Last updated: 5/13/2026
Introduction
At Caven, transparency and privacy are core to our mission. We use trusted AI providers to deliver our speech-to-text transcription and meeting summarization features. This page explains how these services process your data and the steps we take to protect it.
AI Services Used
AssemblyAI
We use AssemblyAI's EU endpoint to provide speech-to-text transcription of your recorded meeting audio. AssemblyAI securely processes audio streams to convert spoken words into text transcripts with no training on customer data.
OpenAI
We use OpenAI's enterprise APIs for optional transcript summarization, action items, and insight extraction. Where enabled, requests are routed through EU-oriented OpenAI configurations or a customer-controlled EU endpoint.
Data Processing Principles
When you use Caven's AI features, the following principles apply:
- AI providers only process the specific data required to perform the requested transcription or summarization.
- Data is processed only when you explicitly record a meeting.
- Our providers are contractually prohibited from using any customer data (including audio and text) for advertising or AI model training.
- AssemblyAI transcription is sent through its EU endpoint, and OpenAI summarization is limited to EU-oriented or customer-controlled EU routing where enabled.
- All processing utilizes secure, enterprise-grade APIs with strict privacy controls in place.
Google Calendar Data
Caven accesses limited Google Calendar metadata through the Google Calendar API to detect scheduled meetings and facilitate automatic recording workflows.
The following metadata may be accessed:
- Event title
- Event start and end time
- Event participant email addresses
Google Calendar metadata is strictly separated from our AI processing pipelines and is never shared with AssemblyAI, OpenAI, or any other third-party AI providers.
Security and Privacy Commitment
Caven is designed from the ground up with privacy in mind. We ensure your data is protected using:
- End-to-end encrypted data transfers (TLS 1.3).
- Secure, EU-hosted infrastructure for all core processing.
- Minimal data processing practices-we only handle what is strictly necessary.
- Zero-retention AI APIs, meaning your data is ephemerally processed and immediately discarded by the AI providers once the task is complete.
For more comprehensive details on how we handle and protect all of your personal data, please review our full Privacy Policy and our Data Processing Agreement (DPA).