hesed Join waitlist

On this page

  1. The short version
  2. Who we are
  3. Two kinds of people this policy covers
  4. What we collect
  5. Sensitive information in your messages
  6. Additional limits on our use of your Google user data
  7. How we use your data, and why we are allowed to
  8. Profiling and automated decisions
  9. AI and automated processing
  10. If you are a contact, not a user
  11. Who we share data with
  12. Where your data goes
  13. How long we keep it, and how to have it deleted
  14. Your rights
  15. Security
  16. Children
  17. Changes
  18. Contact

Privacy policy

Last updated: 21 August 2026

The short version

hesed helps you keep track of the people who matter to you. To do that, it reads your email, calendar, contacts and messages, with your permission, and organises them by person.

  • We do not sell your data. We do not use it for advertising. There is no advertising business here.
  • We do not use your content, or your contacts' content, to train AI models.
  • We never modify or delete anything in your mailbox. We can send a message only when you write one here and press send yourself.
  • You can disconnect any account at any time, and ask us to delete your data whenever you want.
  • If you are one of our users' contacts and you want to know what we hold about you, or want it gone, write to privacy@hesedapp.ai and we will act on it.

The rest of this page is the detail. If anything below contradicts the summary, the detail wins.

Who we are

Hesed Holdings Ltd (company number 17219082), registered in England and Wales, trading as hesed.

We are the data controller for the personal data described here. That means we decide why and how it is processed, and we carry the legal responsibility for it. We do not push that responsibility onto you.

Questions, requests and complaints: privacy@hesedapp.ai.

Two kinds of people this policy covers

This matters, and most privacy policies fudge it. We hold personal data about two groups.

Users. People who create an account and connect their own accounts to the service. If that is you, you chose to be here and everything below about accounts and rights applies to you directly.

Contacts. People who appear in a user's email, calendar, address book or messages. If that is you, you did not sign up: someone you know did, and their mailbox contains messages with you in them. The section below sets out exactly what we hold about you and how to have it removed.

What we collect

Information you give us

Your email address, and any preferences or notes you enter. We hold no password: you sign in with a one-time code sent to your email. If and when we charge for the service, our payment provider handles your card details and we never see them.

Providing this is necessary to have an account. Connecting any third-party account is optional, though the product does very little without one.

Information from the accounts you connect

You choose which accounts to connect, and you can disconnect any of them at any time. Today that is:

Source What we read What we never do
Gmail (gmail.readonly, gmail.send) Message headers (sender, recipients, subject, date) and the plain-text body, truncated at 32,768 characters. On first connection, the last 90 days. Read or store attachments of any kind. Modify, label or delete anything. Send anything you did not write and send yourself.
Google Calendar (calendar.readonly) Event title, location, start and end times, attendees, organiser and video-call link, for 90 days either side of today. Read the description or notes body of any event. Create, change or cancel events.
Google Contacts (contacts.readonly) Names, email addresses, phone numbers and birthdays. Request photos, job titles, postal addresses or notes. Write back to your address book.
Slack Message content and participants from conversations you are in. Post as you without your action.
WhatsApp Message content, participants and call logs from chats you are in. Send without your action.
LinkedIn Your connections, conversations and message content. Send without your action.
Granola Your meeting notes and transcripts, and who attended. Modify your notes.

gmail.send deserves its own sentence, because it is the permission people are right to be wary of. It is used in exactly one place: when you write a reply inside hesed and press send. No background job, scheduled task or AI process can send mail. Nothing is ever sent on your behalf without you doing it.

Information we generate

Summaries, suggested reach-outs, drafted messages, and signals such as how long it has been since you last spoke to someone. These are derived from the above, and they are personal data too, about you and about the people in your contacts.

Information collected automatically

We keep operational logs so we can run the service and diagnose faults. They record identifiers, counts and error types. They do not contain the content of your messages, calendar entries or contacts.

We do not run advertising pixels, cross-site tracking, or third-party analytics.

Sensitive information in your messages

Email, calendar entries, messages and meeting transcripts are not neutral. Over a few years of correspondence they will almost certainly reveal things the law treats as special category data: health, religious or philosophical beliefs, political opinions, trade union membership, sex life or sexual orientation, and possibly racial or ethnic origin. A hospital appointment in your calendar is health data. A synagogue committee thread is data about religious belief.

We do not go looking for it, we do not tag or index it as such, and we do not use it to categorise anyone. But it is in there, and our summaries are produced from it.

If you are a user: by connecting an account you give your explicit consent for us to process whatever special category data it contains, for the sole purpose of providing the service to you. You can withdraw that consent at any time by disconnecting the source or asking us to delete your account, and doing so does not affect processing that already happened.

If you are a contact: see the section below.

Additional limits on our use of your Google user data

This section is required by Google and it overrides anything else on this page.

hesed's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy and the Google Workspace User Data and Developer Policy, including the Limited Use requirements.

Specifically:

  1. We use Google user data only to provide and improve the user-facing features described on our site and in this policy.
  2. We do not transfer Google user data to others, except as necessary to provide those features (see who we share data with), to comply with applicable law, or as part of a merger, acquisition or sale of assets where the acquirer is bound by this policy.
  3. We do not use Google user data for advertising, and we do not sell it. We do not use it to assess creditworthiness or for lending purposes.
  4. We do not retain or use Google user data to develop, improve or train generalised or foundational AI or machine learning models, and we do not store Google user data in conjunction with any such model. Where Google user data is processed by an AI model, it is only to carry out the specific action you have asked for in a user-facing feature, and only through providers who are contractually prohibited from retaining it or training on it.
  5. We do not allow humans to read your Google user data, unless you have given us your affirmative agreement to view specific messages, it is necessary for security purposes such as investigating abuse, it is required by law, or it is necessary for internal operations and the data has been aggregated and anonymised first.
  6. Connecting a Google account is not required to create an account with us.

You can revoke our access at any time at myaccount.google.com/permissions, independently of anything you do in our app.

How we use your data, and why we are allowed to

Under UK GDPR we need a lawful basis for each purpose. Ours:

What we do Why Lawful basis (Article 6)
Create and run your account You asked us to Contract
Build your per-person timeline from connected accounts It is the core of the product Contract
Generate summaries, suggestions and draft messages Same Contract
Send a message you have written, from your connected account You asked us to, each time Contract
Send you service messages and reminders you configured Same Contract
Keep the service secure, prevent abuse, debug failures We have to Legitimate interests
Marketing emails to people who are not yet users To grow Consent, withdrawable in one click
Comply with legal obligations We have to Legal obligation
Hold and process data about your contacts, who are not our users It is what makes the product work Legitimate interests, balanced against their rights

Where the data is special category data, Article 6 is not enough on its own and a condition under Article 9 is also required. For users we rely on your explicit consent, as described above.

Profiling and automated decisions

The product does profile people. Working out that a relationship has gone quiet, ranking who is worth your attention today, and inferring how close two people are, are all profiling in the legal sense, and we would rather name it than hide behind a denial.

What we do not do is make decisions about anyone by purely automated means that produce legal effects or similarly significant effects on them. Every suggestion is a proposal to a human. Nothing sends itself, nothing is decided about a person without you, and there is no scoring of people that is shared with anyone or used for any purpose beyond ordering your own list. If you want to know how a particular suggestion was arrived at, ask us.

AI and automated processing

The product uses large language models to summarise conversations, spot who has gone quiet and draft messages. To do that, the relevant message content, including email body text, is sent to a model provider along with names and dates. Three commitments:

  • We do not train models on your content. Not ours, not our providers'. Our AI providers are contractually bound not to retain data sent through their APIs or use it for model training.
  • Your data is not mixed with other users' data in any model, index or cache.
  • Nothing sends itself. Suggestions and drafts are proposals. You decide whether to act.

Content you connect is sent to the AI providers named below so it can be processed. If that is not acceptable to you, do not connect the account.

If you are a contact, not a user

You are reading this because someone told you we hold data about you, or because a user of ours mentioned us.

Where we got it. From an account belonging to someone you know, who connected their own email, calendar, address book or messaging account to our service. We did not buy it, scrape it or find it in a public register.

What we are likely to hold. Your name, email address, phone number if your contact had it, and the content of messages, meetings and calls between you and that person, because those sit in their accounts. We generate summaries of that history for their use only.

Who can see it. Only the user whose account it came from. Other users cannot see it. We do not build a shared database of people across users, we do not sell or publish any of it, and we do not use it to market to you.

How long we keep it. For as long as that user's account is open and the source stays connected, or until either of you asks us to remove it.

Why we are allowed to. We rely on legitimate interests: the user has a genuine interest in keeping track of their own correspondence, the processing is limited to correspondence they already lawfully hold, and we keep it confined to their account rather than pooling it across users.

What you can do about it. Write to privacy@hesedapp.ai. You can ask us what we hold, ask for a copy, ask us to correct it, object to the processing, or ask us to delete it. If you object, we will stop unless we have a compelling reason not to, and in practice we expect to comply. You can also ask the user directly to remove you, which achieves the same thing faster. You can complain to the ICO.

Who we share data with

We share personal data with:

  • Service providers who host, process or support the service, listed below. They act only on our written instructions under contracts containing the terms Article 28 requires, and cannot use the data for their own purposes.
  • Professional advisers, regulators and law enforcement, where we are legally required to, and only to the extent required.
  • An acquirer, if the business is sold, on the condition that they remain bound by this policy.

We do not sell personal data, and we do not share it for cross-context behavioural advertising.

Who What they receive Where
Amazon Web Services Hosting and database storage: all of your data United Kingdom (London)
OpenRouter, routing to Anthropic and Google Message content sent for summarisation and drafting United States
Amazon SES Your own email address, to send sign-in codes. No message content. United Kingdom (London)
Unipile The whole LinkedIn connection, in both directions: your connections, conversations and message content as we sync them, and any message you send European Union
Granola Meeting notes and transcripts, where you connect it per Granola's terms

WhatsApp is not on that list because we host that connection ourselves, so those messages do not pass through anyone else. Slack is reached directly.

We will publish any change to this list before it takes effect.

Where your data goes

Your data is stored in the United Kingdom (AWS London). Our AI providers are in the United States. Where personal data leaves the UK we rely on the UK International Data Transfer Addendum, EU Standard Contractual Clauses, or the provider's certification under the UK extension to the EU-US Data Privacy Framework.

How long we keep it, and how to have it deleted

We keep your data for as long as your account is open. Disconnecting a source stops us syncing anything further from it.

To have your data deleted, write to privacy@hesedapp.ai. You can ask us to delete everything from a particular connected account, or to close your account and delete all of it. We will do it within 30 days and confirm when it is done, and that includes the summaries and drafts generated from the data. Encrypted database backups age out on a rolling 7-day cycle.

We are building this as a self-service control in the product. Until it is there, the email route above is how it is done, and it is a real commitment rather than a formality.

Records we are required to keep by law, such as tax records, are kept for as long as the law requires and no longer.

Your rights

Under UK GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or send it to another provider in a portable format. Where we rely on consent, you can withdraw it at any time without affecting what we did before you did.

Write to privacy@hesedapp.ai. We will respond within one month. It is free unless a request is manifestly unfounded or excessive.

These rights belong to the people in your contacts as much as they belong to you.

Revoking access to a connected account. You can disconnect any account from within hesed at any time, which stops all syncing. To withdraw the permission itself at Google's end as well, visit myaccount.google.com/permissions. We recommend doing both.

Complaints. If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office, the UK supervisory authority, at ico.org.uk/make-a-complaint or on 0303 123 1113. We would rather you gave us the chance to fix it first, but you do not have to.

Security

Your data is held in a private database in AWS London that is not reachable from the public internet and is encrypted at rest. Connections to hesed are encrypted in transit over TLS 1.2 or better. Credentials for your connected accounts get a second layer: each is separately encrypted with AES-256-GCM before it is stored, using a key held in a managed secret store and never written to the database.

Access to production systems is limited to the smallest number of people and used only to operate the service. We hold no security certification such as SOC 2 or ISO 27001 today, and we would rather say so than imply otherwise. No system is perfectly secure. If a breach is likely to result in a risk to your rights we will report it to the ICO within 72 hours, and if the risk is high we will tell you directly and without undue delay.

Children

The service is not for anyone under 18, and you must be 18 to open an account. We do not knowingly collect data from children, and we will delete it if we find it.

Contacts are a different matter: a user's address book may contain family members who are children, and their data is processed like any other contact's. If you are a parent or guardian and want a child's data removed, write to privacy@hesedapp.ai and we will act on it.

Changes

We will update this page when the product changes, and the date at the top will change with it. For anything material we will email account holders before it takes effect.

Contact

privacy@hesedapp.ai

Hesed Holdings Ltd, company number 17219082, registered in England and Wales.

hesed

© 2026 Hesed. All rights reserved.