Privacy Policy
How EventMatch processes, protects, retains, and deletes information across the product and its connected services.
Last updated September 22, 2026What EventMatch processes
EventMatch processes professional-event information you authorize, including event schedules, visible attendee-directory information, and Omi conversations that overlap an event window you explicitly enable. If you use EventMatch Camera, EventMatch also processes the photos you choose to capture or upload, their capture time, requested camera direction, and conservative event-assignment status. If you import an ordinary audio file, EventMatch processes the private file, its safe display filename, validated media type, byte size, duration, file date, and conservative event-assignment status. For Omi app connections, EventMatch receives an Omi user identifier. During a user-started ChatGPT Event Mode, Omi may also send realtime transcript callbacks. If you have enabled Live Coach, EventMatch automatically accepts normalized transcript and speaker segments only during that active event window, encrypts them, and uses them to create private rolling summaries and guidance. If Live Coach is off, EventMatch discards transcript and speaker content immediately and retains only a recent-signal time, one-way session fingerprint, and count for the active event window. A timestamp-only pre-arm heartbeat may remain in short-lived server cache for up to 30 seconds to cover the ChatGPT tool-call delay. For local developer testing, an Omi developer API key may be used.
Omi identifiers, developer keys, and normalized transcripts are encrypted at rest. EventMatch stores allowlisted conversation metadata, transcript segments inside the authorized window, summaries, action items, attendee-match evidence, and reviewable follow-up drafts. It does not store Omi audio, geolocation, raw API responses, or conversations outside the authorized window. Realtime webhook envelopes are not retained. Ordinary audio files you select yourself are a separate EventMatch source and are not treated as Omi data.
Camera uploads are decoded only as JPEG, PNG, WebP, or HEIC, resized to bounded dimensions, and re-encoded as JPEG. Original EXIF and other source metadata are not retained. Ordinary capture, event assignment, Photo AI, and MCP do not use face recognition. EventMatch does not infer sensitive traits from photos.
Photo AI Review is disabled until you explicitly enable it. When enabled, supported iPhones analyze visible text, QR URLs, badge-like rectangles, and face regions locally, and EventMatch sends each normalized private photo to its configured multimodal AI for a separate badge reading. EventMatch encrypts the device, server, and reconciled observations. Face regions are used only to support manual review: faces are never identified or compared with profile photos. Suggested People and badge details require your confirmation.
Optional biometric face matching is unavailable by default and requires separate organization approval from an owner or administrator and separate consent from the current user. Earlier face-matching permission and Photo AI Review permission do not apply. When the deployment, organization, and user controls are active, EventMatch sends approved photos of visible attendees from your organization and selected event to Amazon Rekognition. EventMatch creates encrypted face-reference data that stays separated by organization and event. Amazon Web Services acts as a subprocessor. After you grant the separate consent, automatic review is enabled by default as a distinct setting for at most 10 new photos per event and only when fewer than 500 active visible attendees are present. You may turn that setting off without withdrawing consent. Later photos, larger events, and older photos require an explicit action. Your private photo is analyzed only for the requested comparison and is never stored as an attendee reference. Encrypted EventMatch records connect provider-generated face identifiers to existing People. Face references are removed when approval ends, the source photo changes, the related Person or event is deleted, organization approval is withdrawn, or the event retention period expires. Processing older photos requires another explicit event-scoped request. Results are review candidates only: insufficient confidence returns no match, multiple candidates always require review, and every photo-to-Person link requires your explicit confirmation. The feature does not create or merge People, change identity records, or infer demographics, emotion, health, ethnicity, religion, or any other protected or sensitive attribute.
Why the data is used
The data is used to help you remember professional-event conversations, deterministically match people in conversations to the authorized attendee directory, review commitments, and prepare follow-up drafts. EventMatch never sends those drafts automatically. Uploaded audio file dates are also used to propose nearby events for your review. EventMatch does not confirm those suggestions automatically. Name alone is never treated as a confirmed identity match.
Exa Deep Research
When Deep Research is enabled and you explicitly request it for one person, EventMatch sends Exa only a directly provided public professional profile URL or the person's exact name and company. Exa acts as a subprocessor for that request. EventMatch does not send the event name, ICP, private notes, Omi data, photos, provider payloads, hidden contact information, or information about other people. EventMatch stores only normalized professional facts and their public citations, not the raw Exa response or full search query.
The integration remains disabled until EventMatch has reviewed the applicable Exa data-processing terms, retention configuration, and subprocessor requirements. Deep Research never contacts a person or searches for hidden email addresses or phone numbers.
OpenAI processing
When you explicitly request transcription or an event report, EventMatch sends the selected private audio file, or bounded audio chunks prepared from it, to OpenAI to create text. EventMatch may also send bounded transcript text and allowlisted event context to OpenAI to extract speaker-labeled event sections, structured professional topics, identities supported by direct transcript evidence, and explicit commitments or actions. OpenAI is a subprocesser for these features. AI does not perform voice biometrics, infer sensitive traits, change deterministic identity confidence, or receive hidden contact information. If OpenAI is unavailable, deterministic processing and Omi-provided summaries remain available.
When Live Coach is enabled, EventMatch may send a bounded rolling window of the encrypted-at-rest realtime transcript and the current event title to OpenAI to produce private conversation summaries, explicit professional facts, commitments, and short coaching suggestions. The transcript is processed only for the connected user and authorized Event Mode window.
If you connect the EventMatch plugin to ChatGPT or Codex, OpenAI can request only the organization-scoped EventMatch records covered by the read scopes you approve. The plugin may return professional-event details, authorized visible attendee records, event-match scores and evidence, attendee-provided professional profile URLs, existing unsent outreach drafts, prospecting plans, safe job status, and technical record identifiers needed to continue a requested lookup. It does not return Omi transcripts, photos, hidden contact information, provider payloads, or credentials. Information returned to ChatGPT is then processed under the terms and privacy choices of your OpenAI account.
When ChatGPT successfully completes a new OAuth connection to the public read-only EventMatch MCP, EventMatch retains the first confirmed time and the associated EventMatch user, organization, and OAuth client for private connection counts and duplicate prevention. This is not a count of plugin installations. Private operations receive a notification without the user's email or organization name. OAuth codes and tokens are not included in this connection history or notification.
The private EventMatch event-companion connection may start or end the connected user's Event Mode after confirmation. It may return that same user's Live Coach summary and guidance, but not the raw realtime transcript. It cannot start or stop Omi recording.
If an organization owner or administrator connects the private EventMatch app, the same connection can read the approved information above and request EventMatch to start Luma event synchronization, attendee-directory synchronization, or analysis jobs after confirmation. EventMatch records the requesting user, target record, and safe job identifier for audit purposes. The app cannot send outreach, register for events, expose browser controls, or access the excluded data above.
Luma connection choices
When the internal Luma Session Companion canary is available, you may explicitly transfer your existing Chrome Luma session instead of signing in inside the EventMatch browser. The extension reads only bounded first-party luma.com cookies and exact-origin local storage after your separate confirmation, encrypts the data locally, and sends only the encrypted envelope to EventMatch. EventMatch decrypts it only for the in-memory import into a new organization-isolated browser profile and verifies that the session persists after restart before replacing an existing profile.
Failed candidates and temporary keys, capabilities, and envelopes are cleared. The promoted server-browser profile remains credential-equivalent private account data until you disconnect or replace the Luma connection. EventMatch never asks the extension for your password, history, clipboard, another origin, IndexedDB, or hidden account information.
Cookies and product analytics
EventMatch uses essential session and CSRF cookies to keep sign-in and authenticated requests secure. It also stores safe browser preferences, including theme and cookie choices, on your device. Essential storage cannot be disabled through the preference center because the product cannot operate securely without it.
With your permission, EventMatch uses Google Analytics 4 to understand aggregate product usage, such as page categories, device and browser types, approximate region, and referral source. Analytics does not load until you choose to allow it on this browser.
EventMatch does not send Google Analytics attendee names, people names, event-match scores, transcripts, photos, search parameters, invitation or reset tokens, or internal record identifiers. Dynamic page addresses are reduced to generic route categories. Advertising signals and ad personalization are disabled.
See the Cookie Policy for the current categories and controls.
Retention, disconnect, and deletion
Imported Omi transcripts, authorized Live Coach transcript segments, and derived data are retained until you explicitly delete them, or until your user or organization is deleted. Disconnecting Omi removes the local connection credential but does not delete prior imports. You can delete all of your Omi data in Settings, delete one event's data in the event workspace, or delete an individual imported conversation from its report.
Captured photos are retained until you delete the photo or your user or organization is deleted. Deletion removes the normalized image and thumbnail, encrypted Photo AI observations, review suggestions, and encounter-draft photo link. Disabling Photo AI Review stops future external photo analysis but does not delete completed results; delete the corresponding photo to remove them.
EventMatch does not retain face templates or embeddings. Encrypted biometric run candidates and evidence expire within 30 days. Withdrawing biometric consent or deleting the photo, user membership, user, or organization will delete associated unconfirmed biometric artifacts. Biometric reference images and URLs, scores, candidates, evidence, and results are excluded from logs, analytics, notifications, MCP, Django Admin, audit metadata, and background-job payloads or results. A photo-to-Person tag you explicitly confirmed is an ordinary private tag and remains until you remove it or delete the photo.
Uploaded audio is retained until you delete the file or your user or organization is deleted. A transcript, speaker segments, and event report created from uploaded audio are encrypted and retained with that recording until the same deletion. Deletion removes the private audio object, transcript, derived report, and event suggestions. Importing or assigning an audio file does not start transcription automatically.
Omi does not provide EventMatch with a remote revocation endpoint. After disconnecting in EventMatch, disable the EventMatch app in Omi to revoke Omi-side access.
You can revoke a ChatGPT or Codex connection in Settings. Revocation invalidates its EventMatch access and refresh tokens immediately, but it does not delete content already present in your OpenAI conversations. Delete that content through the applicable OpenAI product controls.
Revoking a public ChatGPT connection does not erase its first-connection history, so a reconnect is not counted twice. This minimal history is deleted when the associated EventMatch user, organization, or OAuth client is deleted. Operational notification records expire after 30 days.
Access and security
Transcript-dependent records belong to the EventMatch user who imported them and are not visible to other members of the same organization. Business records are organization-scoped, and cross-organization access is rejected without revealing whether the record exists. EventMatch uses session authentication, CSRF protection, encrypted secret storage, rate limits, bounded payloads, and redacted operational logs.
Captured photos are visible only to the user who captured them, even when other users belong to the same organization. Photo files are delivered through authenticated, non-cacheable responses.
Uploaded audio files are visible only to the user who imported them, even when other users belong to the same organization. Playback uses the same authenticated, non-cacheable delivery boundary.
Recording consent and contact
You are responsible for giving notices and obtaining any consent required before recording or processing a conversation. Laws differ by location and the people involved.
Questions or deletion requests can be sent to info@eventmatch.ai.