Hestini

Privacy Policy

Last updated: February 24, 2026

1. Introduction

Hestini ("we", "our", or "us") is an enterprise AI-powered document management and collaboration platform. This Privacy Policy describes how we collect, use, store, and protect your personal information when you use our services.

2. Information We Collect

We collect the following categories of information:

  • Account information: Name, email address, profile picture, and organization details provided during registration or via Google OAuth sign-in.
  • Google Meet data: When you connect your Google account, we access Google Meet space links, calendar events (for scheduling meetings), and meeting transcripts (for AI-powered analysis and search). This data is accessed via the Google APIs listed in Section 5.
  • Documents and files: Files you upload to Hestini for processing, storage, and AI-assisted analysis.
  • Chat and interaction data: Messages you send through our AI chat interface and collaboration features.
  • Usage data: Log data such as IP addresses, browser type, and pages visited, collected automatically for security and analytics.

3. How We Use Your Information

  • To provide, maintain, and improve our services.
  • To create and manage Google Meet meetings on your behalf.
  • To schedule calendar events with meeting links.
  • To fetch and process meeting transcripts for AI-powered search and analysis.
  • To perform AI-assisted document analysis using Retrieval-Augmented Generation (RAG).
  • To communicate with you about service updates and support.
  • To ensure security and prevent abuse.

4. How We Store and Protect Your Data

  • OAuth tokens: Google OAuth tokens are encrypted using AES-256-GCM encryption and stored server-side only. Tokens are never exposed to the browser or stored in cookies.
  • Documents: Uploaded files are stored in Google Cloud Storage (GCS) with access controlled by signed URLs with expiration.
  • Database: All data is stored in encrypted databases with access restricted to authorized services.
  • Transport: All data in transit is protected using TLS/HTTPS encryption.

5. Google API Scopes and Usage

Hestini requests the following Google API scopes when you connect your Google account:

  • meetings.space.created: Used to create Google Meet spaces when you start instant or scheduled meetings from within Hestini.
  • calendar: Used to create calendar events with Meet links for scheduled meetings and to send invites to participants.
  • drive.meet.readonly: Used to fetch meeting transcripts from Google Drive after meetings end, enabling AI-powered transcript analysis and search within Hestini.

Hestini's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

6. Data Retention

  • Account data is retained for as long as your account is active. Upon account deletion, personal data is removed within 30 days.
  • Google OAuth tokens are deleted immediately when you disconnect your Google account or when your account is deleted.
  • Uploaded documents and generated artifacts are retained according to your organization's retention settings. Artifacts not linked to documents expire after 30 days.
  • Chat and interaction logs are retained for the duration of your account for service improvement.

7. Third-Party Services

We use the following third-party services to provide our platform:

  • Google APIs: Google Meet, Google Calendar, and Google Drive for meeting management and transcript access.
  • Google Cloud Storage: For secure document and file storage.
  • Google Gemini: For AI-powered document analysis and chat.

8. Your Rights

You have the right to:

  • Access your data: Request a copy of the personal data we hold about you.
  • Correct your data: Update or correct inaccurate personal information.
  • Delete your data: Request deletion of your account and associated data.
  • Revoke Google access: Disconnect your Google account at any time from Settings, which immediately deletes stored OAuth tokens. You can also revoke access from your Google Account permissions page.
  • Data portability: Request an export of your data in a standard format.

9. Data Sharing

We do not sell your personal data to third parties. Data is shared only with the third-party services listed in Section 7, strictly for the purpose of providing our services. Within your organization, document access is governed by your organization's permission settings.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page and updating the "Last updated" date. Continued use of our services after changes constitutes acceptance of the updated policy.

11. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us at: khiemtruong@hestini.com