Last updated · 1 August 2026
Privacy Policy
Aperture helps a company see how its own work actually gets done. To do that it reads material the company already has — documents, meeting transcripts, chat threads — and, where the company chooses, records how its own operators work. This page says exactly what that means: what is collected, why, where it is kept, and how to have it removed.
Aperture is sold to organisations, and an organisation's administrator decides what is connected and who is recorded. If you are an employee of a customer and want to know what applies to you, your administrator can show you these same settings in the console.
What we collect
Documents you connect. When an administrator connects Google Drive, Slack, GitHub or a meeting-notes provider, Aperture reads the material that connection covers and stores the text so it can be searched and cited.
Recordings you choose to make. The desktop recorder captures how an operator works — which application is in focus, what is clicked, what is typed into which field. It runs only while the operator starts it, and stopping is not sending: a recording stays on the operator's own machine until they explicitly submit it for analysis.
Account and usage data. Who signed in, what they asked, what the system spent answering. This is how an administrator audits the product's own behaviour.
We do not buy data about you, we do not use advertising identifiers, and we do not build profiles of individuals.
Cookies on this website
This website sets optional cookies only after you accept them in the banner. Analytics (Google Analytics) tells us how the site is used. Marketing (Apollo) tells us which companies visit, not which people. Necessary cookies, which remember your choice, are always on. To change your answer, clear this site's cookies and the banner will ask again.
What we deliberately do not collect
- Passwords. Password fields are stripped before anything leaves the browser or the desktop.
- The values you type. Input values are hashed one-way before they leave your machine, so we can tell that the same value was entered twice without ever holding the value.
- Screens and audio, by default. Screenshots stay on the operator's own machine and are not uploaded unless that is explicitly turned on.
Personal identifiers found inside documents — email addresses, phone numbers, national identity numbers — are masked before storage. Storage holds the masked form; nothing displays the original.
Google user data, and our Limited Use commitment
When you connect Google Drive, Aperture requests the drive.file scope only.
That scope grants access to the individual files you pick in Google's own file
picker and to nothing else in your Drive. We cannot see, list, or open anything
you have not chosen, and we cannot browse your folders.
For the files you do pick, we read the file's contents and metadata, convert the text into passages so a finding can cite the exact passage it came from, and store that text in the customer's own workspace.
Aperture's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Google user data is used only to provide the features the customer connected it for; it is never sold, never used for advertising, never used to train generalised AI or ML models, and never read by a human except with the customer's explicit permission, to resolve a support issue they raised, for security purposes, or where the law requires it.
Disconnecting the integration in the console, or revoking access at myaccount.google.com/permissions, stops all further access immediately.
Where it goes, and who can see it
Material is stored in the customer's own workspace and is visible only to people that customer's administrator has admitted. Aperture staff do not browse customer content.
To produce findings, document text and recorded activity are sent to the AI model providers we use for analysis. They process it to return a result and do not use it to train their models. Content is not shared with anyone else.
How long we keep it
Raw recordings are transient. They are deleted automatically after the retention window the customer sets, seven days by default.
Derived material is kept. The workflows, findings and cited passages built from that raw capture are the product, and they persist until the customer deletes them.
Removing a document takes it out of every view and stops it being collected again. Anything already citing it keeps working, because the cited passage was copied at the time it was cited.
Your choices
- Stop everything. An administrator can turn off collection for the whole organisation or for one machine, from Trust and permissions in the console. It takes effect within a minute.
- Change what is connected. Any integration can be paused or disconnected, and a Drive selection can be edited file by file.
- Delete. Ask your administrator, or write to us at the address below, and we will delete your data. We will confirm when it is done.
Children
Aperture is a workplace product. It is not directed at anyone under 16 and we do not knowingly collect their data.
Changes
If this policy changes materially, we will say so here and date it, and tell customer administrators before the change takes effect.
Contact
Questions, access requests and deletion requests: hello@aperture.example