Skip to content
Data policy

What Mavio accesses, and why.

Mavio connects to a service only when you ask it to, and asks for the narrowest permission the feature can run on. This page lists every vendor Mavio can connect to, what each permission is used for, and what it does not allow.

EffectiveSep 14, 2026UpdatedSep 19, 2026
01

What this page covers

Mavio records and transcribes meetings on your own device, then sends what it produces wherever you ask. Everything on this page describes that second half: the third-party accounts you can connect, exactly what Mavio is permitted to do inside each one, and what it is not permitted to do.

Every connection is optional, is granted separately at the moment you turn that feature on, and can be revoked at any time. None of them is a condition of using Mavio — the product works with no integration connected at all.

Mavio is operated by Syntrigen Tech Private Limited. Recording, transcription and summarisation happen on your own device and in our own infrastructure. Connecting a vendor adds a destination for the results, and in the case of a calendar, a source of meeting titles and times.

This page supplements our Privacy Policy, which governs your Mavio account data itself. Where the two describe the same thing, the more specific statement here applies to that vendor.

02

Google

Mavio can connect to Google Calendar, Google Docs and Google Drive. Each is granted separately, so connecting one grants nothing about the others. A Google Chat integration is built but not yet available — see the end of this section.

Google Calendar — https://www.googleapis.com/auth/calendar.events.readonly. Mavio reads events from the calendars you select so it can list your upcoming meetings, start a recording already named after the right meeting, and assemble a brief from previous meetings with the same attendees. This scope is read-only. Mavio cannot create, modify, or delete an event, and the application rejects any such request internally rather than sending it to Google.

Google Docs — https://www.googleapis.com/auth/documents. Mavio creates a new Google Doc containing a meeting's transcript, summary, or action items, or appends that content to a document you explicitly nominate as the destination.

Google Drive — https://www.googleapis.com/auth/drive.file. Mavio lists the destination folder you choose, and uploads charts or images that it embeds into a document it has just created, deleting those temporary files once the embed is complete. This is the per-file Drive scope: it restricts Mavio to files it created or that you specifically opened with Mavio, and does not permit access to the rest of your Drive.

Google Chat — not yet available, and Mavio requests no Google Chat scope today. The integration is built, but a Google Chat app has to be created under a Google Workspace account and ours is not in place yet. When it is offered it will request https://www.googleapis.com/auth/chat.spaces.readonly, to list the spaces available to you so you can choose where summaries should go, and https://www.googleapis.com/auth/chat.messages.create, to post meeting summaries into the space you chose. It will not read the messages in those spaces: the read scope covers the list of spaces, not their contents.

Why not a narrower scope: https://www.googleapis.com/auth/drive.file already covers creating a document and editing one Mavio created, and it is the only Drive scope Mavio holds. https://www.googleapis.com/auth/documents is requested for one additional case — appending a meeting to a document that already exists and that you nominate as the destination. That file was not created by Mavio, so drive.file cannot reach it. Mavio requests no wider Drive access: it never asks for the full drive or drive.readonly scopes, so it cannot list, open, or download anything else you own.

Sign-in — openid, email, profile, and https://www.googleapis.com/auth/userinfo.email. Where you sign in with Google, Mavio receives your name, email address, and profile picture in order to identify your account and to show which Google account a connection belongs to.

03

Google Limited Use

Mavio's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. That policy is published at https://developers.google.com/terms/api-services-user-data-policy.

Providing user-facing features: we use Google user data only to provide and improve the features described on this page, each of which is visible in the Mavio interface at the point where the data is used.

Transfers: we do not transfer Google user data to third parties except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger or acquisition after obtaining your explicit consent.

Advertising: we do not use Google user data for advertising, ad targeting, ad measurement, or any related purpose, and we do not sell it.

Human access: we do not allow humans to read Google user data except with your explicit consent for specific items, where necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and anonymised for internal operations.

04

AI and machine learning

The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. This includes the Google API Services User Data Policy and the Google Workspace API User Data and Developer Policy.

Mavio uses AI models, including models operated by third-party AI service providers, to power the features described on this page — for example, using the title and attendees of a Google Calendar event to name a recording or prepare a meeting brief. Google user data is sent to those models only to provide the feature you are using at that moment.

We do not use, transfer, or sell Google user data — whether raw, aggregated, anonymised, or derived — to create, train, fine-tune, or improve foundational or generalised machine-learning or artificial-intelligence models, whether our own or a third party's. We use AI service providers only under terms that do not permit them to use this data to train or improve their models.

The same commitment applies to data from every other vendor on this page, and to your meeting recordings and transcripts themselves.

05

What Google permissions do not allow

Mavio cannot create, edit, move, or delete Google Calendar events, and cannot see calendars you have not selected.

Mavio cannot browse, open, or download files in your Google Drive that it did not create.

Mavio cannot read anything in Google Chat. That integration is not yet available and neither Chat scope is requested today.

Mavio cannot read any Gmail mailbox. Mavio no longer integrates with Gmail at all and requests no Gmail scope.

Mavio cannot access Google services you have not connected. Connecting Calendar does not grant Google Docs, and disconnecting one does not affect the others.

06

Microsoft

Mavio can connect to Microsoft Word, Outlook Calendar, OneNote, Microsoft Teams, OneDrive and SharePoint through Microsoft Graph. Every one of them also requests User.Read, to identify the connected account, and offline_access, so the connection survives without asking you to sign in again.

Microsoft Word and OneDrive — Files.ReadWrite and Files.ReadWrite.All. Mavio creates a document from a meeting in the location you choose, and updates documents it created. Microsoft Graph does not offer a per-file equivalent of Google's drive.file scope, so this is the narrowest grant that can write a file at all.

Outlook Calendar — Calendars.ReadWrite. Mavio reads your upcoming events to list meetings and name recordings, the same as Google Calendar. The write half of this scope is what allows Mavio to add a meeting to your calendar when you ask it to; Graph does not expose a read-only scope that also supports that action.

OneNote — Notes.ReadWrite and Notes.Create. Mavio creates a page for a meeting in the notebook and section you choose.

Microsoft Teams — Team.ReadBasic.All, Channel.ReadBasic.All and ChannelMessage.Send. Mavio lists your teams and channels so you can choose a destination, then posts meeting summaries to the channel you chose. It does not read channel conversations.

SharePoint — Sites.ReadWrite.All and Files.ReadWrite.All. Mavio writes meeting documents to the site and library you nominate.

Mavio does not integrate with Outlook Mail and requests no Microsoft mail scope. Mail.ReadWrite and Mail.Send were removed in September 2026.

07

Other integrations

The integrations below all follow the same shape: Mavio reads only enough to let you pick a destination, and writes only the meeting output you asked it to send. None of them is used to read your existing content back into Mavio unless that is the feature you turned on.

Collaboration — Slack (channels:read, groups:read, im:read, users:read and users:read.email to list channels and people, chat:write and chat:write.public to post a summary, files:write to attach one, commands for the /mavio slash command), Google Chat (not yet available — see the Google section), Zoom Chat (chat_channel:read:user, chat_message:write:user, user:read:user), Webex (spark:rooms_read, spark:messages_write, spark:people_read), and Microsoft Teams (covered above).

Notes and documents — Notion, which grants access to the specific pages you select in Notion's own picker rather than through scopes; Confluence (read and write for page, space and content); Google Docs, Microsoft Word and OneNote (covered above); and Obsidian, which is a local vault folder on your own machine and involves no account, no OAuth and no network access.

Task and project trackers — Jira (read:jira-work, read:jira-user, write:jira-work, manage:jira-project), Linear (read, write, issues:create), Monday (me:read, boards:read, boards:write), plus Asana, Trello and ClickUp. Mavio creates issues or cards from action items, and reads project and board lists so you can choose where they go.

CRM — HubSpot (crm.objects.contacts and crm.objects.deals read and write, crm.schemas read), Pipedrive (deals, persons, contacts and activities), Zoho CRM, Salesforce, Close and Copper. Mavio logs a meeting against the contact, deal or opportunity you choose, and reads those records to find the right one.

Storage and data — Google Drive, OneDrive and SharePoint (covered above), Dropbox (files.metadata.read, files.content.write), Box (root_readwrite, the only scope Box offers for file and folder access), Egnyte, and Airtable (schema.bases:read, data.records:read, data.records:write).

For any integration, the authoritative list of what you are granting is the consent screen that provider shows you at the moment you connect. We deliberately do not restate every scope string for every vendor here, because a list that drifts out of date is worse than no list — the Google and Microsoft sections above are stated in full because those are the grants under formal review.

08

Processors and sub-processors

Speech to text: meeting audio is transcribed by Deepgram. Audio is sent for transcription, and the recording is deleted once the transcript exists, subject to your plan's retention settings.

AI models: summaries, action items, meeting briefs and the Eva assistant run on models from OpenAI, Anthropic, Groq and Google. Which provider handles a given request depends on the model configured for that feature.

None of these providers is permitted to use your data to train or improve their models, and none receives data for any purpose other than returning the result of the request Mavio made. See the AI and machine learning section above.

Infrastructure: Mavio runs on Amazon Web Services, with the database, authentication and file storage provided by Supabase. Payments are processed by Paddle, which receives your billing details and not your meeting content.

Meeting content is never sold, never used for advertising, and never used to train a generalised model — whether it came from a recording, a transcript, or a connected vendor.

09

How connected data is stored and secured

OAuth tokens are encrypted at rest and used only to make the API calls described on this page on your behalf. They are never exposed to other users or to the browser.

Data retrieved from a vendor — for example the title and time of an upcoming meeting — is stored against your account and is subject to the retention rules in our Privacy Policy and to your plan's retention settings.

All data is encrypted in transit using TLS and at rest using AES-256. Access by our personnel is restricted, logged, and governed by the human-access commitment stated above.

Disconnecting an integration revokes the token with the provider where that provider supports revocation, and deletes the stored credential either way.

10

Reviewing and withdrawing access

In Mavio, open Settings → Integrations and disconnect the service you no longer want connected. Mavio revokes the token and deletes the stored credentials for that connection.

You can also review and revoke Mavio's access from the provider's own account settings, which takes effect immediately regardless of what Mavio does. For Google that is https://myaccount.google.com/permissions, and for Microsoft https://account.microsoft.com/privacy.

Deleting your Mavio account removes the stored credentials for every connected service. See the data retention section of our Privacy Policy for the full timeline.

Questions

Questions about a specific permission?

If anything here is unclear, or you want detail on a particular scope before connecting, our privacy team will answer directly.