Introduction
Bromance Studio SRL ("we", "our", "Kasset") operates the website https://kasset.com and the related Service: an AI note taker that captures conversations from your computer, your phone, and compatible wearable devices, then turns them into notes, decisions, and next steps.
This policy explains how we handle two distinct kinds of data: the data about you, our customer (your account), and the data you capture through Kasset about the people in your meetings and conversations.
Our two roles: controller and processor
For the data in your account (your name, email, organisation settings, and billing details), Kasset is the data controller.
For the personal data in the conversations you record (audio, transcripts, speaker labels, notes, decisions, and actions: together, "Conversation Data"), you are the controller and Kasset acts as your processor. We handle Conversation Data only to provide the Service and only on your documented instructions. That processing is governed by our Data Processing Agreement.
For account data, we rely on these lawful bases: the contract to provide the Service, our legitimate interests in keeping the platform secure and improving it with aggregated statistics, and legal obligations such as invoicing. For Conversation Data we act only on your instructions, as your processor.
Data we collect about you
You provide directly:
- Account information (name, email address, password if you choose one)
- Organisation settings (company name, members, invitations, plan, and paired devices)
- An optional profile picture, including one copied from Google or Microsoft when you sign in that way and have not set one yourself
- Waitlist or beta details, when you apply (typically a work email, company name, and company size)
- Billing information, when applicable, processed by our payment provider
We collect automatically:
- Technical metadata (IP address, browser or app type, pages visited, timestamps)
- Service usage data (features used, volume of recordings and seats). Usage events carry counts and identifiers, never a transcript or note.
You can create an account with email and password, or with Google or Microsoft. Those sign-in providers receive only that you are signing in to Kasset, and return an email, name, and optional picture. We do not store their access tokens. No Conversation Data is sent to them.
Connected calendars
You can optionally connect a Google or Microsoft calendar. Kasset requests read-only access and retrieves the calendars in your account and the events on calendars you choose to use. This can include calendar names and colours, and an event's title, start and end times, location, meeting link, organiser, invitees, their email addresses, and their response status. Kasset cannot create, edit, or delete calendar data through this connection.
We use calendar data to show upcoming meetings, countdowns, and meeting alerts, and to associate a meeting you choose to record with its title and invitees. Calendar list details and encrypted access tokens remain while the calendar is connected. Upcoming events are normally fetched live. To deliver meeting alerts, Kasset keeps a short-lived copy of eligible meetings from the next day and removes them after they pass. If you record a meeting, Kasset stores a snapshot of that event with the recording and deletes it when the recording is deleted. When you disconnect a calendar, Kasset asks the provider to revoke its grant and deletes its connection and stored calendar data from Kasset.
Data you capture through Kasset
To produce notes on your behalf, Kasset stores and processes the data you send us from the desktop app, the mobile app, a connected wearable, or the web app:
- Audio: the recording of a conversation. Audio is stored separately from the rest of your account, keyed by an opaque identifier. No email or name appears in the object key or its metadata.
- Transcripts: the text of what was said, with timestamped segments and a speaker label per segment. A label separates voices. It is not matched to a person, an account, or another recording.
- Notes and actions: summaries, decisions, action items, and other items the Service derives from a transcript, including actions prepared for the tools you connect.
- Device records: the wearable or phone you pair, so a recording can be attributed to the right workspace.
We process Conversation Data solely to provide the Service: to store your recordings, transcribe them, produce notes, and let you search what was said. Your Conversation Data is never used to train AI models, is never sold, and is never shared with third parties other than the sub-processors listed below and the tools you yourself connect and instruct Kasset to use. We do not sell account data either.
Your organisation
Conversation Data lives in the organisation you belong to. Other members and administrators may access it according to the permissions and policies that organisation sets, including whether administrators may read transcripts. If you join a workspace owned by your employer, they control that workspace.
How we use data
- Provide and maintain the Service
- Transcribe your recordings and produce notes, decisions, and actions
- Let you search and ask questions across your conversation memory
- Send transactional email (sign-in, password reset, invitations, digest)
- Protect the platform from abuse
- Improve the product (aggregated, de-identified statistics, never used to identify an individual)
- Comply with our legal obligations
AI processing
Speech recognition and language understanding run in France, on a per-request basis. Each request carries one recording's audio, or that recording's transcript. When a recording is associated with a connected calendar event, the language-understanding request can also include the meeting title and time and the names and email addresses of invitees. Kasset uses that context only to produce the requested note and help identify speakers. No account identifier, device identifier, or conversation history outside that recording is sent with the request.
Kasset also includes an agent that can act through the tools you choose to connect (see "Connected integrations" below). The agent can read your notes and transcripts to prepare an action, such as a draft email or a CRM entry. By default, any action with an effect outside Kasset is queued for your confirmation and runs only after you approve it. You can mark a specific automation you wrote as trusted so its actions run without a per-action confirmation; that choice is yours, per automation, and reversible. Without a connected tool, the agent can do nothing outside Kasset. Kasset does not make automated decisions about you that produce legal or similarly significant effects.
Notes and transcripts are generated automatically, and so are the actions the agent proposes. You should review them before you rely on them.
If you connect a third-party tool such as Claude or Cursor through MCP, that tool can query the conversation memory you choose to expose. Those providers are not our sub-processors for that purpose. You decide what to connect, and you are responsible for what that tool receives.
Google Workspace API data
Kasset's use of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Kasset does not use, transfer, or sell raw or derived Google Workspace user data to create, train, or improve foundational or generalized AI or machine learning models.
Connected integrations
Separately from the inbound access described above, you can connect outbound integrations: tools Kasset acts in on your behalf, such as your email, calendar, task manager, CRM, or any MCP server you point Kasset at. When you connect a tool and instruct Kasset to use it, through a confirmation, an automation you wrote, or a question you asked, Kasset sends that tool the data your instruction requires: typically note excerpts, transcript excerpts, and the details of the action itself.
Connections made from the built-in gallery are routed through Composio, our integration sub-processor, which hosts the sign-in flow, holds the OAuth tokens, and executes the tool calls. We have configured Composio not to retain tool-call payloads; it keeps audit metadata only. Connections to a custom MCP server go directly from our servers in France to that server, with no intermediary.
Outbound integrations are entirely optional and off by default. What a connected tool does with the data it receives is governed by that tool's own terms and privacy policy. You can disconnect a tool at any time from your settings, which stops all further data flow to it.
Website analytics
The marketing website uses Plausible, a cookie-less analytics service hosted in the European Union. It records page views without advertising cookies, session replay, or a marketing pixel. The application itself does not send Conversation Data to any analytics service. The application uses a session cookie so you stay signed in. The marketing website does not set advertising or tracking cookies.
Sub-processors
Kasset relies on the following sub-processors to operate the Service:
| Sub-processor | Role | Location |
|---|---|---|
| Scalingo | Application hosting, PostgreSQL database, and Redis queues | France |
| Scaleway | Temporary storage of recording audio | France |
| Mistral AI | Speech to text and interpretation | France |
| Letter | Transactional email, waitlist forms, and product events | Belgium (last-mile delivery via AWS SES, US / EU) |
| Composio | Integration execution and OAuth token custody, only for tools connected from the gallery (configured for zero payload retention; SCCs in place) | United States |
| Google Identity and Calendar | Optional sign-in and read-only calendar connection | United States |
| Microsoft Identity and Calendar | Optional sign-in and read-only calendar connection | United States |
Recording data (audio, transcripts, notes) stays in the European Union, with one opt-in exception: when you connect a tool from the integrations gallery and instruct Kasset to act in it, the data that instruction requires transits Composio in the United States. That flow exists only for users who connect a gallery integration, and carries only what the instruction sends, never your recordings wholesale. Custom MCP connections do not use Composio: they go directly from our French servers to the tool. When you connect a calendar, Google or Microsoft returns the account and calendar data you authorise Kasset to read. Kasset does not send Conversation Data to those providers as part of that inbound calendar connection. Letter's last-mile email delivery may leave the EEA; it carries system email and account fields, never a transcript or note.
We give customers reasonable prior notice before adding or replacing a sub-processor that processes Conversation Data, so you can object if needed.
We may also disclose data when the law or a valid legal request requires it (we notify you when we can), or if we sell or reorganise the business, to a successor who must honour this policy. We do not disclose Conversation Data for advertising.
Retention
- Account and Conversation Data: retained while your account is active, and deleted within 30 days of account closure.
- Audio: kept for the period you choose, then deleted. You can delete it as soon as a recording is processed, keep it for a set number of days, or keep it until you delete it. Transcripts and notes remain until you or your organisation delete them, or the account is closed.
- Conversations you delete from a workspace are removed promptly, including any remaining audio.
- Technical logs: retained for 30 days, then purged. Logs record identifiers, durations, and error codes. They do not record audio, transcripts, or the text of notes.
- Invoices: retained for 7 years (Belgian accounting law).
Your rights (GDPR)
For your account data, you can ask us to access, correct, export, or delete it; to restrict or object to certain processing; or to withdraw consent where we rely on it. To exercise these rights, email [email protected]. You also have the right to lodge a complaint with a supervisory authority. In Belgium that is the Data Protection Authority (APD / GBA).
For Conversation Data, the individual's rights are exercised through the customer who controls that data. If you were recorded in a meeting and wish to access or delete your data, please contact the organisation that used Kasset. We assist our customers in responding to these requests as their processor.
International transfers
Optional sign-in, connected calendars, last-mile email delivery, and gallery integrations use providers located in the United States. Where data is transferred outside the European Economic Area, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, including with Composio for the integration data flow described above. Conversation Data itself is hosted in France; it leaves the EEA only when you connect an integration and instruct Kasset to send data to it.
Security
All communications are encrypted in transit with TLS. Credentials and secrets are encrypted at rest. Audio is stored in a private bucket with no public URLs. Code and infrastructure access is restricted to a small set of administrators, who are bound to confidentiality. If we become aware of a breach of Conversation Data, we will notify the customer without undue delay and within 72 hours.
Minors
Kasset is a professional tool. The Service is not intended for people under the age of 16. If we learn we have collected data from someone under 16, we delete it.
Changes
We will notify you by email at least 30 days before any significant change to this policy takes effect.
Contact
Bromance Studio SRL · VAT BE1040.904.426 · [email protected]