Last updated: June 22, 2026
Privacy Policy
LISA is an AI meeting assistant built by GetMax Healthcare Solutions. This page explains what data we collect when you use LISA, how we use it, and how long we keep it.
Who this covers
This policy applies to people who sign in to LISA at lisa.getmaxglobal.com and to anyone whose meeting data passes through the service. For example, a participant in a meeting that a LISA user records or transcribes.
What we collect and why
Account and identity
- Your name and email address, from Google or Microsoft sign-in.
- We use this to authenticate you and to scope your data inside our database.
Calendar and meeting metadata
- Meeting titles, times, attendees, and video conference links from your Microsoft 365 calendar.
- We read this to show your upcoming meetings and to know when to join on your behalf.
- We do not read calendar invite bodies beyond what is needed to find a conference link.
Meeting transcripts and minutes
- When LISA joins a meeting, it records audio and generates a transcript.
- We process the transcript to produce minutes, action items, and follow-up drafts.
- Transcripts are stored in our database and accessible only to users in your workspace.
Email metadata (inbox integration)
- If you connect your Microsoft 365 inbox, LISA reads subject lines, sender, and recipient fields to surface relevant emails alongside meetings.
- LISA reads full message bodies only when you ask it to summarize or reply to a specific email.
Tasks, notes, and agent memory
- Action items and notes you create, or that LISA extracts from meetings, are stored in our database scoped to your account.
- LISA maintains a short-term memory of recent instructions so it can act consistently across a session.
Usage activity
- Actions you take inside LISA (scheduling a meeting, running a summary, sending an email) are logged for debugging and audit purposes.
- We do not use these logs for advertising.
HIPAA and healthcare data
GetMax Healthcare Solutions operates in healthcare Revenue Cycle Management. If you use LISA in a healthcare context, meeting transcripts may contain Protected Health Information about patients.
LISA is designed to operate under HIPAA constraints:
- Transcript data is stored only in our secured database, not used to train any AI model.
- We do not share transcript content with third parties except as required to deliver the service.
- If your organization requires a Business Associate Agreement, contact sriram@getmaxrcm.com.
How long we keep data
- Meeting transcripts and minutes: Retained until you request deletion. No automatic expiry.
- Tasks and notes: Retained until you delete them or request account deletion.
- Activity logs: Retained for 90 days, then deleted automatically.
- Rate-limit records and session tokens: Short-lived; expire within hours to days.
- Waitlist entries: Retained until you ask to be removed.
You can request deletion of all your workspace data at any time. See the rights section below.
Who we share data with
We do not sell your data. We share it only with services required to run LISA:
- MongoDB Atlas - our database (US region, encrypted at rest).
- Microsoft Graph API - to read your calendar and inbox with your permission.
- Recall.ai - meeting bot infrastructure that joins video calls to record and transcribe.
- AI providers (Groq, Anthropic, OpenRouter) - to generate summaries, minutes, and replies. We pass only the content needed for the task.
- Email delivery (Brevo, Resend) - to send notifications and follow-up emails on your behalf.
Each provider is bound by their own data processing terms. We do not grant them the right to use your data for their own purposes.
Your rights
Email sriram@getmaxrcm.com at any time to:
- Get a copy of the data we hold about you.
- Correct inaccurate data.
- Request deletion of all your workspace data — meetings, transcripts, tasks, notes, activity logs, agent memory, state, connections, and autorecord rules. We will complete deletion within 30 days and confirm by email. You can also trigger deletion by calling
DELETE /api/lisa/data/deletewhile signed in. - Withdraw your Microsoft or Google access grant through account settings at any time.
Cookies and authentication
LISA uses a session cookie (lisa_session) to keep you signed in. It is HTTP-only, Secure, and SameSite=Lax. We do not use tracking or advertising cookies.
Two-factor authentication state is stored in a short-lived cookie (lisa_2fa) that expires within minutes.
Security
All traffic uses HTTPS with a one-year HSTS policy. Every API route that reads or writes user data requires an authenticated session. We offer TOTP two-factor authentication and recommend enabling it.
Changes to this policy
If we make a material change to how we use your data, we will email you before it takes effect. The date at the top of this page shows when it was last revised.
Contact
sriram@getmaxrcm.com
GetMax Healthcare Solutions