Privacy Policy
Last updated: May 27, 2026
HeyARIA ("we," "us," or "our") provides an email-native AI scheduling assistant for entertainment industry executives. This Privacy Policy explains what data we collect, how we use it, who we share it with, and your rights regarding your data.
If you have questions or want to exercise any rights described here, contact us at privacy@heyaria.cc.
1. Who we are
HeyARIA is operated by HeyAria LLC, a California limited liability company. Our products are designed for executive professional users who connect their work calendar and email so we can help schedule meetings on their behalf.
2. What we collect
Information you provide directly
When you onboard as an executive user, you provide:
- Name, work email address, phone number (optional), professional title and company
- Time zone and scheduling preferences
- A list of relationships (people in your professional network) and active projects, used to inform your assistant's scheduling decisions
- The name you'd like for your AI assistant (e.g., a custom name or a randomly assigned unique gender-neutral name; subject to availability)
Information from connected services (with your authorization)
When you connect Google Calendar, we request the following OAuth scope:
https://www.googleapis.com/auth/calendar.events— read your calendar availability, and create, modify, or cancel calendar events at your direction.
We also receive an OAuth refresh token (encrypted at rest) so the assistant can continue accessing your calendar between active sessions, since scheduling activity happens around the clock.
When you connect Microsoft 365 (via Microsoft Graph), we request the following scopes:
User.Read— read your basic profile (name, email) to identify your account.Calendars.ReadWrite— read your calendar availability, and create, modify, or cancel calendar events at your direction.OnlineMeetings.ReadWrite— generate Microsoft Teams meeting links on your behalf when you authorize a meeting that requires one.offline_access— required so the assistant can continue accessing your calendar between active sessions, since scheduling activity happens around the clock.
We store the resulting access and refresh tokens encrypted at rest.
Permission to generate video meeting links (Google Meet via Google Calendar, Microsoft Teams via Microsoft Graph, or Zoom via the Zoom integration when configured).
When you connect Slack:
- Your Slack user ID, used to direct messages from your AI assistant
Information from email correspondence
When email is sent to your assistant's address (e.g., aria@heyaria.cc):
- Email body text
- Sender, recipient, subject, headers
- Any attachments mentioned (we currently store only filenames, not file contents)
Information generated through use
- Scheduling threads and the messages within them
- Outbound emails sent by your assistant
- Slack conversations between you and your AI assistant
- Daily or weekly digest summaries
- Items you flag for follow-up or for Weekend Read
- Calendar event references created by your assistant
Information automatically collected
- System logs (function invocations, error traces) for operational purposes
- Email delivery status (sent, bounced, opened) from our email service providers
Information for paid plans (when applicable)
- Billing email address
- Payment information processed by our payment processor. We do not store full credit card numbers; only a tokenized reference and the last four digits, which our payment processor provides for receipt purposes.
3. What we do not access or collect
HeyARIA only sees what is explicitly forwarded to or CC'd on your AI assistant's address. We do not have access to your broader inbox, contacts, files, or any other service.
We do not access:
- Your email inbox beyond the dedicated assistant address (emails sent directly to you that aren't forwarded to or CC'd to your assistant are invisible to us)
- Your contacts list or address book
- Your files in Google Drive, OneDrive, or similar
- Any service beyond the calendar APIs you explicitly connect
We do not collect (unless explicitly disclosed by you in correspondence with your scheduling assistant):
- Financial or payment information beyond what's required to process subscription payments (when applicable — see Section 5 for our payment processor)
- Health information
- Government-issued IDs
- Data from anyone known to be under 18
If sensitive information of any of the above categories appears incidentally in an email forwarded to your scheduling assistant, it is processed and retained under the same retention policy as other email content (see Section 6). We do not specifically extract, analyze, or share such information.
4. Third-party correspondents
HeyARIA processes information about third parties whose emails are sent to or CC'd on your assistant's dedicated address — for example, people you are scheduling with, their assistants, agency contacts, and other professional collaborators. This may include:
- Names and email addresses
- Professional roles and affiliations mentioned in correspondence
- Scheduling preferences and availability shared in messages
- The content of email messages they send to or are CC'd on
You represent that you have the necessary rights, consents, or lawful basis under applicable law to share this information with us. We rely on you to maintain appropriate authorization for any third-party data passing through HeyARIA. (See our Terms of Service for related warranties.)
Third-party correspondents may exercise rights regarding their personal data under applicable law (including CCPA, GDPR, and similar) by contacting privacy@heyaria.cc. We will respond within 30 days and may require verification of identity before processing requests.
Such third-party data is retained under the same retention policy as other email content (see Section 6).
5. How we use it
Core service operation. All collected data is used to provide the scheduling assistant service: reading inbound emails, reasoning about availability, sending outbound emails as your assistant, creating calendar events, sending you decision prompts via Slack, and producing daily/weekly digests.
AI-generated content. HeyARIA generates email and Slack messages on your behalf based on the context you provide. While we work to ensure accuracy, AI output may contain errors, including misinterpretation of context or unintended recipients. You remain responsible for reviewing decisions HeyARIA makes on your behalf and for the actions you authorize through Slack approvals or other means.
Service improvement. We may analyze aggregate, non-identifying patterns of use (e.g., "70% of meetings are scheduled within 48 hours of first inbound") to improve the product.
We do NOT:
- Sell your data to anyone
- Share your data for advertising or cross-context behavioral marketing
- Use your data to train AI models (our LLM provider, Anthropic, also does not use API data for training per their Commercial Terms)
- Read your messages for any purpose other than providing scheduling assistance, support, and security incident response
Google API Limited Use. HeyARIA's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: data received via the calendar.events scope is used solely to read your availability, create calendar events on your behalf, and update or cancel those events at your direction. It is not used for advertising, shared with third parties for independent purposes, or processed for any use unrelated to scheduling.
Microsoft Graph data use. Data received via Microsoft Graph (User.Read, Calendars.ReadWrite, OnlineMeetings.ReadWrite) is used solely to identify your account, read your calendar availability, create and update calendar events at your direction, and generate Microsoft Teams meeting links you authorize. It is not used for advertising, shared with third parties for independent purposes, or processed for any use unrelated to scheduling.
6. Who we share it with
We use third-party service providers ("sub-processors") to deliver the product. Each sub-processor receives only the data necessary for its function:
| Sub-processor | Purpose |
|---|---|
| Anthropic | AI model inference for your assistant's reasoning |
| Supabase | Database storage |
| Vercel | Application hosting and compute |
| Postmark | Outbound email delivery |
| Resend | Inbound email receiving |
| Calendar API (when you connect Google) | |
| Microsoft | Microsoft Graph — Microsoft 365 calendar API (when you connect Microsoft 365), including Teams meeting link generation |
| Slack | Messaging (when connected) |
| Zoom | Video meeting links (when generated by Zoom) |
A complete vendor data flow document with security certifications, retention details, and DPA links is available on request to legal@heyaria.cc.
We do not share your data with any third party other than the above sub-processors, except as required by law (e.g., subpoena or court order) or with your explicit consent.
7. How long we keep it
| Data category | Retention |
|---|---|
| OAuth tokens | Until you disconnect or delete your account |
| Email/Slack message content | 120 days (configurable per contract) |
| Saved Weekend Read items | 30 days after delivery |
| Outstanding follow-ups | Until you mark them done |
| Exec profile data (relationships, projects, schedule rules) | Until account deletion |
| Calendar event references | Until account deletion |
| System logs | 30 days |
| Postmark delivery records | ~45 days (per Postmark's policy) |
| Resend inbound records | ~30 days (per Resend's policy) |
| Anthropic API logs | Max 7 days for abuse detection (per Anthropic's policy) |
Our message-content retention is enforced by an automated daily purge job. After expiration, the content is permanently deleted from our database.
8. Your rights
You have the following rights regarding your data:
Access. You may request a copy of all data we hold about you.
Correction. You may request correction of inaccurate data.
Deletion. You may request full deletion of your account and all associated data. We will process deletion requests within 30 days. After deletion, we retain only the minimum information required by law (e.g., billing records if applicable). Email service provider logs (Postmark, Resend) will purge within 45 days per their respective retention policies.
Disconnection. You may revoke calendar/Slack/email permissions at any time through the respective service provider's settings or by contacting us.
Portability. You may request your data in a machine-readable format.
Objection / restriction. You may object to specific processing activities or request restriction of processing.
Complaint. EU users have the right to lodge a complaint with their local data protection authority.
To exercise any right, email privacy@heyaria.cc. We will respond within 30 days.
Additional rights for California residents
If you are a California resident, you have the following specific rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):
- Right to know what personal information we collect, the purposes for collection, and the categories of sources and third parties involved.
- Right to delete your personal information (subject to certain exceptions, such as legal compliance).
- Right to correct inaccurate personal information.
- Right to opt out of sale or sharing of personal information. We do not sell your personal information, and we do not share your personal information for cross-context behavioral advertising.
- Right to limit use of sensitive personal information. Where we process information that may qualify as sensitive (such as the contents of communications), we use it only to provide the service you have requested, and not for inferring characteristics about you.
- Right to non-discrimination. We will not deny service, charge different prices, or provide a different quality of service because you exercised your privacy rights.
To exercise these rights, email privacy@heyaria.cc. We will verify your identity before fulfilling the request.
9. Security
We implement layered security to protect your data:
At rest:
- All data encrypted at the database disk layer (AES-256 via Supabase)
- OAuth tokens additionally encrypted at the application layer (AES-256-GCM) — even with database access, calendar credentials cannot be extracted without our encryption key
- Encryption keys held in Vercel environment variables, never in the database
In transit:
- All API calls and webhooks use TLS 1.2 or higher
- All sub-processors enforce HTTPS
Access control:
- Backend-only access to the database; no public-facing read/write endpoints
- Production credentials accessible only to authorized personnel
- Service-role keys and API credentials rotated at least annually and on suspected compromise
- Multi-factor authentication required on all administrative accounts to our sub-processor consoles (Vercel, Supabase, GitHub, Anthropic, Postmark, Resend, Slack, Google Cloud, Microsoft Azure)
- Authorized personnel (currently the founder of HeyAria LLC) have administrative access to the underlying database for support, security incident response, and abuse investigation. All such access is logged. As the team grows, we will implement role-based access controls and customer-viewable audit logs.
Operational:
- Service operates on SOC 2-certified infrastructure (Vercel, Supabase, Anthropic, Postmark, Resend, Google, Microsoft, Slack, Zoom)
- Daily database backups via Supabase
- Automated dependency vulnerability scanning on the application codebase
- Automated secrets scanning on all code commits to prevent accidental credential exposure
- Daily automated retention enforcement
- Versioned encryption format permits future key rotation without data loss
Breach notification: In the event of a personal data breach affecting your data, we will notify you within 72 hours of becoming aware of the breach. Notification will include the nature of the breach, the categories of data affected, the likely consequences, and the steps we are taking to remediate. Where required by law, we will also notify the relevant regulatory authorities and affected third parties.
10. International data transfers
HeyARIA operates from the United States. By using the service, you consent to your data being processed in the United States. For users in the European Economic Area or UK, our sub-processors offer GDPR-compliant data transfer mechanisms (Standard Contractual Clauses or equivalent).
11. Children's privacy
HeyARIA is intended for adult professional users in the entertainment industry. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided data, contact privacy@heyaria.cc and we will delete it.
12. Changes to this policy
We may update this Privacy Policy. Material changes will be communicated via email to active users at least 30 days before taking effect. Non-material changes (typos, clarifications, sub-processor updates) may be made without notice.
The "Last updated" date at the top reflects the most recent change.
13. Contact
Questions, requests, complaints, security disclosures:
- Privacy questions: privacy@heyaria.cc
- Security issues: security@heyaria.cc
- Legal: legal@heyaria.cc
- General inquiries: hello@heyaria.cc
Effective date: May 27, 2026.