Aberyarn LogoAberyarn
AboutPricing
LoginGet Started
  • About
  • Pricing
  • Login
  • Get Started

Privacy Policy

This Privacy Policy describes how Aberyarn (“we”, “us”, or “our”) collects, uses, and protects information in connection with our communication platform and related services (collectively, the “Service”). We are based in Scotland, United Kingdom, and this policy is governed by UK GDPR and the Data Protection Act 2018.

By using the Service, you acknowledge that you have read and understood this policy.

1. Information We Collect

We collect the following categories of information:

  • Account information: your name, email address, and organisation details provided when you sign up.
  • Post and communication content: updates, summaries, titles, descriptions, and audience targeting preferences you create within the Service.
  • Meeting data: meeting titles, agendas, scheduled times, locations, and the identities of participants you add when scheduling meetings through the Service.
  • Google Calendar data: if you choose to connect your Google account, we access your calendar free/busy information and event data solely to check availability and create calendar events on your behalf. We also store a Google OAuth refresh token securely to maintain this connection. See Section 6 for full details.
  • Slack workspace data: when an admin connects your organisation's Slack workspace, we store the workspace ID, team name, and a bot access token to enable posting updates to Slack channels and sending direct messages to users. See Section 7.
  • Device and push notification data: if you opt in to browser push notifications, we store a push subscription endpoint unique to your device/browser combination, which we use to send you notifications. You can revoke this at any time via your browser settings or the Service.
  • Engagement and behavioural data: we record your interactions with posts — including whether you have viewed a post, when you were notified about it, and your response status. We also store your feedback submissions, including your message, the page you were on, and your browser user-agent string.
  • Usage data: anonymous, aggregated information about how the Service is used, collected via Plausible Analytics. This contains no personal information and cannot identify any individual. See Section 10.
  • Communications: messages you send to our support team.

2. Legal Basis for Processing

Under UK GDPR, we process your personal data on the following legal bases:

  • Contract performance: processing necessary to provide the Service you have signed up for, including operating your account, delivering posts, and scheduling meetings.
  • Consent: where you explicitly connect your Google Calendar, enable push notifications, or connect your organisation's Slack workspace, we process that data on the basis of your consent, which you may withdraw at any time in your account settings or via your browser.
  • Legitimate interests: improving the Service, preventing fraud, maintaining security, and sending catch-up emails based on your engagement patterns — where these do not override your rights.
  • Legal obligation: where we are required to process data to comply with applicable law.

3. How We Use Information

We use the information we collect to:

  • Operate, maintain, and improve the Service.
  • Generate AI-assisted summaries and meeting agendas based on content you provide.
  • Deliver updates via the in-app feed, email, Slack, or push notifications.
  • Check participant availability and schedule meetings on your behalf when you use the meeting scheduling feature.
  • Send transactional communications such as email notifications and security alerts.
  • Send automated catch-up emails that intelligently select which posts to surface based on your engagement history, urgency flags, deadlines, and post status — designed to help you stay on top of important updates.
  • Send deadline reminder notifications automatically when post deadlines are approaching.
  • Provide customer support and respond to enquiries.
  • Comply with legal obligations.

We do not use your content or calendar data for advertising, and we do not build behavioural profiles for marketing purposes. Automated emails (catch-up and deadline reminders) are solely for Service functionality.

4. AI Processing

We use Anthropic's Claude to generate audience-tailored summaries and meeting agendas. When you create a post or schedule a meeting, the relevant content (post title, description, and participant context) is sent to Anthropic's API for processing.

Anthropic processes this data solely to return a response and does not use your content to train their models under their API terms. We do not send calendar event details or personal calendar data to Anthropic. You can read Anthropic's privacy policy at anthropic.com/privacy.

5. Google Calendar Integration

Aberyarn offers an optional Google Calendar integration to enable meeting scheduling. If you choose to connect your Google account, we request the following permissions:

  • calendar.events: to create calendar events and send invites when a meeting is scheduled.
  • calendar.readonly: to read your calendar events for the purpose of checking availability.
  • calendar.freebusy: to check your free/busy status without reading event details.

We store a Google OAuth refresh token securely in our database to maintain the connection between sessions. We access your calendar data only to check availability and create events on your behalf. We do not read, store, or share the content of your calendar events. We do not use your Google Calendar data for any purpose beyond the meeting scheduling feature.

You can disconnect your Google Calendar at any time from your account settings. Disconnecting will revoke our access and delete your stored refresh token. You can also revoke access directly from your Google Account permissions page.

Aberyarn's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

6. Slack Integration

Aberyarn offers an optional Slack integration that enables posting updates to Slack channels and sending direct messages to users. When an organisation admin installs the Slack integration, we:

  • Store the Slack workspace ID, team name, and a bot access token to authenticate with Slack's API.
  • Post updates to channels you configure and send direct messages to users who have linked their Slack accounts.
  • Access public channel information to populate channel selection lists.

We do not read the content of your Slack conversations beyond what is necessary to post our own messages. Only organisation admins can install or remove the Slack integration. Users may unlink their individual Slack accounts at any time in their notification settings.

7. Push Notifications

If you opt in to browser push notifications, we subscribe your browser to our push notification service using VAPID (Voluntary Application Server Identification). This stores a unique endpoint URL associated with your device/browser combination. We use this endpoint solely to send you notifications about activity in the Service (mentions, replies, meeting invitations).

You can revoke push notification permission at any time via your browser settings or by disabling notifications in the Service. Revoking will delete the subscription endpoint from our servers.

8. Sharing and Disclosure

We do not sell your personal information. We share data only in the following circumstances:

  • Service providers: we use Supabase (database and authentication), Railway (hosting), Anthropic (AI processing), Stripe (payment processing), Resend (email delivery), and Plausible (analytics). Each is bound by data processing terms and may only use your data to provide their services to us.
  • Google: when you connect your calendar, data is exchanged with Google APIs as described in Section 5.
  • Slack: when connected, messages are posted to your Slack workspace via Slack's API.
  • Within your organisation: posts and meeting details are shared with the colleagues and teams you designate within the Service.
  • Legal requirements: we may disclose information if required by law, court order, or to protect the rights, property, or safety of Aberyarn or others.

9. Data Retention

We retain your account data for as long as your account is active or as needed to provide the Service. Post history is subject to retention limits based on your subscription plan. Meeting data is retained for as long as necessary to provide the Service and for a reasonable period thereafter for legal and support purposes.

Google OAuth tokens are deleted when you disconnect your calendar or delete your account. When your account is closed, we will delete or anonymise your personal data within 30 days, except where retention is required by law.

10. Your Rights

Under UK GDPR, you have the following rights:

  • Access: request a copy of the personal data we hold about you.
  • Rectification: ask us to correct inaccurate or incomplete data.
  • Erasure: request deletion of your personal data, subject to legal retention requirements.
  • Restriction: ask us to restrict processing of your data in certain circumstances.
  • Portability: receive your data in a structured, machine-readable format.
  • Objection: object to processing based on legitimate interests.
  • Withdraw consent: where processing is based on consent (e.g. Google Calendar), withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at support@aberyarn.com. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).

11. Cookies and Analytics

We use essential cookies to keep you signed in and to remember your session preferences. We do not use advertising or third-party tracking cookies.

For analytics, we use Plausible Analytics — a privacy-first, EU-hosted service (servers in Frankfurt, Germany). Plausible does not use cookies, does not collect personal data, does not track individuals across sites or devices, and does not store IP addresses. All data is fully anonymised and aggregated. No cookie consent banner is required. You can read more at plausible.io/privacy.

12. Security

We implement appropriate technical and organisational measures to protect your data against unauthorised access, loss, or misuse. All data is transmitted over encrypted connections (HTTPS). OAuth tokens are stored encrypted at rest. However, no system can guarantee 100% security, and you are responsible for maintaining the confidentiality of your account credentials.

13. International Transfers

Some of our service providers (including Anthropic and Supabase) may process data outside the UK or EEA. Where this occurs, we ensure appropriate safeguards are in place — such as Standard Contractual Clauses or adequacy decisions — consistent with UK GDPR requirements.

14. Children's Privacy

The Service is not directed to children under 16. We do not knowingly collect personal information from children. If we learn that a child has provided us with personal information, we will delete it promptly.

15. Updates to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date below. For material changes, we will notify users by email or via a prominent notice in the Service. Your continued use of the Service after changes become effective constitutes acceptance of the updated policy.

16. Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, please contact us at support@aberyarn.com.

Last updated: 3 June 2026