Introduction
Ron is an AI Talent Manager operated by Polar Bear ("Polar Bear", "we", "us"). Ron works inside a company's own messaging tools to support onboarding, growth conversations, scheduling and follow-ups. Your privacy matters to us, and this Privacy Policy explains what information we collect, how we use it, and the choices you have.
Our role: controller and processor
Ron is deployed for companies ("Clients"), and the people who talk to Ron ("Users") are typically the Client's team members. This creates two roles:
- Polar Bear as processor. For data processed inside a Client deployment (conversations with Ron, onboarding progress, meeting scheduling, review-cycle materials), the Client is the data controller and Polar Bear processes this data on the Client's behalf, under a data processing agreement with that Client and according to its instructions.
- Polar Bear as controller. For data we collect directly (website visits, demo conversations with Ron, waitlist and contact form submissions, and account data of Client administrators), Polar Bear is the data controller.
Data we collect
- Identity and contact data: name, work email address, messaging platform identity (e.g. Slack user ID, WhatsApp or Telegram number), and, where you submit our forms, your LinkedIn profile URL and company.
- Conversation data: the content of your conversations with Ron in connected messaging platforms.
- Client Materials: org structure, roles, career frameworks, values, policies and similar content the Client provides to configure Ron.
- Process data: onboarding milestones, check-in responses, scheduling and reminder state, and review-cycle inputs handled through Ron as configured by the Client.
- Calendar data: if you connect a Google account, the calendar information described in the Google Calendar section below.
- Website data: basic analytics about visits to our public website.
We practice data minimization. Ron does not track working hours or activity, does not read messages, channels or documents it has not been given access to, and does not collect data beyond what the configured journeys require. We do not intentionally collect sensitive personal data (such as health information or beliefs); if a User volunteers such information, Ron is designed to redirect the conversation to a designated human contact rather than process it further.
How we use data
- To provide the Service: hold conversations, onboard new joiners, schedule and prepare meetings, send reminders, and run the people processes the Client has configured.
- To give each User access to their own information (for example, their own past feedback or growth plan), with access controls: a User sees their own data, a manager sees their team as configured, and leadership sees aggregated views only.
- To improve the Service, using aggregated and de-identified information.
- To communicate with prospective Clients who contact us or join our waitlist.
- To comply with legal obligations.
Legal bases (GDPR)
- Contract performance (Art. 6(1)(b)): providing the Service to Clients and Users.
- Legitimate interests (Art. 6(1)(f)): service improvement, security, and abuse prevention.
- Consent (Art. 6(1)(a)): connecting a Google account, demo conversations, and any marketing communications. Consent can be withdrawn at any time.
- Legal obligation (Art. 6(1)(c)): compliance with applicable law.
Google Calendar integration
When you connect your Google account, Ron requests only the OAuth scopes needed to help you schedule meetings. Ron never requests access to your Contacts, Gmail, Drive, or any other Google product.
Ron uses free/busy access to find availability and event access to keep the meetings it manages current. Write access is used only for meetings Ron schedules or is explicitly asked to manage: Ron may create those events, update their time, details or attendees, or cancel them. Ron does not edit, delete, or otherwise modify existing calendar events that it did not book for you.
The scopes we request, and how each one is used:
openid,userinfo.email,userinfo.profile: identify the Google account you connected so we can associate the integration with your Ron identity. We store the connected account's email address.calendar.calendarlist.readonly: read-only access to your calendar list so Ron can find your primary calendar and timezone for scheduling.calendar.freebusy: read your free/busy availability (busy time blocks only, no event titles, descriptions, attendees or locations) so Ron can suggest times that work for you.calendar.events.owned: view event details on calendars you own so Ron can support scheduling, preparation and follow-up of the meetings it manages. Ron uses the write portion of this scope only to create, update or cancel meetings Ron books for you when you authorize scheduling.
Google API Services Limited Use disclosure
Ron's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google user data only to provide and improve user-facing features of Ron's scheduling experience.
- We do not transfer Google user data to third parties except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition or sale of assets with notice to users.
- We do not use Google user data for serving advertisements, including retargeting, personalized or interest-based advertising.
- We do not use calendar attendee information to market to or enroll those attendees in Ron.
- We do not use Google user data to train AI or machine-learning models.
- We do not allow humans to read Google user data unless we have your affirmative consent for specific data, it is necessary for security purposes (such as investigating abuse), to comply with applicable law, or for internal operations where the data has been aggregated and anonymized.
You can disconnect your Google account from Ron at any time by asking Ron, contacting us, or revoking access directly at myaccount.google.com/permissions. Disconnecting stops all future calendar access; events Ron previously created remain on your calendar unless you delete them. Calendar data already processed may be retained subject to the retention rules below unless you request deletion.
Third-party AI processing
Ron's conversational capabilities are powered by third-party AI model providers, such as Anthropic and OpenAI. Conversations with Ron and the context needed to answer (such as relevant Client Materials) may be processed by these providers to generate Ron's responses. These providers process data according to their own privacy and security terms, and we select them based on their security practices. Where a Client deployment uses the Client's own AI provider account (API keys), that processing occurs under the Client's agreement with the provider. We do not permit our AI providers to train their models on Client or User data processed through Ron.
Data sharing
- Within your organization: Ron shares information between colleagues only as the configured process requires, for example, a meeting agenda sent to both participants, or an aggregated flag to a manager. Check-in responses are private by default; managers receive signals, not transcripts, and leadership receives aggregated views only.
- Service providers: hosting, database, messaging platform, and AI model providers necessary to run the Service, bound by data protection agreements.
- Legal: where required by applicable law.
We do not sell personal data. We do not share personal data with advertising platforms.
Data retention
- Client deployment data: retained for the duration of the Client agreement and deleted or returned within 90 days of its termination, per the data processing agreement.
- Google Calendar data: availability lookups are used transiently; details of meetings Ron manages are retained while those meetings are active and per the Client agreement.
- Demo and waitlist data: retained up to 12 months after last contact, then deleted.
- Legal compliance data: retained as required by applicable law.
Security
- Encryption of data in transit and at rest.
- Personal identifiers stored separately from working data, with pseudonymized references in operational databases.
- Role-based access controls: each User sees their own data, managers see their configured team, leadership sees aggregates.
- Audit logging of system actions.
- Access to personal data by Polar Bear team members is restricted to what is necessary for operating, securing and supporting the Service, under confidentiality obligations.
Data breaches
In the event of a personal data breach that poses a high risk to your rights and freedoms, we will notify affected Clients and Users without undue delay, describing the nature of the breach, its likely consequences, and the measures taken or proposed to address it.
Your rights (GDPR)
- Access (Art. 15): request information about, and a copy of, your personal data.
- Rectification (Art. 16): request correction of inaccurate data.
- Erasure (Art. 17): request deletion of your personal data in certain circumstances.
- Restriction (Art. 18): request that we limit processing in certain situations.
- Portability (Art. 20): receive your data in a structured, machine-readable format.
- Objection (Art. 21): object to processing based on legitimate interests.
- Automated decision-making (Art. 22): Ron does not make decisions producing legal or similarly significant effects about you; employment decisions are made by humans at your organization.
To exercise these rights, contact privacy@meet-polar-bear.com. Where Polar Bear acts as processor for your employer's deployment, we may refer your request to your organization as the controller, and will support them in responding. We respond within one month of receiving a valid request.
Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated at least 30 days before they take effect. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.
Contact
- Privacy and data protection: privacy@meet-polar-bear.com
- General inquiries: hi@meet-polar-bear.com
Operated by Polar Bear · Last updated: July 10, 2026