HeyARIA. PRIVACY POLICY

Privacy Policy

Last updated: September 15, 2026

HeyARIA ("we," "us," or "our") provides an AI executive assistant for entertainment industry professionals. Your assistant handles scheduling and calendar coordination, phone sheets and call tracking, to-dos, weekend read management, contact and relationship tracking, project tracking, and expense tracking, communicating with you via email and direct message. This Privacy Policy explains what data we collect, how we use it, who we share it with, and your rights regarding your data.

If you have questions or want to exercise any rights described here, contact us at privacy@heyaria.cc.


1. Who we are

HeyARIA is operated by HeyAria LLC, a California limited liability company. Our products are designed for executive professional users who connect their work calendar and related services (such as Google Drive, Slack, and Zoom) and route correspondence through a dedicated assistant email address. We never connect to or access your own email inbox.


2. What we collect

Information you provide directly

When you onboard as an executive user, you provide:

Information from connected services (with your authorization)

When you connect Google Calendar, we request the following OAuth scope:

We also receive an OAuth refresh token (encrypted at rest) so the assistant can continue accessing your calendar between active sessions, since assistant activity happens around the clock.

When you connect Google Drive, we request the following OAuth scope:

This scope only permits access to files and folders that HeyARIA itself creates. We cannot see, read, or list any other files in your Google Drive.

When you connect Microsoft 365 (via Microsoft Graph), we request the following delegated scopes:

We store the resulting access and refresh tokens encrypted at rest.

When your organization provisions an assistant mailbox on your corporate domain (enterprise plans), your IT administrator grants our separate "HeyARIA Mailbox" application the following Microsoft Graph application permissions, restricted by your administrator to designated assistant mailboxes only:

These permissions apply only to the assistant mailbox your organization designates. HeyARIA cannot access any other mailbox in your organization. Your IT administrator controls this scoping and may revoke it at any time.

When you connect Zoom, we request the following OAuth scopes:

We also receive an OAuth refresh token (encrypted at rest) so the assistant can continue creating meeting links between active sessions, since assistant activity happens around the clock.

Zoom's free tier limits meetings to 40 minutes. A licensed Zoom account is recommended if you host longer meetings, but is not required to connect.

If you remove HeyARIA from your Zoom account, Zoom notifies us and we delete your stored Zoom tokens. Meetings already created remain in your Zoom account and are unaffected.

When you connect Slack, we receive your Slack user ID, used to direct messages from your AI assistant.

When you connect iMessage (where available), you provide the phone number where your assistant should message you. Messages between you and your assistant are relayed via our messaging sub-processor and retained under the retention terms described in Section 7.

Information from email correspondence

When email is sent to your assistant's address (e.g., aria@heyaria.cc, or your organization's designated assistant mailbox on enterprise plans):

Information generated through use

Information automatically collected

Information for paid plans (when applicable)


3. What we do not access or collect

HeyARIA only sees what is explicitly forwarded to, CC'd on, or sent to your assistant's address. We do not have access to your broader inbox, contacts, files, or any other service.

We do not access:

We do not collect (unless explicitly disclosed by you in correspondence with your assistant):

If sensitive information of any of the above categories appears incidentally in an email sent to your assistant, it is processed and retained under the same retention policy as other email content (see Section 7). We do not specifically extract, analyze, or share such information.


4. Third-party correspondents

HeyARIA processes information about third parties whose emails are sent to or CC'd on your assistant's address — for example, people you are scheduling with, their assistants, agency contacts, and other professional collaborators. This may include:

You represent that you have the necessary rights, consents, or lawful basis under applicable law to share this information with us. We rely on you to maintain appropriate authorization for any third-party data passing through HeyARIA. (See our Terms of Service for related warranties.)

Third-party correspondents may exercise rights regarding their personal data under applicable law (including CCPA, GDPR, and similar) by contacting privacy@heyaria.cc. We will respond within 30 days and may require verification of identity before processing requests.

Such third-party data is retained under the same retention policy as other email content (see Section 7).


5. How we use it

Core service operation. All collected data is used to provide the assistant service: reading inbound emails, reasoning about availability and priorities, sending outbound emails as your assistant, creating calendar events, maintaining your phone sheet, to-dos, contacts, projects, weekend reads, and expense records, compiling expense reports at your direction, sending you decision prompts via your connected messaging channel, and producing daily/weekly digests.

AI-generated content. HeyARIA generates email and direct messages based on the context you provide. While we work to ensure accuracy, AI output may contain errors, including misinterpretation of context or unintended recipients. You remain responsible for reviewing decisions HeyARIA proposes and for the actions you authorize.

Service improvement. We may analyze aggregate, non-identifying patterns of use (e.g., "70% of meetings are scheduled within 48 hours of first inbound") to improve the product.

We do NOT:

Google API Limited Use. HeyARIA's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: data received via the calendar.events scope is used solely to read your availability, create calendar events on your behalf, and update or cancel those events at your direction. Data received via the drive.file scope is used solely to create HeyARIA's dedicated folders in your Drive and save weekend read attachments, expense receipt files, and expense report PDFs to them at your direction. Google user data is not used for advertising, shared with third parties for independent purposes, or processed for any use unrelated to providing the Service.

Microsoft Graph data use. Data received via Microsoft Graph — User.Read, Calendars.ReadWrite, OnlineMeetings.ReadWrite, and, on enterprise plans, Mail.Send and Mail.ReadWrite restricted to your organization's designated assistant mailbox — is used solely to identify your account, read your calendar availability, create and update calendar events at your direction, generate Microsoft Teams meeting links you authorize, and send and receive assistant email through the mailbox your organization designates. It is not used for advertising, shared with third parties for independent purposes, or processed for any use unrelated to providing the Service.

Zoom data use. Zoom authorization is used solely to create meeting links for meetings you authorize. We do not access Zoom recordings, transcripts, meeting content, participant lists, or your Zoom meeting history. Zoom data is not used for advertising, shared with third parties for independent purposes, or processed for any use unrelated to providing the Service.


6. Who we share it with

We use third-party service providers ("sub-processors") to deliver the product. Each sub-processor receives only the data necessary for its function:

Sub-processorPurpose
AnthropicAI model inference for your assistant's reasoning
SupabaseDatabase storage
VercelApplication hosting and compute
PostmarkOutbound email delivery
ResendInbound email receiving
GoogleCalendar API and Drive API (when you connect Google services)
MicrosoftMicrosoft Graph — Microsoft 365 calendar API (when you connect Microsoft 365), Teams meeting link generation, and assistant mailbox email on your corporate domain (enterprise plans)
SlackMessaging (when connected)
PhotoniMessage relay between you and your assistant (when connected, where available)
ZoomVideo meeting link generation (when you connect Zoom)

A complete vendor data flow document with security certifications, retention details, and DPA links is available on request to legal@heyaria.cc.

We do not share your data with any third party other than the above sub-processors, except as required by law (e.g., subpoena or court order) or with your explicit consent.


7. How long we keep it

Data categoryRetention
OAuth tokens (calendar, Drive, mail, Zoom)Until you disconnect the integration, remove the app from the provider's side, or delete your account
Email and direct-message content120 days (configurable per contract)
Saved Weekend Read itemsRaw source email purged per your message-content retention window (120 days by default); the saved item, summary, and Drive links are retained until you delete them. Attachments saved to your Google Drive remain in your Drive under your control.
Phone sheet, to-do, contact, and project recordsUntil account deletion (individual items until you delete them)
Expense records and expense reportsUntil account deletion (individual items until you delete or void them). Receipt files and report PDFs saved to your Google Drive remain in your Drive under your control. Raw source emails containing receipts purge per your message-content retention window (120 days by default)
Outstanding follow-upsUntil you mark them done
Exec profile data (relationships, projects, schedule rules)Until account deletion
Calendar event referencesUntil account deletion
System logs30 days
Postmark delivery records~45 days (per Postmark's policy)
Resend inbound records~30 days (per Resend's policy)
Photon iMessage relay recordsPer Photon's retention policy while our account is active (when iMessage is connected)
Anthropic API logsMax 7 days for abuse detection (per Anthropic's policy)

Our message-content retention is enforced by an automated daily purge job. After expiration, the content is permanently deleted from our database. Retention applies to raw correspondence; records your assistant derives from it (such as contacts, notes, phone sheet entries, and read summaries) persist as described above so your working history remains intact.


8. Your rights

Depending on your jurisdiction, you may have the following rights regarding your data:

Access. You may request a copy of all data we hold about you.

Correction. You may request correction of inaccurate data.

Deletion. You may request full deletion of your account and all associated data. We will process deletion requests within 30 days. After deletion, we retain only the minimum information required by law (e.g., billing records if applicable). Email service provider logs (Postmark, Resend) will purge within 45 days per their respective retention policies. Files saved to your own Google Drive remain yours and are unaffected by our deletion.

Disconnection. You may revoke calendar, Drive, email, messaging, or video integration permissions at any time through the respective service provider's settings, through your HeyARIA settings, or by contacting us.

Portability. You may request your data in a machine-readable format.

Objection / restriction. You may object to specific processing activities or request restriction of processing.

Complaint. EU users have the right to lodge a complaint with their local data protection authority.

To exercise any right, email privacy@heyaria.cc. We will respond within 30 days.

Additional rights for California residents

If you are a California resident, you have the following specific rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):

To exercise these rights, email privacy@heyaria.cc. We will verify your identity before fulfilling the request.


9. Security

We implement layered security to protect your data:

At rest:

In transit:

Access control:

Operational:

Breach notification: In the event of a personal data breach affecting your data, we will notify you within 72 hours of becoming aware of the breach. Notification will include the nature of the breach, the categories of data affected, the likely consequences, and the steps we are taking to remediate. Where required by law, we will also notify the relevant regulatory authorities and affected third parties.


10. International data transfers

HeyARIA operates from the United States. By using the service, you consent to your data being processed in the United States. For users in the European Economic Area or UK, our sub-processors offer GDPR-compliant data transfer mechanisms (Standard Contractual Clauses or equivalent).


11. Children's privacy

HeyARIA is intended for adult professional users in the entertainment industry. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided data, contact privacy@heyaria.cc and we will delete it.


12. Changes to this policy

We may update this Privacy Policy. Material changes will be communicated via email to active users at least 30 days before taking effect. Non-material changes (typos, clarifications, sub-processor updates) may be made without notice.

The "Last updated" date at the top reflects the most recent change.


13. Contact

Questions, requests, complaints, security disclosures:


Effective date: September 15, 2026.