Privacy Policy
hello hero is a macOS app released as a public research preview. Features and functionality may change before its full release. This policy explains how personal data is handled when you use the hello hero website, macOS app, accounts, team workspaces, sync, transcription, AI features, and related services.
1. What this policy covers
This policy covers personal data we control through hello hero. It does not govern a third-party service you choose to connect, such as Google, Microsoft, an AI model provider, a transcription provider, or a payment provider. Those services also apply their own terms and privacy notices.
2. Information we handle
Account and profile information
When you sign in with Google or Microsoft, we receive an account identifier, name, verified email address, profile image, and authentication information needed to keep you signed in. We also process workspace membership, role, invitation, and device-key metadata needed for access and encrypted sync.
Your content
Your content may include recordings, audio, transcripts, meeting summaries, notes, files, folders, prompts, chat messages, AI outputs, and edits. Local content stays on your Mac unless you choose a feature that syncs, shares, or processes it online. For team workspaces and sync, the service stores encrypted content payloads together with the metadata required to organize, authorize, and synchronize them.
Live transcription and AI requests
When you use hosted transcription, relevant microphone or system audio is sent to our transcription service. When you ask hero a question, create a summary, or use another AI feature, the request may include your prompt and relevant transcript, note, file, workspace, or chat context. The app sends only the context needed to perform the action you requested, but that context must be readable by the processing provider during the request.
Connected calendars
If you connect Google Calendar or Microsoft Outlook, we store the authorization tokens needed to maintain the connection and retrieve event details shown in hello hero. These details can include event titles, times, organizers, attendees, locations, meeting links, status, and a description preview. You can disconnect a calendar to stop future access.
Billing and usage
We process plan, credit balance, usage, purchase, subscription, customer, and transaction metadata. Polar handles checkout and payment details. We receive the identifiers and status needed to credit your account, manage a subscription, prevent fraud, and keep financial records; we do not receive or store complete card details.
Technical and support information
Our infrastructure providers may process IP address, request time, service route, browser or app version, error information, and security logs needed to deliver and protect the service. If you contact us, we process the message and contact details you provide.
Website data
The public website does not currently use advertising trackers, product analytics, persistent analytics cookies, or session recording. Cloudflare processes technical request information needed to deliver and protect the website. If we add optional analytics later, we will update this policy and, where required, request consent before enabling it.
3. How we use information
We use personal data to:
- provide the macOS app, authentication, encrypted sync, collaboration, transcription, AI features, billing, and support;
- show calendar context and maintain integrations you enable;
- protect accounts, workspaces, infrastructure, and users from abuse or unauthorized access;
- diagnose faults, maintain reliability, and improve features based on direct feedback and aggregate service operation;
- enforce our Terms and comply with legal, tax, accounting, and regulatory obligations.
4. Legal bases for processing
Where the GDPR or similar law applies, we rely on:
- Contract: to provide the service and features you request.
- Legitimate interests: to secure, operate, troubleshoot, and improve the service, provided those interests are not overridden by your rights.
- Consent: where you make an optional connection or where law requires consent. You can withdraw consent without affecting earlier lawful processing.
- Legal obligations: for tax, accounting, legal requests, and other duties that apply to us.
5. Local storage, sync, and encryption
hello hero encrypts supported local text and files at rest using AES-256-GCM. The local device key is protected using macOS secure storage, and the app can create a recovery kit. Keep the recovery kit secure: anyone who has it together with your encrypted data may be able to recover that data.
For supported synced and shared workspace content, hello hero generates client-side content and workspace keys and uploads encrypted payloads. Our service still needs readable account, membership, authorization, billing, credit, usage, and operational metadata to run the service.
Encryption at rest does not protect content while it is displayed on an unlocked Mac, included in a decrypted export, shared with another workspace member, or sent for hosted transcription or AI processing. Hosted processing is a separate operation from encrypted storage.
6. Service providers and disclosures
We disclose data only as needed to operate the service, follow your instructions, protect users, complete a business transaction, or comply with law. Our main provider categories are:
- Cloudflare: website delivery, hosted processing endpoints, and collaboration transport.
- Convex: authentication, account and workspace services, encrypted sync storage, calendar connections, and billing or usage metadata.
- OpenRouter and the selected model provider: AI chat, summaries, and related model requests.
- Soniox: live and file-based hosted transcription.
- Polar: checkout, subscriptions, payments, and purchase records.
- Google and Microsoft: sign-in and, only when connected, calendar access.
We do not sell or rent personal data, and we do not disclose it for cross-context behavioral advertising.
7. International transfers
Some providers process data outside Slovakia or the European Economic Area. Where required, we use an adequacy decision, approved contractual safeguards, or another lawful transfer mechanism. Provider locations and subprocessors can change as their services evolve.
8. Retention and deletion
- Local data: remains on your Mac until you delete it, remove the app data, or replace the device. A decrypted export is controlled by you and is no longer protected by hello hero encryption.
- Account and workspace data: is kept while your account or workspace is active and for a limited period afterwards where needed for recovery, security, disputes, or legal obligations.
- Synced content: remains until it is deleted by an authorized user or the relevant account or workspace is deleted. Deletion can take additional time to age out of provider backups.
- Hosted transcription: our hosted flow requests deletion of provider-side transcription and uploaded file artifacts after processing. Provider security logs and backups may follow the provider's own retention schedule.
- Billing records: are retained as required by tax, accounting, fraud-prevention, and payment rules.
9. Your choices and rights
Depending on where you live, you may have rights to be informed, access your personal data, correct it, delete it, restrict or object to processing, receive portable data, withdraw consent, and complain to a data protection authority. These rights are subject to legal limits and the rights of other people.
You can also delete local content in the app, export local data, disconnect a calendar, leave a team workspace where permitted, and manage access to content you share. To exercise a privacy right concerning data controlled by us, email privacy@hellohero.ai. We may need to verify your identity.
10. Recording other people
Recordings and transcripts can contain personal data about other participants. The person or organization using hello hero is responsible for providing any notice and obtaining any consent required by applicable law or workplace policy before recording, transcribing, sharing, or processing a conversation.
11. Security
We use technical and organizational measures designed to protect personal data, including encryption, access controls, scoped workspace permissions, and provider security controls. No system is completely secure. Read our Security page for the product's security boundaries and recovery considerations.
12. Children
hello hero is not directed to children, and we do not knowingly collect personal data from a child who cannot lawfully consent to the service. If you believe a child has provided personal data improperly, contact us so we can investigate and delete it where required.
13. Changes to this policy
We may update this policy as the product, providers, or law changes. We will post the revised version here, change the date above, and provide additional notice when a change materially affects your rights or how we use personal data.
14. Contact
Email privacy@hellohero.ai with privacy questions or requests. You may also complain to the Slovak data protection authority or the competent authority where you live or work.