Legal

Privacy policy

What we collect, why, who it's shared with and the choices you have.

Effective 09/29/2026

1. Who we are

DebriefIQ is provided by DebriefIQ (“we”, “us”), 274 Nespral Dr., San Antonio, TX 78253. You can reach us about privacy at support@debriefiq.com.

Companies use DebriefIQ to coach their sales teams. For the call data a company brings into DebriefIQ, that company is in charge of the data (the “controller”) and we process it on its behalf. For our own website, sign-in accounts, billing records and contact form messages, we are the controller.

2. What we collect

  • Account details: your name, email address, company and role, from your Google or Microsoft sign-in.
  • Call data: transcripts of calls your team records, which include what prospects and customers said on those calls, and the scores, coaching, notes and follow-ups DebriefIQ creates from them.
  • Calendar data: event titles, times, meeting links and attendee names and email addresses, used to match calls to accounts and prepare for upcoming calls.
  • CRM data: company, contact and deal names and identifiers, used to log each call against the right record.
  • Connection tokens: the access tokens for the services you connect, encrypted at rest.
  • Billing records: your subscription status, seat count and Paddle customer ID. Paddle collects your payment details; we never see or store card numbers.
  • Contact form messages: your name, email, company, team size and message.
  • Technical data: our servers keep standard logs, such as IP addresses and request times, to run and secure the service.

DebriefIQ does not store call audio or video.

3. How we use it

We use personal data to provide DebriefIQ (importing, scoring and coaching calls, and syncing with the tools you connect), to support customers, to bill subscriptions, to keep the service secure and to tell you about changes to the service. We don't sell personal data, don't use it for advertising and don't use call data to train AI models.

4. Who we share it with

We share data only with the service providers that help us run DebriefIQ, and only as needed for that:

  • Google: sign-in, Google Calendar and Google Meet (when you connect them), and the Gemini API, which processes transcripts to score calls and write coaching. We use Gemini's paid service, under which Google doesn't use prompts or responses to improve its products.
  • Microsoft: sign-in, Outlook Calendar and Microsoft Teams (when you connect them).
  • Zoom, HubSpot, Salesforce and Slack: only when your company connects them.
  • Paddle.com: our reseller and Merchant of Record, which processes payments, taxes and invoices. See Paddle's privacy policy for how it handles your data.
  • Hosting: Google Cloud.

We may also disclose data if the law requires it, or as part of a merger or acquisition, in which case this policy continues to apply to it.

5. How DebriefIQ uses Google user data

When you sign in with Google or connect your Google account, you choose to give DebriefIQ access to the data below. We ask only for what the features need, and you can revoke access at any time.

Data we access

  • Basic profile (openid, email, profile): your name and email address, to sign you in and to put you in your company's workspace.
  • Google Calendar, read-only (calendar.readonly): the titles, times, meeting links and attendee names and email addresses of your calendar events, to find your upcoming sales calls, match recorded calls to the right account and prepare you for the next call. DebriefIQ cannot create, change or delete calendar events.
  • Google Meet, read-only (meetings.space.readonly): the transcripts and participant lists of Meet calls you recorded, so each call can be scored and coached. DebriefIQ does not access Meet audio or video, and cannot join, start or change meetings.

How we use it

Only to provide DebriefIQ's features to you and your team: scoring and coaching your calls, tracking follow-ups, and showing your upcoming calls. We don't use Google user data for advertising, we don't sell it, and we don't use it to build profiles unrelated to the service. People at DebriefIQ don't read it unless you ask us to (for example for support), it's needed for security or abuse investigations, or the law requires it.

Sharing

Call transcripts, including those from Google Meet, are sent to Google's Gemini API to produce scores and coaching. We use Gemini's paid service, under which Google doesn't use prompts or responses to improve its products. Transcripts are also visible to the people in your company's DebriefIQ workspace. If your company connects HubSpot or Salesforce, a summary note of each scored call and its follow-up tasks are written to your CRM. We don't transfer Google user data to anyone else, except as needed to run the service (our hosting provider, Google Cloud), to comply with the law, or as part of a merger or acquisition with notice to you.

No AI model training

We do not use Google user data, including data from Google Workspace APIs, to develop, improve or train generalized or non-personalized AI or machine learning models.

Storage and protection

Data is stored on servers hosted by Google Cloud, in a separate database for each company, and transmitted over encrypted HTTPS connections. The access tokens Google gives us are encrypted at rest with AES-256-GCM. Access to the servers is limited to the people who operate DebriefIQ.

Retention and deletion

  • Calendar events are refreshed as your calendar changes; events removed from your calendar are removed from DebriefIQ at the next sync.
  • Calls, transcripts and their scores are kept while your company uses DebriefIQ, and anyone with access can delete a call from its page.
  • Disconnecting Google in Settings deletes the stored access tokens immediately and stops all further access.
  • To delete your account or your company's workspace and all its data, email support@debriefiq.com. We delete it within 30 days of your request.

Revoking access

You can remove DebriefIQ's access at any time from Settings in DebriefIQ, or from your Google Account at myaccount.google.com/permissions.

Limited Use

DebriefIQ's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

6. Cookies

DebriefIQ uses only the cookies it needs to work: one that keeps you signed in, one that protects the sign-in process, and a few that remember display preferences such as a collapsed sidebar. We don't use advertising or analytics cookies. Paddle's checkout may set its own cookies when you pay.

7. How long we keep it

We keep workspace data while your company uses DebriefIQ. Deleted calls are removed from our database. When your subscription ends, you can ask us to delete your workspace data and we'll do so within 30 days of your request. We keep contact form messages for up to two years, and billing records for as long as tax law requires.

8. Security

Each company's data is kept in its own database, access tokens are encrypted, and DebriefIQ asks for read-only access wherever it can. See our security page for more.

9. International transfers

Our providers may process data in countries other than yours, including the United States. Where the law requires it, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

10. Your rights

Depending on where you live, you may have the right to access, correct, delete or export your personal data, and to object to or restrict how we use it. Email support@debriefiq.com and we'll respond within the time the law requires. If your data is in DebriefIQ because your employer or a company you spoke with uses it, we may refer your request to that company. You can also complain to your local data protection authority.

11. Children

DebriefIQ is a business tool and isn't meant for anyone under 18.

12. Changes

We'll post any update here with a new effective date, and tell customers by email or in DebriefIQ before a material change takes effect.