Privacy

What Whistle stores on your computer, what extensions send to other services and what BlazingBanana holds.

Last updated: 8 September 2026

1. What BlazingBanana holds

BlazingBanana Ltd holds the records needed to provide a licence and respond to support requests:

The release notification list is separate from the software. Joining or leaving it has no effect on the application. The application does not send BlazingBanana analytics, crash reports, meeting content or provider account data.

2. What stays on your computer

Whistle saves recordings, transcripts and documents in your workspace. Its own transcription and writing models run on your computer. Extensions can send transcripts or documents to other services as described below. The security notes explain workspace storage and encryption.

3. Extensions

Extensions are optional. Before one can connect, you must install it, approve its access, turn it on and sign in. Turning it off stops its requests to that service.

Google data

The Google Account integration reads upcoming Google Calendar event titles, times, organisers, invitees and Meet links. It creates or finds a Google Drive folder named Whistle and uploads only exports selected for provider filing. It does not request Gmail content and does not request access to every file in Google Drive.

The Google Calendar, Drive and Meet option can also check whether a scheduled Meet has an active conference and read participant display names exposed to the connected meeting owner or participant. It does not receive participant audio. It works with personal Gmail and Google Workspace accounts when the connected user is permitted to access that conference.

Microsoft data

The Microsoft 365 integration reads upcoming Outlook event titles, times, organisers, invitees and Teams join links. When provider filing is enabled, it uploads selected exports to the configured SharePoint library or to the connected person's OneDrive. It does not receive separate Teams participant audio streams.

How calendar data and uploads are used

Calendar and meeting data is used to show a meeting prompt and attach the selected meeting context to a local recording. Upcoming meeting data is held in memory. Context selected for a recording can be stored in that local workspace. OAuth access and refresh tokens are stored in the operating system keychain. Public integration settings are stored in the local application configuration. If an administrator uses a custom Google desktop OAuth application, its client ID and Google-issued desktop client secret are also stored in that local configuration. Google treats a secret distributed with an installed application as non-confidential; it is not the person's password or OAuth token.

The Microsoft and Google extensions do not send data to BlazingBanana, advertisers or analytics services. Whistle's models do not train on it. Google user data is used only for the Calendar, meeting context and Drive filing features shown in Whistle, in accordance with the Google API Services User Data Policy, including its Limited Use requirements.

Google and Microsoft receive the sign-in and API requests needed to provide their connected features. An export uploaded to Drive, SharePoint or OneDrive remains there under the provider account's normal retention and sharing controls. BlazingBanana does not receive a copy.

Codex and Claude Code

When you use Codex or Claude Code to write a document, Whistle sends OpenAI or Anthropic your full transcript, including speaker labels, and your chosen document template. If Whistle makes a separate request to extract action items, it also sends the overview it has written. Recording, transcription and speaker labelling run on your computer. Your audio isn't sent. BlazingBanana doesn't receive any of this content.

Sign-in details are saved in a private folder for the extension on your computer. Removing the extension deletes these details. It doesn't delete content already sent to OpenAI or Anthropic or cancel your subscription.

How long OpenAI or Anthropic keeps this content, and whether it can be used for training, depends on your account and its settings. Check the OpenAI privacy policy or Anthropic privacy policy and your account's terms. Use Whistle's local writing model if your transcript must stay on your computer.

Disconnecting Microsoft or Google

Disconnecting or removing an integration deletes its local OAuth tokens. A person can also revoke Whistle Enterprise in their Google Account or Microsoft account. Existing local meeting records and documents remain until the person deletes them from the local workspace. Existing provider uploads remain until the person deletes them from Drive, SharePoint or OneDrive. Provider consent can remain after a local disconnect and must be revoked through the provider account when that is required.

4. Whistle Enterprise will never

5. What the installer contains

The installer contains Whistle and its offline models. Extensions are separate downloads. There is no analytics software, crash reporting service or connection to a licensing server. To update Whistle, download and install the new version yourself. The application doesn't check for updates.

6. Subject access and deletion

To request a copy of the data BlazingBanana holds, or to request its deletion, email [email protected]. We will respond within one calendar month. BlazingBanana cannot retrieve or delete local workspace data or provider data because it does not hold either.

7. Data controller

BlazingBanana Ltd, registered in the United Kingdom (company no. 15329501). UK GDPR applies. Lawful basis is contract for licence records, legitimate interest for support correspondence and consent for release notification emails. Consent for notifications can be withdrawn at any time using the unsubscribe link in any release email.


Questions about this notice? Email [email protected].