Integrity
Privacy Policy
Last updated: July 19, 2026
Integrity ("we", "us") — operated by Integrity, Inc., 701 Tillery Street Unit 12, 2457, Austin, TX 78702, USA — provides an AI-native workspace at app.integrity.sh. We are the data controller for the personal data described here. This policy explains what we collect, why, and the choices you have.
Data we collect
- Account data — your email address, name, and optional avatar, used to create and secure your account.
- Workspace content — the notes, documents, canvases, files, meeting recordings, transcripts, and chat messages you and your team create or import. This content belongs to you.
- Billing data — subscription and usage records. Payments are processed by Stripe; we never store card numbers.
- Technical data — standard server logs (IP address, user agent, timestamps) kept for security and debugging.
Meeting recording and transcription
Meetings recorded inside Integrity stream their audio to our speech-to-text providers (Deepgram, and in some configurations AssemblyAI) to produce the live transcript. The audio and transcript belong to your workspace; you are responsible for obtaining participant consent where required.
Connected integrations
When you connect a third-party service (Zoom, Google, Telegram, or an MCP server), we store the credentials or identifiers needed to act on your behalf — OAuth tokens for Zoom, Google, and MCP servers (encrypted at rest), or the chat linkage for the Telegram bot. They are used only to provide the feature you connected, and disconnecting an integration deletes them.
Zoom integration
- We access the audio transcript files of cloud recordings for meetings you host, and your basic Zoom profile (user and account identifiers) so we can route those transcripts to your workspace. We do not access meeting video or audio.
- Imported transcripts become workspace content in your Meetings section, visible to your workspace members, and can be edited or deleted by you at any time. If enabled, we generate an AI summary of the transcript.
- Zoom OAuth tokens are encrypted at rest. If you disconnect the integration in Integrity, or remove the app from your Zoom account, we delete the stored connection and its tokens.
AI processing
Integrity's AI features send relevant workspace content to AI model providers to fulfill your requests — for example, summarizing a meeting transcript. Our primary providers (Anthropic, OpenAI, Google) are used under API terms that do not permit training on your data; specific features may use additional model providers listed below under their respective terms.
Service providers
We never sell your data. We share it only with the providers that run Integrity, and only as needed to provide the service:
- Infrastructure — Hetzner (compute, Germany), Neon (database, Germany), Cloudflare (file storage and delivery, EU region).
- Payments — Stripe. Email — Amazon Web Services (SES).
- AI models — Anthropic, OpenAI, Google, and for specific features fal.ai, Nebius, DeepSeek, Gonka, Z.ai, or xAI.
- Speech-to-text — Deepgram (and in some configurations AssemblyAI).
- Error monitoring — Sentry (EU ingest).
- The integrations you explicitly connect (Zoom, Google, Telegram, MCP servers).
We may disclose data if required by law.
International transfers
Your content is stored in the EU (Germany). Some providers above (e.g. AI model providers, Stripe, AWS, Sentry) may process data in the United States or other countries; where they do, we rely on their standard contractual safeguards for such transfers.
Cookies
The app uses strictly necessary cookies only: a session cookie to keep you signed in and a CSRF token to protect against forged requests. Our marketing site (integrity.sh) uses Google Analytics to understand visits; the app itself does not.
On the marketing site, Google Analytics runs without cookies by default: we count the visit, but nothing is stored on your device and no identifier follows you between visits. Analytics cookies are set only after you accept them. Where consent is legally required — the EU and EEA, the UK, and Switzerland — we ask before setting any, and declining keeps measurement cookieless rather than switching it off.
Security
All traffic is encrypted in transit (TLS). Integration tokens are encrypted at rest. Webhook endpoints verify cryptographic signatures. Access to workspace content is scoped by workspace membership.
Retention and deletion
Workspace content is kept for as long as your workspace exists. When you delete content, a workspace, or your account, it is removed or rendered permanently inaccessible in our systems; residual copies held by our infrastructure providers expire on their standard schedules. Server logs are kept for a limited period for security and debugging, then discarded.
Your rights
You can access, export, correct, or delete your data at any time from the app, or by writing to support@integrity.sh. Depending on your jurisdiction (e.g. GDPR), you may also have rights to portability, restriction, and objection — the same address handles those requests. We process your data to perform our contract with you, for our legitimate interest in securing and improving the service, and with your consent where the law requires it.
Children
Integrity is not directed to children under 16, and we do not knowingly collect their data.
Changes
We will update this page when our practices change and revise the date above. Material changes will be announced in the app.