HeyBob. ← Back to heybob.ai

Privacy Policy

Last updated: 19 July 2026

This policy explains what data HeyBob collects, why, and how we protect it. HeyBob is operated by Tiny Cloud Ventures (“we,” “us”). If anything here is unclear, email [email protected].

This is our plain-English policy for the current product. It is not a substitute for legal advice, and we will publish a fuller version reviewed by counsel before general availability.

What we collect

What we do not do

How connected credentials are handled

Credentials for tools you connect are held in a dedicated OAuth vault, encrypted at rest, and are never stored in our application database. Agent runs execute in isolated sandboxes with no direct access to those credentials; tokens are used server-side to make the specific tool calls a task requires.

Google user data

When you connect a Google account, Bob accesses Gmail, Google Calendar, Google Drive, and Google Sheets data only to carry out the specific task you ask for in a thread. Bob’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Because some of what you can ask Bob to do touches Gmail and Google Drive content, we affirm the following Limited Use commitments for Google user data specifically:

Bob reads only the messages, events, and files needed for the request in that thread; it does not bulk-export, index, or retain your Google content beyond what your run history and audit log record.

Subprocessors

To run the product we rely on a small set of vendors: a cloud hosting provider (which also hosts our database), our AI model provider (Anthropic), a payments processor (Stripe), the connector platforms that securely store the OAuth credentials for the third-party apps you choose to connect, a text-embeddings provider used for workspace memory, an inbound-email processor, and our website analytics providers. Bob's use of Anthropic's models runs on our own commercial account; your prompts and connected-tool content are not used to train any AI model. We provide our current, named list of subprocessors, including what each does and the data it may process, to customers on request and as part of your data processing addendum.

Data retention & deletion

We retain workspace data, run history, and audit logs for as long as your workspace is active, so your receipts and audit trail remain complete. You can request export or deletion of your workspace data at any time by emailing us; we will action deletion requests within 30 days, subject to any legal retention obligations. Data present in encrypted database backups is purged as those backups roll off on our provider's schedule.

Security

Data is encrypted in transit (TLS) and at rest. Access to production systems is restricted and logged. A SOC 2 examination is in progress; we will update this page as that work completes.

Your rights

Depending on where you are, you may have rights to access, correct, export, or delete your personal data. To exercise any of these, email [email protected] and we’ll respond.

Changes to this policy

If we make material changes, we’ll update the date above and, where appropriate, notify workspace admins.