Back to product

Privacy Policy

This policy explains what data Gisti collects, why we collect it, who we share it with, and the choices and rights you have. It applies to gisti.ai and the Gisti application.

Last updated: July 16, 2026

1. Who we are and what this policy covers

Gisti (“Gisti”, “we”, “us”) is a software-as-a-service product, available at https://gisti.ai, that helps product teams turn raw customer feedback — reviews, support tickets, messages, and meeting notes — into organized, prioritized product opportunities.

This policy covers two categories of data. For account and usage data (the information we collect about you when you visit our site or use Gisti), we decide how and why the data is processed. For Customer Content (the feedback data you and your team upload or connect to your workspace, which may contain personal data about your end users), we process it only on your behalf and under your instructions to provide the service. Your organization remains responsible for having a lawful basis to collect and share that content with us.

2. Information we collect

Account information. When you create an account we collect your name (optional), work email address, and — if you sign in with Google — the basic profile information described in section 5 (name, email address, and profile picture). Authentication is handled by Amazon Cognito. We also store your workspace membership and role (admin, editor, or viewer).

Customer Content. Depending on what you upload or connect, your workspace may contain: CSV files of customer feedback; public app-store reviews (Google Play and Apple App Store); reviews retrieved through the Google Play Developer API; support tickets from Zendesk; messages from Slack channels you choose to connect; conversations from Intercom; feedback submitted through the Gisti web feedback API; and recordings and transcripts of meetings you invite the Gisti notetaker to join. This content can include names, email addresses, and anything your customers wrote or said.

Usage and device data. We collect product analytics (pages viewed, features used, and similar events), along with browser type, device information, and IP address. See section 6 for details, including session replay.

Billing information. Payments are processed by Dodo Payments. We receive and store your subscription status, plan, and billing identifiers. Full payment-card details are handled by Dodo Payments and never touch Gisti servers.

Communications. If you email us or request support, we keep the correspondence.

3. How we use information

We use the data described above to:

  • provide the service — ingesting your feedback, grouping it into themes, generating opportunity summaries and impact scores, and answering questions through the Gisti assistant;
  • create and secure your account and workspace, and enforce role permissions;
  • operate billing, trials, and plan quotas;
  • understand how the product is used and improve it, using the analytics described in section 6;
  • detect, prevent, and respond to abuse, fraud, and security incidents;
  • communicate with you about your account, such as invitations, verification codes, and important service or billing notices;
  • comply with legal obligations.

We do not sell personal data, and we do not use your data for third-party advertising.

4. AI processing of your content

Gisti’s core features are powered by large language models and embedding models provided by OpenAI. To provide the service, Customer Content is sent to OpenAI’s API to compute embeddings, group feedback into themes, generate summaries and scores, and answer questions you ask the Gisti assistant. Meeting audio is transcribed using speech-to-text models.

We do not use your Customer Content to train AI models, and our AI providers process it under API terms that prohibit them from using it to train their models. AI-generated output is produced automatically and may be inaccurate; it is provided to help your team review evidence, not to replace it.

5. Data received from Google APIs

Sign in with Google. If you choose to sign in with Google, we receive your basic Google profile information: your name, email address, and profile picture. We use it solely to create and authenticate your Gisti account and to display your identity inside your workspace.

Google Play Developer API.If your workspace connects the Google Play integration, we access your app’s review data through the Google Play Developer API solely to import those reviews into your workspace as feedback. We do not access any other data in your Google account.

Gisti’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we do not use Google user data for advertising, we do not sell it, we do not use it to train generalized AI models, and humans do not read it except with your explicit permission, where necessary for security or legal compliance, or where the data has been aggregated and anonymized. You can revoke Gisti’s access at any time from your Google account permissions page.

6. Cookies, analytics, and session replay

Essential cookies. Gisti uses first-party, HTTP-only cookies to keep you signed in (access and refresh tokens) and a preference cookie for your theme. These are required for the service to work.

Product analytics. We use PostHog (hosted in the United States) to understand product usage. Analytics requests are routed through our own domain. Analytics profiles are created only for signed-in users; we associate events with your account and workspace so we can understand feature adoption.

Session replay. We use PostHog session replay to diagnose usability problems. Replay is configured to mask all text and all input on every page — the recordings capture page structure and interactions, not the contents of your feedback, account data, or anything you type.

We do not use third-party advertising cookies or trackers.

7. How we share information

We share data only with service providers (subprocessors) that help us run Gisti, and only to the extent needed to provide the service:

  • Amazon Web Services (United States, us-east-1) — cloud hosting, databases, file storage, and authentication (Amazon Cognito).
  • OpenAI (United States) — embeddings and language-model processing of Customer Content, as described in section 4.
  • PostHog (United States) — product analytics and masked session replay.
  • Dodo Payments — subscription billing and payment processing.
  • Recall.ai (United States) — operates the meeting notetaker bot that joins meetings your team invites it to.

When you connect an integration (Google Play, Apple App Store, Zendesk, Slack, Intercom, or a meeting platform), data flows between Gisti and that platform as you configure it, under that platform’s own terms. You can disconnect an integration at any time from the Integrations page, which stops further syncing and deletes the stored credentials for it.

We may also disclose information if required by law, to protect the rights, safety, or property of Gisti or others, or as part of a merger, acquisition, or sale of assets (in which case this policy will continue to apply to your data until you are notified otherwise).

8. Data retention and deletion

We retain account information and Customer Content for as long as your workspace is active, so your team’s feedback history and opportunities remain available. Disconnecting an integration stops new data from syncing; previously imported feedback remains in your workspace until deleted.

You can request deletion of your account, your workspace, or specific content by emailing shubham@gisti.ai. We verify the request and delete the data within 30 days, except for limited records we must keep for legal, billing, or security purposes (which we delete when no longer required). Backup copies are purged on our backup rotation schedule.

9. Security

Measures we use to protect your data include:

  • encryption in transit (TLS) for all traffic, and encryption at rest for databases and storage;
  • workspace isolation enforced at the database layer with row-level security, so one customer’s data cannot be read through another customer’s session;
  • integration credentials (such as OAuth tokens) stored encrypted;
  • authentication tokens kept in HTTP-only cookies that are never exposed to client-side scripts;
  • role-based access control within each workspace, and least-privilege access internally.

No system is perfectly secure. If we learn of a breach affecting your personal data, we will notify you and the relevant authorities as required by law.

10. International data transfers

Gisti is hosted in the United States, and the subprocessors listed in section 7 process data primarily in the United States. If you use Gisti from outside the US, your data will be transferred to and processed there. Where the law of your jurisdiction (such as the GDPR in the EEA or UK) requires safeguards for such transfers, we rely on appropriate mechanisms, including standard contractual clauses with our subprocessors where applicable.

11. Your rights and choices

Depending on where you live, you may have the right to access, correct, export, delete, or restrict the processing of your personal data, and to object to certain processing. You can exercise these rights by emailing shubham@gisti.ai; we respond within the timelines required by applicable law and never discriminate against you for making a request. If you are in the EEA or UK, you also have the right to lodge a complaint with your local supervisory authority.

If your personal data appears in a Gisti workspace as part of Customer Content (for example, a review or support ticket you wrote to one of our customers), the organization that operates that workspace controls it — we will refer your request to them, or assist them in fulfilling it.

12. Meeting recordings

The Gisti notetaker joins a meeting only when someone on your team invites it. It is visible as a named participant in the meeting. The organization inviting the notetaker is responsible for providing any notice to, and obtaining any consent from, meeting participants that applicable recording laws require. Transcripts are stored in your workspace’s isolated storage and are treated as Customer Content under this policy.

13. Children

Gisti is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it.

14. Changes to this policy

We may update this policy as the product evolves. We will post the updated version on this page and revise the “Last updated” date above; for material changes we will give you additional notice, such as by email or an in-app message. Your continued use of Gisti after an update means the revised policy applies.