Privacy Policy
Last updated: 4 October 2026
This policy explains what data HeyBob collects, why, and how we protect it. HeyBob is operated by Tiny Cloud Ventures (“we,” “us”). If anything here is unclear, email [email protected].
What we collect
- Account & workspace data: your name, work email, workspace name, and billing details.
- Messages you direct to Bob: the requests you @mention or send Bob, and the results, files, and receipts of each run.
- Connected-tool data: the specific data Bob reads or writes in the tools you connect (e.g. a CRM record, an accounting entry) in order to complete a task you asked for.
- Workspace memory: preferences, definitions, and decisions your team asks Bob to remember. This is scoped to your workspace and editable by you.
- Usage & audit metadata: run timestamps, tool calls, approvals, and credit accounting: the data behind your receipts and audit log.
- Website analytics: usage events on heybob.ai (pages viewed, links and buttons clicked) via Aptabase and PostHog, our analytics providers. We set no cookies for analytics; PostHog uses a first-party identifier stored in your browser to group a visit into a funnel. No cross-site tracking, no advertising networks, and no session recording.
- Waitlist requests: if you ask to be told when Microsoft Teams support is ready, we store the email address you type and nothing else. We use it to email you about that one thing. It is not a newsletter signup, it is not shared, and you can have the entry deleted at any time by emailing [email protected].
What we do not do
- We do not use your data, prompts, or connected-tool content to train external AI models.
- We do not sell your data.
- Bob only reads the messages directed to him (an @mention or a direct message), not your team’s wider conversations.
Meeting audio and notes
If you record a meeting in the HeyBob app, the audio is sent to our transcription provider a minute at a time to be turned into text, and the transcript and your notes are then sent to our AI model provider to write the notes, summary and action items. Our servers keep none of the audio; the app holds each minute on your Mac only until it has uploaded. The transcript, your notes and the summary are stored encrypted until you delete the meeting, and deleting it removes them. Deleting the meeting does not remove what was made from it elsewhere: a summary you chose to post in a channel, the action items Bob sent to your Slack or Teams DM, Bob’s answers when you asked him about the meeting, and any job you asked Bob to do from an action item. Those stay where they are, and our records of those jobs follow the retention rules below.
How connected credentials are handled
Credentials for tools you connect are held in a dedicated OAuth vault, encrypted at rest, and are never stored in our application database. Agent runs execute in isolated sandboxes with no direct access to those credentials; tokens are used server-side to make the specific tool calls a task requires.
Google user data
When you connect a Google account, Bob accesses Gmail, Google Calendar, Google Drive, and Google Sheets data only to carry out the specific task you ask for in a thread. Bob’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Because some of what you can ask Bob to do touches Gmail and Google Drive content, we affirm the following Limited Use commitments for Google user data specifically:
- We use Google user data only to provide and improve the user-facing features you invoke in a given request.
- We do not transfer or sell Google user data to third parties, except as needed to provide the feature you asked for, for security purposes, or to comply with applicable law.
- We do not use Google user data for advertising.
- We do not allow humans to read Google user data unless you give explicit consent for specific messages or files, it is necessary for security or to comply with the law, or the data has been aggregated and anonymized.
- We do not use Google user data to train AI models.
Bob reads only the messages, events, and files needed for the request in that thread; it does not bulk-export, index, or retain your Google content beyond what your run history and audit log record.
Subprocessors
To run the product we rely on a small set of vendors: a cloud hosting provider (which also hosts our database), our AI model provider (Anthropic), a payments processor (Stripe), the connector platforms that securely store the OAuth credentials for the third-party apps you choose to connect, a text-embeddings provider used for workspace memory, a speech-to-text provider for meeting transcripts, an inbound-email processor, and our website analytics providers. Bob's use of Anthropic's models runs on our own commercial account; your prompts and connected-tool content are not used to train any AI model. We provide our current, named list of subprocessors, including what each does and the data it may process, to customers on request and as part of your data processing addendum.
Data retention & deletion
Different records are kept for different lengths of time, and we would rather say so than round up. Your workspace settings, connections, schedules, memories and the activity log (which tool ran, when, on whose request, and whether it succeeded) are kept for as long as your workspace is active. The step-by-step timeline inside each run, the part you scroll through when you open a run, is kept for 90 days and then deleted. Bookkeeping around learning and delivery is kept for between 7 and 90 days, and the short-lived markers we use to avoid handling the same event twice are deleted after 48 hours. You can request export or deletion of your workspace data at any time by emailing us; we will action deletion requests within 30 days, subject to any legal retention obligations. Data present in encrypted database backups is purged as those backups roll off on our provider's schedule.
Security
Data is encrypted in transit (TLS) and at rest. Access to production systems is restricted and logged. A SOC 2 examination is in progress; we will update this page as that work completes.
Your rights
Depending on where you are, you may have rights to access, correct, export, or delete your personal data. To exercise any of these, email [email protected] and we’ll respond.
Changes to this policy
If we make material changes, we’ll update the date above and, where appropriate, notify workspace admins.