PRIVACY POLICY

Introduction

Last Updated: July 10, 2026

This Privacy Policy ("Policy") explains how RapportScore.ai ("we," "us," "our," "Company," "Service"), operated by Rapport Score LLC, collects, uses, discloses, and otherwise processes personal data when you use our website, web application, browser extensions, integrations (including Zoom, Google Meet, or other platforms), APIs, and related services (collectively, the "Service").

We are committed to protecting your privacy and ensuring transparency about how we handle your data. Please read this Policy carefully. If you do not agree with our practices, please do not use the Service.

1. Data Controller and Contact Information

Service Provider:

Rapport Score LLC
1817 Crescent Boulevard, Suite 101-C
Orlando FL 32817
USA
privacy@rapportscore.ai

For privacy-related inquiries, you may contact us at privacy@rapportscore.ai.

2. Information We Collect

We collect personal data in the following categories:

2.1 Conversation Data

● Recordings and Transcripts: Audio recordings, video recordings, transcripts, and metadata from meetings and conversations you choose to record, upload, or integrate with RapportScore.ai (e.g., Zoom meetings, Google Meet calls, or other sources).

● Metadata: Meeting title, participants' names, email addresses, date, time, duration, and platform source.

● Communication Content: Text messages, chat logs, or other communication data you submit to the Service, including disfluencies, pauses, and timing information

2.2 Coaching and Analysis Outputs

● Rapport Scores: Automated analyses of conversations generating communication metrics and rapport scoring.

● Feedback and Suggestions: AI-generated coaching recommendations, identified patterns, and behavioral insights.

● Performance Metrics: Aggregated statistics about communication performance over time.

2.3 Account and Registration Data

● Name, Email Address, and Contact Information: Used to create and manage your account.

● Organization/Team Information: Company name, team membership, role, title, and department.

● Billing and Payment Information: Billing information (processed by Stripe), such as subscription status, invoices, and payment identifiers. We do not store full credit card numbers (tokenized by Stripe).

● Authentication Data: Passwords (encrypted), security questions, and multi-factor authentication settings.

2.4 Technical and Usage Data

● Device Information: Device type, operating system, browser type, browser version, and IP address.

● Log Data: Pages visited, features used, time spent on features, links clicked, errors encountered, and actions taken within the Service.

● Cookies and Similar Technologies: Identifiers stored on your device to enhance experience (see Section 6).

● Integrations: Data about connected platforms (e.g., Zoom, Google Meet) and frequency of use.

● Analytics: General usage patterns, feature adoption, and Service performance metrics.

2.5 Communication and Support Data

● Support Tickets: Messages, attachments, and information you provide when requesting technical support or customer service.

● Feedback and Surveys: Responses to surveys, feature requests, bug reports, and product feedback.

● Marketing Communications: Email addresses and preferences for receiving product updates, webinars, and promotional content.

2.6 Data You Provide About Others

If you upload recordings that include other individuals, or invite colleagues to your account, you are responsible for obtaining their consent and informing them of this Policy.

2.7 SMS Communications and Opt-In Details

Phone Number Collection: If you provide a phone number during account registration or through your account settings, you consent to receive SMS messages from RapportScore.ai for the purposes described in Section 2.5 (Communication and Support Data) and the Terms of Service Section 12A (SMS Communications and Compliance).

SMS Data Sharing: SMS Content is not shared with third parties except SMS providers.

Opt-In Method: We collect SMS consent through:

● Explicit checkbox at signup: I consent to receive appointment reminders and similar transactional messages from Rapport Score at the phone number provided. Message frequency may vary. Message & Data rates may apply. Reply HELP for help or STOP to opt-out. You can review our Terms of Service at https://app.rapportscore.ai/terms.html and Privacy Policy at https://app.rapportscore.ai/privacy.html.

● We maintain records of opt-in timestamps and consent method for compliance verification.

Opt-In Consent Language: By providing your phone number and checking the SMS opt-in box, you agree to receive SMS messages from RapportScore.ai. You consent to receive text messages about account security, billing, service updates, and customer support. Message and data rates may apply. Message frequency varies depending on your activity. You can opt out anytime by texting STOP to our SMS phone number, and youíll receive a confirmation message. Consent to receive SMS messages is not a condition of purchasing any product or service from RapportScore.ai. Reply HELP to any message for assistance. Carriers are not liable for delayed or undelivered messages.

Withdrawal of Consent: You can withdraw SMS consent at any time by:

● Texting STOP to our SMS number.

● Disabling SMS notifications in your account settings under Preferences

● Emailing privacy@rapportscore.ai with your phone number and request

Upon receipt of an opt-out request, we will remove your phone number from our SMS database within 24 hours and will no longer send SMS messages unless you re-opt-in.

Transactional SMS Exception: Even if you opt out of marketing SMS, we may continue to send transactional SMS messages necessary to maintain your account security and service (e.g., login codes, password resets, billing alerts critical to your subscription).

Data Protection: Your phone number is encrypted, stored securely, and will not be shared with third parties for SMS purposes. We do not sell, rent, or trade your phone number or SMS consent data.

2.8 Mobile Device Information Sharing Statement

Mobile Information Sharing: No mobile information, including opt-in data and consent, will be shared with third parties or affiliates for marketing or promotional purposes. All other data-sharing categories in this privacy policy exclude text messaging originator opt-in data and consent. We share your phone number and consent status strictly with our SMS service provider solely to facilitate message delivery; this provider is prohibited from using your information for any other purpose.

For Mobile App Users: If you access RapportScore.ai via our mobile app (iOS or Android), we collect and share certain device information with service providers:

Mobile Device Data We Collect:

● Device type and OS version (e.g., iPhone 14 Pro, iOS 17)

● Device identifier (IDFA on iOS; Android Advertising ID on Android)

● App version and installation date

● Mobile network type (WiFi, LTE, 5G)

● Device location (only with your explicit app-level permission)

● Push notification settings and token

How We Use Mobile Device Data:

● Service Delivery: Enable login, message delivery, crash reporting, and app performance optimization

● Analytics: Track app adoption, feature usage, and identify technical issues

● Security: Detect fraud, suspicious logins, and prevent unauthorized access

● Personalization: Remember preferences and customize your experience

Sharing with Third Parties: Mobile device information is shared with:

Third Party

Purpose

Data Type

Safeguard

[Crash reporting service, e.g., Sentry, Bugsnag]

Detect app crashes and bugs

Device ID, OS version, error logs

DPA + data minimization

[Analytics provider, e.g., Firebase, Amplitude]

App usage analytics

Device type, events, user flows

DPA + anonymization

[Push notification service, e.g., Firebase Cloud Messaging]

Send app notifications

Device token, notification preferences

DPA + encryption

Apple App Store / Google Play

App review, compliance, fraud prevention

Device identifier (anonymized)

Per app store terms

All third parties are contractually required to:

● Process data only on our instruction

● Not use your mobile data for their own purposes

● Maintain adequate security measures

● Comply with applicable privacy laws (GDPR, CCPA, etc.)

User Control: You can control mobile device data sharing by:

● Location: Disable location access in your device settings Privacy Location Services

● IDFA (iOS): Disable ad tracking in Settings Privacy Tracking toggle app off

● Android Advertising ID: Reset or opt out in Google Settings Privacy Ads

● Crash Reports: Contact support@rapportscore.ai to disable crash analytics (may affect troubleshooting)

● Push Notifications: Disable in app settings or device notification preferences

No Sale of Device Identifiers: We do not sell, rent, or trade your device identifiers (IDFA, Android Advertising ID) or device data to marketers or data brokers. Device data is used solely for app functionality and service improvement.

Data Retention: Mobile device data is retained in accordance with Section 9 (Data Retention). Device identifiers are logged for 12 months for analytics and security purposes.

3. Legal Basis for Processing (GDPR / UK GDPR)

We process personal data based on the following lawful grounds:

Processing Activity

Legal Basis

Purpose

Account creation and management

Contract

Provide the Service and manage your subscription

Conversation analysis and scoring

Contract

Deliver core coaching and analytics features

Service improvement and bug fixes

Legitimate interest

Enhance product functionality and user experience

Security and fraud prevention

Legitimate interest

Protect accounts and prevent unauthorized access

Analytics and usage insights (aggregated)

Legitimate interest

Improve Service performance and features

Marketing emails and product updates

Consent

Send promotional content (opt-in only)

Billing and payment processing

Contract

Process transactions and maintain records

Compliance with legal obligations

Legal obligation

Respond to lawful requests and legal proceedings

Automated decision-making / profiling

Contract (for core service); legitimate interest (for optimization)

Generate rapport scores and coaching insights

 

Consent: Where we rely on consent, we will obtain clear, explicit, informed consent before processing. You may withdraw consent at any time by contacting privacy@rapportscore.ai.

4. How We Use Your Data

We use the personal data we collect for the following purposes:

4.1 Core Service Delivery

● Generate rapport scores and communication analytics for uploaded conversations.

● Provide personalized coaching recommendations and feedback.

● Manage your account, subscription, and access to features.

● Process payments and send billing information.

● Provide customer support and respond to inquiries.

4.2 Service Improvement

● Analyze usage patterns to identify features and improvements.

● Conduct security audits and system monitoring.

● Troubleshoot technical issues and optimize performance.

● Train and improve our internal AI models and algorithms using aggregated stats and anonymized feedback for prompt tuning and QA review. We may use aggregated and de-identified data, as well as user feedback, to improve system performance, prompts, and scoring logic. We do not use customer conversation content to train public or third-party AI models. This does not apply to Google user data: data obtained through Google APIs (including Google Calendar data) is excluded from all model training and improvement activities, in any form.

4.3 Marketing and Communication

● Send product updates, new feature announcements, and promotional material (only with opt-in consent).

● Conduct surveys and gather feedback.

● Invite users to webinars, training sessions, or community events. Google user data obtained through Google APIs is never used for marketing, promotional, or advertising purposes.

4.4 Legal and Compliance

● Respond to legal requests, court orders, or regulatory inquiries.

● Enforce our Terms of Service and other agreements.

● Protect against fraud, abuse, and security threats.

● Comply with applicable laws, regulations, and industry standards.

4.5 Automated Decision-Making and Profiling

Rapport Scoring: RapportScore.ai uses automated decision-making to analyze conversation data and generate rapport scores, communication feedback, and coaching recommendations. These outputs are probabilistic and generated through AI models that evaluate patterns in communication style, tone, language, and engagement.

Limitations: Rapport scores are probabilistic AI outputs, not definitive assessments of skill or performance. Do not use as sole basis for employment decisions, terminations, or legal judgments. Accuracy depends on audio quality and context.

User Rights: You have the right to obtain human review or explanation of automated decisions that produce legal or similarly significant effects. If you wish to request human review of a rapport score or coaching suggestion, please contact support@rapportscore.ai.

4.6 Google User Data and the Google API Services User Data Policy (Limited Use)

If you connect your Google Calendar to RapportScore.ai to enable automatic recording of your scheduled video-conference meetings, we access Google user data through Google APIs under the following OAuth scopes:

● Calendar events (read-only) (https://www.googleapis.com/auth/calendar.events.readonly): event titles, start and end times, video-conference links, and attendee information from your calendar.

● Email address (https://www.googleapis.com/auth/userinfo.email): the email address of the Google account you connected.

How we use this data (and nothing else):

● We use your calendar events to identify your scheduled video-conference meetings so that, when you turn on automatic recording for a connected calendar, our recording assistant can join those meetings, and to label the resulting sessions (meeting title, time, and participants) inside your account.

● We use your email address solely to identify which Google account is connected and to display it back to you in your integration settings.

● Your Google authorization is used to establish the calendar connection with our calendar-sync processor, Recall.ai (a data processor acting on our instructions), which performs the ongoing calendar sync on our behalf. We do not separately store your Google OAuth token.

What we never do with Google user data:

● We do not sell it, and we do not use it for advertising or marketing of any kind.

● We do not use it to train, retrain, fine-tune, or improve any artificial intelligence or machine learning model, whether ours or a third party's, whether generalized or internal, in raw, derived, aggregated, or anonymized form.

● We do not transmit it to any AI/ML service provider.

● We do not allow humans to read it, except (a) with your explicit consent, (b) as necessary for security purposes such as abuse investigation, (c) to comply with applicable law, or (d) where the data has been aggregated and anonymized for internal operations in accordance with this Policy.

● We do not transfer it to any other party except to Recall.ai as described above.

Limited Use attestation: The use and transfer to any other app of raw or derived user data received from Google Workspace APIs by RapportScore.ai will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Disconnecting: You can disconnect your Google Calendar at any time in your RapportScore.ai integration settings. Disconnecting removes the calendar connection at Recall.ai and stops all future syncing. Meeting records already created from past recordings (such as meeting titles and attendee names used to label sessions in your account) are retained as part of your account history, consistent with Section 9 (Data Retention), unless you separately delete those sessions. You can also review or revoke RapportScore's access directly at https://myaccount.google.com/permissions.

5. Recording and Consent Requirements

5.1 Your Responsibility for Consent

You are responsible for ensuring that you have obtained the necessary consent from all participants in any conversation before recording, uploading, or submitting that conversation to RapportScore.ai.

Recording Laws Vary by Jurisdiction:

● One-Party Consent Jurisdictions: You may record a conversation if you are a party to it and at least one party consents.

● All-Party Consent Jurisdictions: All participants must consent to being recorded.

5.2 Disclosure and Notification

If you are the meeting organizer or recording participant, you should:

● Include notice of recording in your meeting invitation or agenda.

● Verbally disclose that the call is being recorded at the start of the meeting.

● Provide participants with the opportunity to opt out or decline.

● Maintain documentation of consent where required by law.

We may provide templates or suggested language in our dashboard but you are responsible for complying with your local recording laws.

5.3 Restricted Use

You agree not to record or upload conversations involving:

● Individuals without their knowledge or consent (where consent is required by law).

● Minors, without parental or guardian consent.

● Highly sensitive personal information (e.g., health, financial, or legal advice) unless specifically authorized.

6. Cookies and Similar Technologies

6.1 What Are Cookies?

Cookies are small files stored on your device that help us recognize you, remember your preferences, and improve your experience.

6.2 Types of Cookies We Use

Cookie Type

Purpose

Retention

Essential/Functional

Session management, authentication, security

Duration of session or until logout

Performance/Analytics

Track usage patterns, feature adoption

12 months

Preference

Remember your language, display settings

12 months

Marketing/Tracking

Support third-party analytics

12 months

 

6.3 Cookie Consent and User Controls

We use a cookie consent banner on our website that appears when you first visit. The banner provides transparent choices about all tracking:

Banner Options (if you are in the EU/EEA or see our banner):

● Accept All: Enable essential, functional, performance, and marketing cookies.

● Reject Non-Essential: Accept only essential and functional cookies; decline analytics and marketing tracking.

● Manage Preferences: Fine-tune which types of cookies you allow (see table in Section 6.2).

Your Controls: You can manage cookie settings at any time by:

● Visiting our cookie preferences page at rapportscore.ai.

● Adjusting browser settings to block or delete cookies

● Using your browserís Do Not Track signal (though not all sites respond to this)

We honor symmetrical cookie consent: rejecting tracking is just as simple and visible as accepting it.

6.4 Tracking Technologies Beyond Cookies

Pixel Tags / Web Beacons: Small transparent images embedded in emails and web pages that confirm email opens and page visits. Used to measure marketing campaign effectiveness.

Local Storage / IndexedDB: Browser storage mechanisms (similar to cookies) that persist across sessions. Used for caching, session management, and feature settings.

Mobile App Identifiers:

iOS IDFA (Identifier for Advertisers): We may use Appleís IDFA if you grant permission in your device settings for personalized analytics and app performance tracking.

Android Advertising ID: We may use Googleís Android advertising identifier similarly with your device-level consent.

Analytics and Tracking Detail:

Tracking Tool

Data Collected

Purpose

Data Shared With

Retention

Google Analytics 4

Pages visited, session duration, events, device type, IP (anonymized)

Understand user behavior, improve features

Google (under DPA)

12-14 months

Stripe (payment)

Transaction metadata, subscription status

Process payments, detect fraud

Stripe (PCI-compliant)

Per legal requirement

Opt-Out Options:

Google Analytics: Install Google Analytics Opt-out Browser Add-on.

6.5 Third-Party Analytics and Tracking

We use the following third-party services for analytics and tracking:

Service

Purpose

Privacy Policy

Google Analytics

Website traffic and usage analysis

https://policies.google.com/technologies/partner-sites

 

Important: These vendors may place their own cookies and tracking pixels. They may have access to de-identified or aggregated data but cannot use your data for their own marketing. We have executed Data Processing Agreements (DPAs) with all primary analytics vendors ensuring compliance with GDPR and CCPA. We recommend reviewing their privacy policies to understand their specific practices.

No Sale of Tracking Data: We do not sell analytics data, user behavioral profiles, or tracking identifiers to third parties for their independent use.

7. Data Sharing and Third Parties

7.1 When We Share Data

We share personal data with third parties only in the following circumstances:

Service Providers and Vendors:

● We use third-party service providers that process audio, video, and text data to provide transcription, language analysis, and AI-powered insights.

All service providers are contractually bound to:

● Process data only on our instructions.

● Maintain appropriate security measures.

● Not use data for their own purposes.

● Comply with applicable privacy laws (GDPR, CCPA, etc.).

We have executed Data Processing Agreements (DPAs) with all primary vendors.

Legal and Compliance:

● Comply with lawful government requests, court orders, or legal process.

● Protect against fraud, abuse, or security threats.

● Enforce our Terms of Service and other agreements.

Business Transfers:

● In the event of a merger, acquisition, bankruptcy, or sale of assets, your data may be transferred as part of that transaction. We will provide notice if materially different privacy practices result.

With Your Consent:

● We do not share data with third parties for marketing or secondary purposes without your explicit consent.

7.2 Data Not Shared

We do not sell, rent, or trade your personal data. We do not share conversation recordings, transcripts, or coaching outputs with third parties without your permission, except where required by law or in the limited scenarios outlined above.

8. International Data Transfers

8.1 Data Location

Your data is processed in data center locations in the United States..

8.2 Transfers Outside EEA (for EU/EEA Users)

RapportScore.ai is a US-based service with all data processed and stored on US servers. We do not knowingly target, market to, or offer services to individuals or organizations in the EU/EEA.

If you are located in the EU/EEA:

● Any access to our Service constitutes your explicit consent to international data transfers to the United States, which does not have an EU adequacy decision.

● Safeguards: We rely on your consent as the transfer mechanism (GDPR Art. 49(1)(a)). Our US-based service providers are bound by Data Processing Agreements (DPAs) requiring them to protect data to equivalent standards.

● No SCCs Required: As a small organization not actively targeting the EU/EEA, we do not maintain Standard Contractual Clauses (SCCs) or appoint an EU representative (Art. 27).

● Your Rights: EU/EEA users may contact privacy@rapportscore.ai to request data access, deletion, or details of transfers. We will respond within 1 month.

We recommend EU/EEA residents use services with EU-based hosting if concerned about US data protection standards.

9. Data Retention

9.1 Retention Periods

We retain personal data only as long as necessary to provide the Service and comply with legal obligations:

Data Category

Retention Period

Reason

Conversation recordings/transcripts

Until removed by the user

Service delivery; user choice

Coaching outputs and scores

Until removed by the user

Service history and analytics

Account and registration data

Duration of active subscription + 30 days after termination

Account management; legal hold

Payment and billing data

7 years

Tax and financial compliance

Analytics and log data

12 months

Service improvement and security

Support tickets and communications

3 years

Legal and dispute resolution

 

9.2 User Deletion Rights

You may request deletion of your data at any time:

● Self-Service: Delete specific recordings and coaching outputs in your account dashboard.

● Full Account Deletion: Users can delete their own data at any time. Users may also request permanent deletion of all account data by emailing privacy@rapportscore.ai. We will delete your data within 30 days unless legally required to retain it.

9.3 Backups and Disaster Recovery

We may maintain backup copies of your data for security and disaster recovery purposes for up to 90 days beyond the stated retention period. Backup data will eventually be securely deleted.

10. Security Measures

10.1 Technical Safeguards

We implement industry-standard security measures to protect your data:

● Encryption in Transit: TLS/SSL encryption for all data transmitted to/from the Service.

● Encryption at Rest: AES-256 encryption for stored data in cloud storage.

● Access Controls: Role-based access, strong password requirements, and multi-factor authentication.

● Audit Logging: Continuous logging of data access and system changes.

● Network Security: Firewalls, intrusion detection, and DDoS protection.

10.2 Organizational Safeguards

● Limited employee access to personal data on a need-to-know basis.

● Employee training on data privacy and security.

● Data handling policies and procedures.

● Regular security audits and penetration testing by internal team.

10.3 No Absolute Security

While we implement rigorous security measures, no system is 100% secure. We cannot guarantee absolute prevention of unauthorized access, data breaches, or misuse.

11. Your Privacy Rights

Depending on your location, you may have the following rights:

11.1 GDPR / UK GDPR Rights (EU/EEA and UK Users)

RapportScore.ai is a US-based service. This Privacy Policy complies with applicable US privacy laws.

If you are located in the European Economic Area (EEA), United Kingdom, or other jurisdictions with comprehensive data protection laws, please note:

● We process your personal data primarily on US servers.

● By using our service, you acknowledge that data transfers to the US may occur, which some jurisdictions consider to have different data protection standards.

● We do not knowingly target or offer services to EU residents.

● EU residents may contact our representative at privacy@rapportscore.ai.

11.2 CCPA / CPRA Rights (California Residents)

If you are a California resident, you have the following rights:

Right to Know:

● You may request what personal information we collect, use, share, and sell.

Right to Delete:

● You may request deletion of personal data we have collected from you (subject to exceptions).

Right to Correct:

● You may request correction of inaccurate personal data.

Right to Opt-Out:

● We do not sell/share personal data. Opt-out requests are still honored.

Right to Limit Use:

● You may limit use of sensitive personal data to necessary service delivery.

Right to Non-Discrimination:

● We will not discriminate against you for exercising your rights.

How to Exercise: Contact privacy@rapportscore.ai.

Verification: We may request verification of your identity before fulfilling requests.

11.3 Other Jurisdictions

If you are located in other jurisdictions with privacy rights (e.g., Canada's PIPEDA, Australia's Privacy Act, Brazil's LGPD), similar rights may apply. Contact us for jurisdiction-specific guidance.

12. Data Breach Notification

12.1 Breach Discovery and Response

In the event of a data breach that compromises the confidentiality, integrity, or availability of your personal data:

● Investigation: We will conduct an immediate investigation to determine scope and impact.

● Notification Timeline: We will notify affected users and relevant authorities within 30 days or as required by law.

● Information Provided: Our notification will include description of the breach, data affected, steps we are taking, and recommended user actions.

12.2 Regulatory Notification

Where required by law (e.g., GDPR, CCPA), we will notify relevant data protection authorities without undue delay (GDPR: within 72 hours of discovery).

13. Children's Privacy

RapportScore.ai is not intended for individuals under 18 years old (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal data from children. If we become aware that a child has provided data, we will delete it immediately and may terminate the account. Parents or guardians concerned about a child's data may contact privacy@rapportscore.ai.

14. Third-Party Links and Services

Our Service may contain links to third-party websites, applications, and services not operated by us. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any personal data.

15. California Privacy Rights (Shine the Light Law)

Under California Civil Code Section 1798.83, California residents may request information about personal data we share with third parties for their direct marketing purposes. To make such a request, please contact privacy@rapportscore.ai with subject line "California Privacy Rights."

16. Changes to This Privacy Policy

We may update this Policy periodically to reflect changes in our practices, technology, law, or other factors. We will notify you of material changes by:

● Posting the updated Policy on our website with an updated "Last Modified" date.

● Sending an email to your registered email address.

● Obtaining your affirmative consent if required by law.

Your continued use of the Service after changes become effective constitutes your acceptance of the updated Policy. We encourage you to review this Policy regularly.

17. Contact Us

If you have questions about this Privacy Policy, our privacy practices, or wish to exercise your rights, please contact:

Email: privacy@rapportscore.ai

We will respond to inquiries and requests as follows:

● Privacy requests (access/deletion): 30 days (extendable to 90 for complex cases) (GDPR0; 45 days (CCPA)

● General inquiries: 10 business days