›Proxy
How it worksProductSecurity
Sign inGet started

Legal

Privacy Policy

Last updated August 18, 2026

Who we are

Proxy is an AI teammate that joins your meetings, answers questions grounded in your codebase, and drafts follow-up work. This policy explains what data we process, why, and the controls you have. It covers useproxy.co and the Proxy service. Your company (the customer) is the data controller; Proxy is the processor acting on your instructions.

What we process

  • Account & identity — your name, work email, and organization domain, from Google (or Microsoft) sign-in, to create and secure your account.
  • Connected-service metadata — the repositories, channels, and calendars you connect, and the scoped tokens needed to read them. Tokens are encrypted at rest (AES-256-GCM) and held only by our control plane.
  • Meeting content — while Proxy is in a live meeting, it consumes the audio/transcript stream to respond. We process it in real time; we do not retain the raw transport stream.
  • Work product — meeting notes, answers, and drafted changes (e.g. pull requests) Proxy produces, stored to your tenant so your team can review them.
  • Operational logs — errors, usage, and cost metering, tagged to your tenant, to run and bill the service.

How we use it

Solely to provide the service: to answer in meetings grounded in your code, to produce the notes and drafts you ask for, to secure and meter usage, and to support you. We do not sell your data, and we do not train foundation models on your content.

Data retention & isolation

  • Every customer is isolated: separate per-tenant storage and a separate per-meeting sandbox. One company's data is never shared with another.
  • The live transport stream is consumed in the moment and not retained.
  • Derived artifacts (notes, a code map, drafts) persist to your tenant until you delete them or offboard, at which point they are purged.
  • Every world-touching action — a pull request, a message — is a draft that waits behind a human click. Proxy never pushes or sends on its own.

Sub-processors

We rely on a small set of vendors to deliver the service: Google Cloud (hosting, in the United States), Anthropic (the Claude model), meeting-transport and transcription providers (Recall, and AssemblyAI through Recall), OpenAI (the live voice session, which receives a meeting's audio and transcript and produces Proxy's spoken replies), and a sandbox provider (E2B). Each processes data only to perform its function. A current list is available on request.

Security

Least-privilege, read-only, revocable scopes on everything we connect. Secrets live in a managed secret store, never in code. Per-tenant credentials are encrypted with domain-separated keys. The meeting sandbox holds no push or send credentials — those stay host-side, behind your approval.

Your rights & choices

You can disconnect any integration, revoke access, export your notes, or delete your organization's data at any time from the console, or by emailing us. We honor access, correction, and deletion requests as required by applicable law.

Contact

Questions or requests: privacy@useproxy.co.

This page describes our current practices and will evolve as the product does. It is provided for transparency and is not a substitute for the data-processing agreement (DPA) your organization signs with us.

›Proxy

An AI teammate that joins your meetings knowing your codebase — and does the work.

PrivacyTermsDPASecurityContact
© 2026 Proxy.