Legal

Privacy Policy

Effective August 25, 2026

Horato operates hora.to, a communications and scheduling control plane that software vendors and agent platforms build on. This policy explains what we collect, why we collect it, who we share it with, and the choices you have. It covers the hora.to website, the dashboard, the API, scheduling pages, and recording features.

1. Who we are and the roles we play

Horato provides one normalized API over email, calendar, contacts, tasks, scheduling, webhooks, agent tools, and meeting recording. Our direct customers are companies and developers who embed these capabilities into their own products.

We act in two distinct roles. For data about our own customers and site visitors — dashboard accounts, billing details, demo requests, support conversations — we are the data controller. For content that flows through the platform on behalf of a customer — their end users' messages, events, contacts, tasks, bookings, recordings, and transcripts — we are a data processor acting on the customer's instructions. If you are an end user of a product built on Horato, the vendor of that product is responsible for your data, and their privacy policy applies alongside this one.

2. Information we collect

Account and organization data, collected when you sign up and use the dashboard:

  • Name, work email address, and a password we store only as a salted hash.
  • Organization and project details, member roles, and API key metadata.
  • Billing profile and subscription state. Card details go directly to our payment provider; we never store full card numbers.

Customer content, processed on behalf of our customers when they or their end users use the platform:

  • Email messages, calendar events, contacts, and tasks synced from connected Google and Microsoft accounts.
  • Scheduling data: event types, availability, and booking details such as the booker's name, email address, and notes.
  • Meeting recordings, transcripts, and summaries produced by the recording features.
  • Webhook payloads, delivery logs, and approval records for agent-initiated actions.

Connection and technical data, collected automatically as the platform runs:

  • OAuth tokens for connected provider accounts, encrypted at rest, plus sync cursors and provider identifiers.
  • API request metadata: request IDs, timestamps, endpoints, response codes, latency, and IP addresses.
  • Audit logs of administrative and security-relevant actions.
  • Basic analytics on the marketing site and dashboard: page views, approximate region from IP address, and device type. We do not use cross-site advertising trackers.

Demo requests on this site collect your name, work email, and company, and are protected against abuse with Cloudflare Turnstile, which processes limited technical signals to distinguish people from bots.

3. Google user data and Limited Use

When a Google account is connected, Horato requests access to read, modify, and send email, and to read and manage calendars, contacts, and tasks, so that the connected application can offer those features. We access only the data needed to provide the functionality the customer has enabled.

Horato's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

  • We do not use Google user data for advertising.
  • We do not sell Google user data.
  • We do not use Google user data to develop, improve, or train generalized artificial intelligence or machine learning models.
  • Humans do not read this data except with explicit permission, when necessary for security or abuse investigation, to comply with applicable law, or when the data has been aggregated and anonymized for internal operations.

4. Microsoft account data

When a Microsoft account is connected, Horato requests equivalent permissions through the Microsoft identity platform: reading and sending mail, and managing calendars, contacts, and tasks. We apply the same commitments to Microsoft account data that we apply to Google user data: no advertising use, no sale, no training of generalized AI models, and no human access outside the narrow cases listed above.

5. How we use information

We use the data described above to:

  • Provide, operate, and maintain the platform: syncing provider data, executing API requests, delivering webhooks, rendering scheduling pages, and orchestrating recordings.
  • Authenticate accounts, enforce per-tenant isolation, and secure the service against abuse, fraud, and unauthorized access.
  • Meter usage, calculate charges, and process payments.
  • Respond to support requests and communicate service changes.
  • Comply with legal obligations and enforce our terms.

We do not sell personal data, we do not use customer content for advertising, and we do not use customer content to train AI models. Transcription and summarization run only to deliver results back to the customer who requested them.

6. Meeting recordings and transcripts

Recording features send a visible participant into a meeting under a name the customer controls. The customer, and the meeting host using the customer's product, are responsible for telling participants the meeting is recorded and for obtaining any consent required by the laws that apply to them. Some jurisdictions require the consent of every participant.

Audio is transcribed using a speech-to-text provider configured for the project — either credentials managed by Horato or credentials the customer supplies, which we store encrypted. Completed transcripts and summaries are stored so the customer can retrieve them through the API. Recording media and transcripts are retained for 30 days by default; each project can configure retention between 1 and 365 days or delete them at any time.

7. When we share data

We share data only as needed to run the service:

  • Infrastructure and hosting providers that run our application, database, and recording runtime.
  • Stripe, for payment processing and billing.
  • OpenAI, for speech-to-text transcription and summaries when the project uses Horato-managed transcription, under API terms that prohibit using the data to train their models.
  • Google and Microsoft, when executing the actions a customer or their end user requests against a connected account.
  • Twilio SendGrid, for transactional email such as demo request confirmations.
  • Cloudflare, for bot protection on public forms.

Each of these providers processes data under contractual terms consistent with this policy. We may also disclose data when required by law, to protect the rights and safety of Horato or others, or as part of a merger or acquisition, in which case this policy continues to apply to previously collected data until it is replaced.

8. Data retention and deletion

  • Account data is retained while your account is active and deleted or anonymized after closure, except where the law requires longer retention of billing records.
  • Customer content is retained under the customer's control: it can be deleted through the API at any time, and it is deleted when the associated project or organization is deleted.
  • Recordings, transcripts, and summaries follow the retention settings of the project that created them.
  • Operational logs and audit records are kept for a limited period for security and reliability, then deleted or aggregated.
  • Residual copies in encrypted backups are purged on the backup rotation schedule.
  • Verified deletion requests are honored within 30 days.

When a provider account is disconnected, we stop syncing and delete the stored OAuth credentials. You can also revoke Horato's access at any time from your Google or Microsoft account security settings.

9. Security

Data is encrypted in transit with TLS and encrypted at rest. Provider OAuth tokens and customer-supplied credentials are additionally encrypted at the application layer with AES-256-GCM. Passwords are stored as salted scrypt hashes. Access inside Horato is scoped: every API call is authenticated, authorized against organization and project scope, and recorded in audit logs. Webhooks are signed so receivers can verify authenticity. No system is perfectly secure, but we design so that a single failure does not expose tenant data across boundaries.

10. International transfers

We operate on infrastructure in multiple regions, and data may be processed outside the country where it originated. Where personal data from the European Economic Area, the United Kingdom, or Switzerland is transferred internationally, we rely on appropriate safeguards such as standard contractual clauses with our providers.

11. Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, restrict, or export your personal data, to object to certain processing, and to complain to a supervisory authority. We honor these rights regardless of jurisdiction where we reasonably can.

If you are an end user of a product built on Horato, direct your request to the vendor of that product; we support our customers in fulfilling these requests. If you are a Horato customer or a visitor to this site, contact us directly and we will respond within the timelines required by applicable law.

12. Cookies

The dashboard uses strictly necessary cookies to keep you signed in. The marketing site does not set advertising cookies and does not track you across other sites.

13. Children

The services are built for businesses and are not directed to children under 16. We do not knowingly collect data from children; if you believe a child has provided us data, contact us and we will delete it.

14. Changes to this policy

We will update this policy as the platform evolves. Material changes are announced to customers by email or in the dashboard before they take effect, and the effective date at the top of this page always reflects the current version.

15. Contact

Questions, requests, or concerns about privacy: email info@hora.to. We answer privacy requests from customers, end users, and visitors alike.