HeyConnect — Privacy Policy
Last updated: [set to publish date]
Heygroup LLC ("Heygroup", "we", "us") operates HeyConnect, a personal CRM for managing your professional contacts, friends, and acquaintances. This policy explains what personal data we handle, why, and your rights over it. It applies to the HeyConnect web application at heyconnect.app.
Who we are
Heygroup LLC is the data controller for the personal data described below.
- Address: 700 El Camino Real, Suite 120-1037, Menlo Park, CA 94025, United States
- Contact for privacy and data requests: support@heyconnect.app
Data we collect
Account data. Your email address and authentication credentials. Passwords are handled by our authentication provider and stored only as a secure hash — we never see or store your password in plain text. We also store your profile name and any cover image you upload.
Contact data you enter. HeyConnect exists to store information about other people. When you add or edit a contact, we store whatever you choose to enter — for example names, email addresses, phone numbers, locations, birthdays and anniversaries, family and relationship details, interests, professional details (company, job title, industry), social profile links, how you met, and your own notes.
Interaction and relationship data. Logs of your interactions and communications, tasks, goals and initiatives, comments, communication samples, and the preferences you set (such as tone, formality, and phrases to use or avoid).
AI-generated content. Summaries, insights, suggested next actions, and draft messages that our AI features generate from the data above, together with cached copies of those outputs.
Usage and billing data. Records of your AI feature usage for metering and rate-limiting, and billing identifiers associated with your subscription (handled through our payment provider — see below).
Email delivery data. Delivery status and suppression records for the transactional and account emails we send you.
We do not use third-party analytics, advertising, or tracking tools. The only cookies we set are strictly necessary ones: a functional cookie that remembers your sidebar state, and the session cookies required to keep you signed in.
Why we use it, and our legal bases
- To provide the service you signed up for — creating and managing your contacts, interactions, and tasks. Legal basis: performance of our contract with you.
- To generate AI insights, summaries, and draft messages, which run only when you explicitly trigger them. Legal basis: performance of our contract with you.
- To process your subscription and payments. Legal basis: performance of our contract with you; compliance with legal obligations.
- To keep the service secure, prevent abuse, and enforce usage limits. Legal basis: our legitimate interests in operating a secure service.
- To send you account and transactional emails, and to maintain email suppression records. Legal basis: performance of our contract; legitimate interests.
Data about other people
Because HeyConnect lets you store information about your own contacts, you are responsible for ensuring you have a lawful basis to store and use that information, and for handling any request from one of your contacts about their data. We process that data on your behalf to provide the service to you.
Who we share data with
We use a small number of service providers ("subprocessors") to run HeyConnect. They may process your data only to provide their services to us:
- Supabase — hosting of our database, authentication, storage, and server functions.
- Our AI processing providers (reached through the Lovable AI Gateway) — when you use an AI feature, the relevant content is sent to generate the requested output. Under our arrangements, your content is not used to train their models.
- Paddle — our payment provider and Merchant of Record. Paddle is the seller of record for your purchase and handles checkout, billing, and tax. Your payment details are provided to and held by Paddle, not us.
- Resend — delivery of our transactional and account emails.
- Cloudflare — hosting and edge delivery of the application.
We do not sell your personal data.
International transfers
We and our providers process data in the United States and may process it elsewhere. Where data is transferred out of the UK or EEA, we rely on appropriate safeguards such as standard contractual clauses.
How long we keep it
We keep your data while your account is active. When you delete your account (see below), your data is erased, subject to limited exceptions: we retain email suppression and unsubscribe records so that we do not contact you again if you re-enter our systems, and copies may persist briefly in routine backups before they cycle out. Our payment provider retains transaction records as required for its own legal obligations.
Your rights
Depending on where you live, you may have the right to access, correct, delete, export, or restrict the processing of your personal data, to object to processing, and to lodge a complaint with your data protection authority.
You can delete your account and all associated data at any time from Settings. For any other request, contact support@heyconnect.app.
Security
We enforce per-user access controls at the database level, encrypt data at rest, screen for leaked passwords at sign-in, and treat AI inputs as data rather than instructions. No system is perfectly secure, but we take reasonable measures to protect your data.
Children
HeyConnect is not directed at children and is not intended for use by anyone under 16. We do not knowingly collect data from children.
Changes
We may update this policy from time to time. Material changes will be notified through the service or by email. The "last updated" date above reflects the current version.