Conversation intake
The signed-in user can connect Google Meet for automatic transcript intake, import a full speaker-labelled transcript, or use manual audio upload as a fallback. Google access is read-only and its OAuth credentials are encrypted at rest. For manual upload, the user confirms authority and Callsect validates the relevant format and size. Audio duration is also verified. Every path enforces the applicable account quotas.
During transcript import
- The user uploads TXT, MD, DOCX, VTT or a supported CSV export, or pastes speaker-labelled text.
- Callsect creates a non-billable preview and requires the user to confirm which detected speaker is YOU; all other detected speakers become CLIENT.
- The preview expires automatically after one hour if it is not confirmed and can be dismissed immediately.
- After confirmation, the saved transcript enters the normal analysis workflow without being sent to AssemblyAI.
Summary-only notes and transcripts that do not contain at least two distinguishable speakers are rejected before analysis.
During Google Meet import
- Callsect periodically checks the connected user's recent Meet conference records.
- For completed transcripts, it retrieves structured entries, speaker timing and participant display names through the Google Meet API.
- When one participant matches one existing Relationship exactly, the Callsect pipeline starts automatically.
- Ambiguous meetings wait in Meeting Inbox without affecting Conversations or Relationships until the user confirms the Customer.
Callsect does not download the original Google Meet recording and does not request general access to Google Drive.
During transcription
- The browser sends the recording over HTTPS to the Callsect backend hosted on Render.
- The backend writes it to temporary server storage for validation.
- The audio is uploaded to AssemblyAI through the configured EU API endpoint.
- AssemblyAI returns transcript text, detected language, speaker turns and timestamps.
- Callsect requests immediate deletion of the AssemblyAI transcript and its associated uploaded audio.
- The temporary Render-side file is deleted after the transcription attempt, including failure paths.
If the AssemblyAI upload succeeds but no transcript identifier is created, or if the deletion request fails, immediate remote deletion cannot be confirmed and AssemblyAI's standard retention rules may apply.
During analysis
Callsect sends the transcript text and speaker-labelled turns to OpenAI to generate the requested dissection, CRM notes, coaching, next-call preparation and relationship-memory updates. The original audio is not sent to OpenAI in the current implementation.
What Callsect keeps
- Call metadata, transcript, speaker segments, duration and limited transcription metadata.
- Linked sign-in provider and stable provider identifier; separately connected Meet identity, encrypted OAuth credentials, sync metadata and minimal source identifiers used to prevent duplicate imports.
- Dissection, CRM notes, coaching, next-call preparation and relationship history.
- Writing DNA data if the user chooses to create a profile.
- Account, legal-acceptance, quota, limited security records and first-party onboarding events needed to run and evaluate the private beta.
The original audio recording is not saved in the Callsect database. Product events do not contain transcript text, call titles, customer names or raw audio.
User control
A user can unlink Google Sign-In after establishing a password, disconnect Google Meet, dismiss an Inbox transcript or temporary transcript preview, delete an individual call, export account data in JSON, or permanently delete the whole account and its user-scoped data, including first-party product events. Deleting a call also updates or removes the related relationship memory. For questions or rights requests, contact privacy@callsect.com.
Important limitations
Callsect cannot determine whether the uploader has satisfied every recording-law, employment-law, confidentiality or customer-contract requirement. That responsibility remains with the uploader and their organisation. Provider logs, backups or exceptional failure paths may follow provider-configured retention periods as described in the Privacy Notice.

