PLAIN ENGLISH
Hey Harold privacy policy
Hey Harold collects the details you choose to provide on the private beta waitlist so we can assess and contact potential beta participants. Invited members can separately choose to connect services such as Google; a waitlist submission never connects an account.
Waitlist information
Your email and country are required. Your mobile number and the task you would give Hey Harold are optional. We record the consent attached to your submission and use this information to operate the waitlist, select beta participants and contact you about Hey Harold's private beta. We do not sell the list.
Google user data
If you deliberately connect Google, Hey Harold requests only the permissions shown on Google's consent screen for the features you enable. This may include your basic Google account identity; Gmail messages, metadata and attachments; calendar events; contacts; Drive file metadata and files you choose to use with Hey Harold; and Google Tasks.
How Hey Harold uses Google data
Hey Harold uses authorised Google data only to provide visible, user-facing features you request. These include finding and summarising relevant messages and attachments, preparing email drafts, showing and organising calendar events and tasks, finding contacts, and locating or working with relevant Drive files. Sending, deletion, sharing and other consequential actions remain separate, explicit approval points. Hey Harold does not sell Google user data, use it for advertising or use it to train general-purpose AI models.
Who receives Google user data
Hey Harold is operated by Happy Monkey. Google user data is processed by Happy Monkey to deliver the connected features you request. It may be disclosed to the following recipients for these purposes:
- Google: to authenticate your connection and retrieve or update the Gmail, Calendar, Contacts, Drive and Tasks records you authorise.
- Recipients and collaborators you choose: for example, an email recipient when you approve sending a message, or a calendar guest or file collaborator when you approve the corresponding invitation or sharing action. Only the information needed for that action is disclosed.
- Service providers acting on our behalf: infrastructure and technical support providers may process information needed to operate and maintain Hey Harold. The current Hey Harold deployment uses Harold-managed AI processing and has hosted language-model processing disabled. The Google connection review page retrieves and displays Google records without sending their contents to an external AI service. Harold-managed processing takes place on our infrastructure and does not mean that all processing runs on your device. Any future external AI processing of Google user data will require an updated disclosure identifying the provider and purpose, and must meet Google's Limited Use requirements.
- Authorities or legal recipients: where disclosure is required by applicable law. In a merger, acquisition or sale, any transfer of Google user data requires the user's explicit prior consent.
We do not sell Google user data or disclose it to advertisers, data brokers or credit-reporting services. We do not use it for personalised advertising or to train general-purpose AI models. Human access to Google data is limited to your affirmative agreement for specific information, necessary security investigations, legal obligations, or internally aggregated and anonymised operations permitted by Google's Limited Use requirements. Payment and account-verification services do not receive your mailbox or Drive contents merely because you subscribe or sign in.
How we protect sensitive Google data
The public Hey Harold website and connections to Google's APIs use HTTPS/TLS to protect data in transit. Google sign-in is handled by Google; Hey Harold receives OAuth tokens rather than your Google password. Stored OAuth token files have operating-system permissions restricted to the service account. Tokens are held on the server and are not displayed in the connection review page.
Authentication and user, tenant and workspace access controls restrict access to connected records. Passwords for Hey Harold accounts are stored as salted password hashes. Session cookies use HttpOnly and SameSite controls, with Secure cookies for HTTPS sessions. Consequential actions, including sending messages and changing message labels, pass through permission and approval checks. The limited connection review account cannot access other users' workspaces or the private administration and conversation APIs.
These are specific controls, not a claim of end-to-end encryption or a completed independent security certification. We restrict stored data through access controls; we do not claim that all stored Google data is encrypted at rest.
Storage and retention
OAuth tokens and retained Google data are stored in the connected member's scoped Hey Harold workspace, separately from the public waitlist. We retain information needed to operate the connected features and any records you choose to keep, subject to account and connector retention controls. Disconnecting removes the stored connection tokens and stops future access through that connection; it does not automatically erase messages, summaries or files already saved in your workspace, or records held by Google or your chosen recipients. You can request deletion of retained Hey Harold information using the contact below. Any information that must be retained to meet a legal obligation is restricted to that purpose.
Your controls
You can disconnect Google in Hey Harold to stop future access, revoke Hey Harold in your Google Account permissions, and request correction or removal of retained account information. You can also ask us to correct or remove your waitlist details, or withdraw contact consent, by replying to any beta message you receive.
Google Limited Use
Hey Harold's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Contact and deletion requests
For privacy questions, correction or deletion requests, contact Happy Monkey at jgbrown23@gmail.com. Include the email address of your Hey Harold account and the information you want corrected or removed. We may verify account ownership before acting. Do not email passwords or OAuth tokens.
Separate storage
Waitlist records are stored separately from Hey Harold user workspaces. Becoming a beta user does not silently move your waitlist answers into Hey Harold's personal memory.
Last updated 10 September 2026.