Privacy Policy
1. Who we are
HeyJEIN(“HeyJEIN”, “we”, “us”) is a signal-intake service operated at heyjein.com. HeyJEIN collects the messages, calendar events and contact records you choose to connect, and routes them into the focus and triage platforms built on top of it. This policy covers heyjein.com, the HeyJEIN intake layer, and those platforms.
HeyJEIN is a personal-productivity product. We do not sell data, we do not serve advertising, and we do not operate an ad network or data broker business of any kind.
2. Google user data
Connecting a Google Account is entirely optional. If you choose to connect one, HeyJEIN requests only the scopes listed below, and uses the data they grant only to provide the features described alongside them.
| Scope requested | What it grants | Why we request it |
|---|---|---|
https://mail.google.com/ | Gmail access over IMAP | To read your recent mail so each message can appear as a triageable signal in your feed; to send a reply when you compose and send one from the app; and to move a message to Trash when you triage it that way. HeyJEIN never sends, archives or deletes mail on its own initiative. |
.../auth/calendar.readonly | Read your calendars and events | To show your upcoming events in context alongside the people and topics they relate to. |
.../auth/calendar.events | Create and update events | To write an event back to your calendar when you schedule or accept one inside the app. Only events you create or change through HeyJEIN are written. |
.../auth/contacts | Read and write your contacts | To match incoming messages and events to the right person, and to save a contact back to Google when you add or correct one in the app. |
.../auth/userinfo.email | Your Google account email address | To label the connection so you can tell multiple connected accounts apart and disconnect the right one. |
Limited Use disclosure
HeyJEIN’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google user data only to provide and improve the user-facing features described above.
- We do not transfer Google user data to third parties except as required to provide those features, to comply with applicable law, or as part of a merger or acquisition (in which case this policy continues to apply).
- We do not use Google user data for advertising, and we do not sell it.
- We do not use Google user data to develop, improve or train generalized or non-personalized artificial-intelligence or machine-learning models.
- No human reads your Google user data except where you have explicitly asked us to (for example, to investigate a support issue you reported), where it is necessary for security purposes such as investigating abuse, or where required by law.
AI processing
HeyJEIN uses AI to help organize and enrich signals. Today, the only data sent to a third-party AI provider (Anthropic) is a company name and public web domain used to look up publicly available business information. The contents of your Gmail messages, calendar events and contact records are not sent to third-party AI providers, and are never used to train any model. If this ever changes, we will update this policy before the change takes effect.
3. Other information we collect
- Account information— the email address you sign up with, and authentication state.
- Content you create— notes, captures, tasks, plans, comments and images you add in the app.
- Other connected sources— if you connect them: Microsoft 365, iCloud, generic IMAP mailboxes, RSS feeds, and other integrations. Each is optional and independently disconnectable.
- Event page responses— if you RSVP to a HeyJEIN event page, the name, email address and note you submit, plus the IP address and browser user-agent of the submission (used to prevent abuse).
- Operational logs— error and request logs generated by our hosting providers, used to keep the service running and secure.
4. Where your data is stored
HeyJEIN’s platform layer (event pages, RSVPs, routing) is stored in a shared PostgreSQL database hosted by Supabase (the heyjein-platformproject). Each tenant platform stores its users’ content in its own separate Supabase project, so one tenant’s data is not commingled with another’s. heyjein.com never reads or writes a tenant database directly; it goes through the HeyJEIN API, which routes to the correct tenant.
Images you capture or upload are stored in object storage (Supabase Storage and, for private capture images, Backblaze B2). All data is stored in the United States.
Security
- All traffic is encrypted in transit over TLS; data is encrypted at rest by our storage providers.
- OAuth refresh tokens for connected accounts are encrypted before being stored, using a key that is not kept alongside the encrypted value.
- Row-level security policies scope every read and write to the account that owns the row.
5. How long we keep it
| Data | Retention |
|---|---|
| Email message content pulled from Gmail / iCloud / IMAP | Pruned after 45 days. The signal record (that a message existed, from whom, and how you triaged it) is kept; the message body is removed. |
| RSS article content | Pruned after 7 days |
| Items you mark Done | Kept for 30 days, then deleted |
| Notes, tasks, plans and other content you create | Kept until you delete it or close your account |
| Google OAuth tokens | Deleted immediately when you disconnect the account |
6. Who we share it with
We share data only with the service providers needed to run HeyJEIN, each of which processes it on our behalf under their own terms:
- Supabase — database, authentication and file storage
- Vercel and Fly.io — application hosting
- Cloudflare — network routing and DDoS protection
- Backblaze B2 — private image storage
- Resend — transactional email (RSVP confirmations, calendar invites, notifications)
- Anthropic — AI enrichment, limited to the data described in section 2
We may also disclose data if required by law, or to protect the rights, safety and property of HeyJEIN or its users. We never sell your data.
7. Your choices and rights
- Disconnect Google at any timefrom Settings → Integrations in the app. Disconnecting revokes the token at Google and deletes the stored credential.
- You can also revoke HeyJEIN’s access directly at myaccount.google.com/permissions.
- Access, correct, export or delete your data— email us at the address below and we will action the request. Deleting your account removes your content and connected credentials.
- Depending on where you live, you may have additional rights under the GDPR or CCPA, including the right to object to processing and to lodge a complaint with a supervisory authority.
8. Children
HeyJEIN is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.
9. Changes to this policy
We may update this policy as the service changes. Material changes to how Google user data is handled will be reflected here before they take effect, and the “Last updated” date above will change.
10. Contact
Questions about this policy, or about data we hold about you: [email protected].