Privacy & Data Policy

Who we are

Drive My Path ("Drive My Path," "we," "us") is a product of JBran LLC — a tool that helps managers run better one-on-ones, track goals and performance, and build stronger working relationships. This policy explains what data the service handles and how. Questions: support@drivemypath.com.

What we collect

  • Account information — your name, email address, and a hashed password (we never see or store your plaintext password).
  • Content you create — team member profiles, meeting agendas and notes (including working notes), goals, metrics, feedback logs, review preparation, and roll-up reports. You control every word of it.
  • Acknowledgment records — when you share a review draft, the recipient's typed name, optional comment, and a timestamp are recorded as proof of receipt.
  • Essential cookies only — a session cookie that keeps you signed in. We run no advertising pixels, no cross-site trackers, and no third-party analytics scripts.

What we do NOT do

  • We do not sell or share your data with third parties.
  • We do not use your data for advertising, ours or anyone else's.
  • We do not allow AI providers to train on your data. When you explicitly use an AI feature, your content is sent for processing only and is not used to train models.
  • We do not read your content except when strictly necessary to fix a problem you've asked us to fix, or as required by law.

Service providers (subprocessors)

Running any cloud service requires infrastructure. These providers process data solely on our instructions to operate Drive My Path, and are bound by their own contractual confidentiality obligations:

  • Supabase — database and authentication hosting. All data is encrypted in transit (TLS) and at rest.
  • Anthropic (optional) — only if you use an AI feature such as AI-polished roll-ups or drafted meeting notes. The relevant text is processed to generate your output and is not used for model training.
  • Deepgram or OpenAI (optional) — only if you record a meeting. Audio is transcribed and then the audio file is deleted immediately; we retain only the transcript you keep.
  • Cloudflare — application hosting and edge delivery. Every request to Drive My Path passes through Cloudflare.
  • Resend (optional) — only if email is enabled on your account. Used to deliver your pre-meeting brief and to send a report the link to their own page. It carries names and meeting subjects, so it is listed here rather than treated as plumbing.
  • Google (optional) — only if you connect a Google Calendar. See the section below, which describes exactly what we read and what we do not.

No other third party receives your data. If this list ever changes, we will update this page before the change takes effect.

Google Calendar data

Connecting a Google Calendar is entirely optional. Drive My Path works without it, and nothing about your account changes if you never connect one — you simply enter your one-on-ones by hand instead of syncing them.

If you do connect it, here is precisely what happens.

  • What we request. Access to the events on your calendar (calendar.events), your free/busy times (calendar.freebusy), and your Google account email address (userinfo.email). We never request access to your calendar's settings, sharing, or anything beyond its events and availability.
  • What we read. Event times, titles and attendee email addresses, used for one purpose: recognising which events are your one-on-ones and matching them to the right team member by their work email.
  • What we create and delete. When you schedule a 1:1 in Drive My Path, we create that one event on your calendar with your team member invited at their work email; if you cancel that 1:1 here, we delete that same event and Google notifies them. We only ever delete events Drive My Path itself created — never anything you or anyone else put on your calendar.
  • What we look up but never store. When you pick a time for a 1:1, we ask Google for busy/free blocks on that day — yours, and your team member's only where their calendar is already visible to your Google account under their own sharing settings. This shows on screen while you schedule and is not saved, logged, or aggregated. It is only ever busy-or-free times, never the contents of anyone's events.
  • What we store. The matched meeting time and a Google event identifier, so the same meeting is not imported twice. We do not copy your wider calendar into our database, and events that do not match a team member are ignored rather than kept.
  • How access is protected. Google access and refresh tokens are stored server-side only, are encrypted at rest, and are never exposed to the browser or to any other user.
  • How to revoke it. Disconnect on the Settings page at any time, which deletes the stored tokens. You can also revoke access directly from your Google Account's security settings, which we honour immediately.

Limited Use. Drive My Path's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Concretely: we do not use Google user data to serve advertising, we do not sell or transfer it, we do not use it to train any AI or machine-learning model, and no human reads it except where you explicitly ask us to for support, or where security or the law requires it.

About your team members' information

Drive My Path is a tool managers use to record information about their direct reports — names, work goals, feedback, and personal details like family names or upcoming events that managers note to be better colleagues. If you are a manager using Drive My Path, you are responsible for using it consistently with your company's policies and applicable employment and privacy laws, including any notice obligations to your team. If you are a team member and want information about you corrected or removed, ask your manager — they have full ability to edit or delete it, and deleting their account removes it entirely.

Recording consent

The meeting recorder captures audio only when a manager starts it. Many jurisdictions require the consent of everyone being recorded. It is the manager's responsibility to obtain any required consent before recording. Audio is deleted the moment transcription completes.

Data retention & deletion

  • Your data is retained while your account is active.
  • Export — you can download a complete copy of your data anytime from Settings.
  • Deletion — deleting your account permanently removes your profile and all content you created (team profiles, notes, reviews, plans, everything). This is enforced at the database level and is not reversible.

Security

  • Encryption in transit (TLS) and at rest.
  • Row-level security on every record: no Drive My Path user can ever read another user's data — including working notes — enforced by the database itself, not just the application.
  • Shared review/plan links use unguessable 128-bit tokens and expose only the fields marked shareable; working notes are never included.
  • Calendar and integration tokens are stored server-side only.

Your rights

Depending on where you live (e.g., GDPR in the EU/UK, CCPA/CPRA in California), you may have rights to access, correct, export, or delete your personal information. The export and delete tools in Settings satisfy most of these directly; for anything else, email support@drivemypath.com and we will respond within 30 days. We do not discriminate against anyone for exercising their rights, and — because we don't sell data — there is nothing to opt out of.

Data Processing Addendum

This addendum is incorporated into the Terms of Service and applies whenever Drive My Path is used for work. It takes effect on acceptance of those terms — no signature and no separate negotiation are required. It exists because the people you keep records about are not our customers and never agreed to anything with us; without a contract of this kind we would be a "third party" rather than a service provider, and would owe obligations directly to your reports that neither of us wants us to hold.

  • Roles. For personal data about your direct reports, your organisation is the controller (or "business") and JBran LLC is the processor (or "service provider"). You are the person acting for it.
  • Limited purpose. We process that data only to provide the service and on documented instructions — which these terms and your use of the product constitute. We do not retain, use, or disclose it for any other purpose, or outside our direct relationship with you.
  • No sale, no share, no combining. We do not sell or share personal data, do not use it for advertising, and do not combine it with personal data from any other source.
  • No training. No customer content is used to train any model, ours or a provider's.
  • Confidentiality. Anyone with access is bound to confidentiality.
  • Security. We maintain the measures described under Security above, including encryption in transit and at rest and row-level isolation enforced by the database.
  • Subprocessors. Only those listed above, each under equivalent written terms. We will update this page before the list changes.
  • Assistance. We will help you respond to a request from one of your reports to access, correct, or delete their information, and will tell you promptly if we receive one directly. The delete tools in the product satisfy most of these without our involvement.
  • Notice of inability. If we can no longer meet these obligations, we will tell you, and you may stop and remediate any unauthorised use.
  • Verification. You may take reasonable steps to confirm we are processing in line with this addendum.
  • Return and deletion. On account closure, or on your written request, we delete the personal data. Account deletion in Settings does this immediately and irreversibly.
  • International transfers. Our infrastructure is in the United States. Where transfer terms are required, the applicable standard contractual clauses are incorporated by reference.
  • Understanding. Both parties understand and will comply with these restrictions.

Changes

If we make material changes to this policy, we will notify account holders by email before the changes take effect. The "effective" date at the top always reflects the current version.