Skip to main content
Platform Review
PricingSign in
← tday.com assessment

tday.com procurement policy evidence

Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.

Verified procurement policy findings for tday.com
TopicPlan or tierRiskTheir wordsSource
DPA, audit rights & data residencyAll applicable tiersunknown“ You have the right to request access to your personal information that we hold. You also have the right to request that we correct any personal information that is inaccurate, out-of-date, incomplete, irrelevant, or misleading. We do not charge a fee for you to access your personal information, although we may charge a reasonable fee for providing copies of information. We will respond to requests within a reasonable timeframe.”Captured 2026-09-25Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown“ You may request access to, export of, or deletion of your Slack integration data at any time by contacting us at privacy@tday.com . You can also disconnect your Slack workspace directly from your tday dashboard or by using the /markup disconnect command in Slack, which will immediately revoke access and deactivate all associated data. We will respond to data requests within 10 business days.”Captured 2026-09-25Open source →Finding permalink →
Data retentionAll applicable tiersunknown“ We take reasonable steps to protect your personal information from misuse, interference, loss, unauthorised access, modification, or disclosure. We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. Client files are retained for a minimum of seven years after the conclusion of our services, unless a longer retention period is required by law or for legitimate business purposes.”Captured 2026-09-25Open source →Finding permalink →
Data retentionAll applicable tiersunknown“ When you disconnect your Slack workspace from tday, your OAuth access token is revoked with Slack and your connection and conversation records are deactivated. Deactivated records are retained for up to 90 days for troubleshooting and audit purposes before being permanently deleted. Webhook delivery records (containing only event type and deduplication identifiers, not message content) are retained for operational integrity.”Captured 2026-09-25Open source →Finding permalink →
Data retentionAll applicable tiersunknown“Ordinary Chromium cache, site storage, permissions, and other profile state may therefore remain in local application data after the app closes. The app does not currently run a general profile or cache erasure during sign-out. This profile is separate from the encrypted Better Auth file and approval proof described above. Desktop approval security records are also kept on the tday server. They include the target and approving user and session references, hashes of the approval code and device nonce, the scheduled expiry, approval, consumption, denial, and revocation timestamps, and creation and update times. The raw approval code and device nonce are not stored in that database record. Expiry is derived from the scheduled expiry when the record is read and does not itself write a separate expiry timestamp or update the row. Approval, consumption, denial, and revocation update the applicable lifecycle timestamps. These records are not automatically deleted merely because the approval expires. Each successful desktop approval action also attempts to create a separate administrative audit row. It can include the acting administrator, action, target session reference, approval reference, browser session or scheduled expiry details when applicable, client IP address, and creation time. An audit-write failure does not block the approval action. These administrative audit rows have no automatic deletion period in the current system. ”Captured 2026-09-25Open source →Finding permalink →
Data retentionAll applicable tiersunknown“The durable record also keeps a meeting reference and snapshot, revision, actor identifiers, and creation or update timestamps. The Save action does not persist raw audio, the full transcript, raw extension signals, source IDs, or diarisation words and turns in the saved note record. Saved Meeting Assistant notes do not currently have an automatic expiry or deletion action. A Save audit record stores the administrator, meeting reference, action, note kind, client IP, and time, but not the note or transcript body. Deleting a user or meeting reference does not currently guarantee erasure of the saved note or its meeting snapshot.”Captured 2026-09-25Open source →Finding permalink →
Data retentionAll applicable tiersunknown“Deployment-enabled analytics and error telemetry can also run there under the same hosted-client configuration. If an admin route fails unexpectedly, operational logs may include the user ID, route path and meeting reference, route parameters, error message, and stack trace. Internal mirrored copies of ordinary runtime logs are retained for 60 days, and warning, error, or fatal logs for 120 days. Copies retained by hosting or AI providers are governed separately and are not covered by those internal periods.”Captured 2026-09-25Open source →Finding permalink →
Data retentionAll applicable tiersunknown“ During a live session, the browser client keeps the current transcript and interim text in application memory. Extension signals are treated as fresh for 30 seconds in the background registry and are removed lazily during later registry operations. The hosted client keeps at most 80 raw attribution events for 60 seconds. Its diarisation audio ring is bounded to 30 seconds. The client schedules a failed diarisation window for discard 30 seconds after its first failure and checks that deadline before each retry. It aborts a retry that is still running when the discard callback executes. Browser timer suspension may delay physical release until page execution resumes. A normal diarisation request is aborted after 30 seconds. The ring and retry window are cleared when capture is stopped or discarded, the meeting changes, or the page is unmounted. The transcription pre-roll is capped by chunk and encoded-size limits. Stopping capture closes audio tracks, connections, and audio buffers, but final transcript segments remain in the current page state until the transcript is cleared, the meeting changes, or the page is unmounted. Meeting Assistant creates a durable note record only when an administrator explicitly selects Save. The saved record contains formatted notes and structured summaries, updates, blockers, decisions, actions, and questions. Generated notes may include participant names, statements, decisions, or other transcript-derived information. ”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ We may collect personal information about you from third parties. If we do so, we will take reasonable steps to notify you that we have collected this information and the circumstances of its collection. Third-party sources may include service providers, business partners, or publicly available sources.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ Google is an AI service recipient in the following separate processing paths: Live transcription: the hosted browser or Mac renderer sends 16 kHz PCM audio directly to Google over a live connection using a one-use, short-lived credential. The long-lived Google API key stays on the tday server. Speaker-attribution metadata is attached to returned transcript text locally and is not sent alongside that live PCM stream. Diarisation: a separate audio window is sent through tday to Google approximately every 10 seconds. Each request is limited to 30 seconds and 2 MiB. tday sends the audio inline in a request configured with store: false and does not create a Google File API object. Rolling notes: the hosted browser or Mac renderer automatically sends tday the meeting title, prior outline, and up to 200 recent final transcript segments, including timestamps and any applied speaker names. tday sends Google up to 40,000 transcript characters, speaker labels, the meeting title, and the prior outline to generate updated notes. This rolling window may be sent again as the transcript changes. The request settings described above do not state or guarantee Google's own logging, abuse-monitoring, data-residency, training, or retention practices.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium“ We may disclose your personal information to third parties in the following circumstances:”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ Model-usage records keep the associated actor or user, model and provider, operation and category, token counts, cost, and timestamps. They do not contain the prompt, transcript, or generated note content. The hosted tday application also loads PostHog, Databuddy, Vercel Speed Insights, and Cloudflare Web Analytics on Meeting Assistant routes when those services are enabled for the deployment. They may receive standard technical and usage metadata, such as network and browser details, route or occurrence references, navigation, interactions, element attributes, performance measurements, and errors. PostHog session replay is enabled. tday marks the standup workspace for PostHog content masking, sanitizes Meeting Assistant pageview and exception locations, and omits standup-review API requests from PostHog network capture. These controls do not mean that every analytics provider receives identical fields or applies the same retention practices. When configured in a deployed build, Sentry receives client error reports and structured client logs through a first-party tday endpoint. Its error-triggered session replay is sampled for every captured error, with all text masked and all media blocked. Idle sessions are not sampled for replay, and default PII transmission is disabled. These controls do not prevent an error report or masked replay from carrying other technical context permitted by the Sentry configuration. The embedded Mac Chromium renderer loads the same hosted routes as a browser. ”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ To protect the rights, property, or safety of Altacomm, our users, or others We take reasonable steps to ensure that any third parties to whom we disclose your personal information are bound by privacy obligations in relation to your personal information.”Captured 2026-09-25Open source →Finding permalink →

Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.