Privacy Policy
Last updated: September 15, 2026
HeyARIA ("we," "us," or "our") provides an AI executive assistant for entertainment industry professionals. Your assistant handles scheduling and calendar coordination, phone sheets and call tracking, to-dos, weekend read management, contact and relationship tracking, project tracking, and expense tracking, communicating with you via email and direct message. This Privacy Policy explains what data we collect, how we use it, who we share it with, and your rights regarding your data.
If you have questions or want to exercise any rights described here, contact us at privacy@heyaria.cc.
1. Who we are
HeyARIA is operated by HeyAria LLC, a California limited liability company. Our products are designed for executive professional users who connect their work calendar and related services (such as Google Drive, Slack, and Zoom) and route correspondence through a dedicated assistant email address. We never connect to or access your own email inbox.
2. What we collect
Information you provide directly
When you onboard as an executive user, you provide:
- Name, work email address, phone number (optional), professional title and company
- Time zone, workday, and scheduling preferences
- Optionally, a list of relationships (people in your professional network) and active projects, used to inform your assistant's decisions
- The name you'd like for your AI assistant (e.g., a custom name or a randomly assigned unique gender-neutral name; subject to availability)
Information from connected services (with your authorization)
When you connect Google Calendar, we request the following OAuth scope:
https://www.googleapis.com/auth/calendar.events— read your calendar availability, and create, modify, or cancel calendar events at your direction.
We also receive an OAuth refresh token (encrypted at rest) so the assistant can continue accessing your calendar between active sessions, since assistant activity happens around the clock.
When you connect Google Drive, we request the following OAuth scope:
https://www.googleapis.com/auth/drive.file— create dedicated HeyARIA folders in your Google Drive (a "HeyARIA Reads" folder, and a "HeyARIA Expenses" folder with subfolders for reports and receipts) and save weekend read attachments, expense receipt files, and expense report PDFs to them on your behalf.
This scope only permits access to files and folders that HeyARIA itself creates. We cannot see, read, or list any other files in your Google Drive.
When you connect Microsoft 365 (via Microsoft Graph), we request the following delegated scopes:
User.Read— read your basic profile (name, email) to identify your account.Calendars.ReadWrite— read your calendar availability, and create, modify, or cancel calendar events at your direction.OnlineMeetings.ReadWrite— generate Microsoft Teams meeting links on your behalf when you authorize a meeting that requires one.offline_access— required so the assistant can continue accessing your calendar between active sessions.
We store the resulting access and refresh tokens encrypted at rest.
When your organization provisions an assistant mailbox on your corporate domain (enterprise plans), your IT administrator grants our separate "HeyARIA Mailbox" application the following Microsoft Graph application permissions, restricted by your administrator to designated assistant mailboxes only:
Mail.Send— send email from your organization's designated assistant mailbox on your behalf.Mail.ReadWrite— read mail arriving at the designated assistant mailbox and manage drafts, so replies can be threaded correctly.
These permissions apply only to the assistant mailbox your organization designates. HeyARIA cannot access any other mailbox in your organization. Your IT administrator controls this scoping and may revoke it at any time.
When you connect Zoom, we request the following OAuth scopes:
meeting:write:meeting— create Zoom meetings on your behalf for meetings you authorize, and retrieve the join link for those meetings.user:read:user— read your basic Zoom profile (name, email, user ID) to identify the Zoom account you connected.
We also receive an OAuth refresh token (encrypted at rest) so the assistant can continue creating meeting links between active sessions, since assistant activity happens around the clock.
Zoom's free tier limits meetings to 40 minutes. A licensed Zoom account is recommended if you host longer meetings, but is not required to connect.
If you remove HeyARIA from your Zoom account, Zoom notifies us and we delete your stored Zoom tokens. Meetings already created remain in your Zoom account and are unaffected.
When you connect Slack, we receive your Slack user ID, used to direct messages from your AI assistant.
When you connect iMessage (where available), you provide the phone number where your assistant should message you. Messages between you and your assistant are relayed via our messaging sub-processor and retained under the retention terms described in Section 7.
Information from email correspondence
When email is sent to your assistant's address (e.g., aria@heyaria.cc, or your organization's designated assistant mailbox on enterprise plans):
- Email body text
- Sender, recipient, subject, headers
- Attachments, when you direct your assistant to save them (e.g., as weekend reads). Saved attachments are stored in the HeyARIA Reads folder of your connected Google Drive; we retain a link and file metadata. Attachments you do not ask your assistant to act on are not stored beyond their filenames.
Information generated through use
- Scheduling threads and the messages within them
- Outbound emails sent by your assistant
- Direct-message conversations between you and your AI assistant (e.g., via Slack or iMessage)
- Phone sheet entries and call records (caller, company, call status, and notes you or your assistant log)
- To-do items you create or your assistant captures
- Contacts, relationship information, and tracking lists your assistant maintains from your correspondence and instructions, including talent and company tracking records
- Project (slate) records and status your assistant tracks on your behalf, including people attached to a project, submissions and their status, notes, drafts, and linked reads and material
- Expense records you log with your assistant — amount, vendor, date, and notes for a described charge, and receipt images or files you provide by direct message or email — and the expense reports compiled from them. Receipt files and expense report PDFs are saved to the HeyARIA Expenses folder of your connected Google Drive; we retain the expense record and a link to those files
- Weekend read items, including attachment links to your connected Google Drive
- Daily or weekly digest summaries
- Calendar event references created by your assistant
Information automatically collected
- System logs (function invocations, error traces) for operational purposes
- Email delivery status (sent, bounced, opened) from our email service providers
- When you sign in to the HeyARIA dashboard (app.heyaria.cc), an essential session cookie used to keep you signed in. We do not use analytics, advertising, or cross-site tracking cookies.
Information for paid plans (when applicable)
- Billing email address
- Payment information processed by our payment processor. We do not store full credit card numbers; only a tokenized reference and the last four digits, which our payment processor provides for receipt purposes.
3. What we do not access or collect
HeyARIA only sees what is explicitly forwarded to, CC'd on, or sent to your assistant's address. We do not have access to your broader inbox, contacts, files, or any other service.
We do not access:
- Your personal email inbox. Emails sent directly to you that aren't forwarded or CC'd to your assistant are invisible to us. On enterprise plans, we access only the designated assistant mailbox your organization provisions — never your own mailbox or anyone else's.
- Your contacts list or address book on any connected service
- Your files in Google Drive, OneDrive, or similar — with one narrow exception: files that HeyARIA itself creates in its dedicated folders in your Google Drive (HeyARIA Reads and HeyARIA Expenses) via the
drive.filescope, which cannot see any other file in your Drive - Any service beyond the integrations you explicitly connect
We do not collect (unless explicitly disclosed by you in correspondence with your assistant):
- Financial or payment information, beyond (a) what's required to process subscription payments (when applicable — see Section 6 for our payment processor) and (b) the business expense details and receipts you deliberately log using the expense feature
- Health information
- Government-issued IDs
- Data from anyone known to be under 18
If sensitive information of any of the above categories appears incidentally in an email sent to your assistant, it is processed and retained under the same retention policy as other email content (see Section 7). We do not specifically extract, analyze, or share such information.
4. Third-party correspondents
HeyARIA processes information about third parties whose emails are sent to or CC'd on your assistant's address — for example, people you are scheduling with, their assistants, agency contacts, and other professional collaborators. This may include:
- Names and email addresses
- Professional roles and affiliations mentioned in correspondence
- Scheduling preferences and availability shared in messages
- The content of email messages they send to or are CC'd on
- Call records logged to your phone sheet
You represent that you have the necessary rights, consents, or lawful basis under applicable law to share this information with us. We rely on you to maintain appropriate authorization for any third-party data passing through HeyARIA. (See our Terms of Service for related warranties.)
Third-party correspondents may exercise rights regarding their personal data under applicable law (including CCPA, GDPR, and similar) by contacting privacy@heyaria.cc. We will respond within 30 days and may require verification of identity before processing requests.
Such third-party data is retained under the same retention policy as other email content (see Section 7).
5. How we use it
Core service operation. All collected data is used to provide the assistant service: reading inbound emails, reasoning about availability and priorities, sending outbound emails as your assistant, creating calendar events, maintaining your phone sheet, to-dos, contacts, projects, weekend reads, and expense records, compiling expense reports at your direction, sending you decision prompts via your connected messaging channel, and producing daily/weekly digests.
AI-generated content. HeyARIA generates email and direct messages based on the context you provide. While we work to ensure accuracy, AI output may contain errors, including misinterpretation of context or unintended recipients. You remain responsible for reviewing decisions HeyARIA proposes and for the actions you authorize.
Service improvement. We may analyze aggregate, non-identifying patterns of use (e.g., "70% of meetings are scheduled within 48 hours of first inbound") to improve the product.
We do NOT:
- Sell your data to anyone
- Share your data for advertising or cross-context behavioral marketing
- Use your data to train AI models (our LLM provider, Anthropic, also does not use API data for training per their Commercial Terms)
- Read your messages for any purpose other than providing the assistant service, support, and security incident response
Google API Limited Use. HeyARIA's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: data received via the calendar.events scope is used solely to read your availability, create calendar events on your behalf, and update or cancel those events at your direction. Data received via the drive.file scope is used solely to create HeyARIA's dedicated folders in your Drive and save weekend read attachments, expense receipt files, and expense report PDFs to them at your direction. Google user data is not used for advertising, shared with third parties for independent purposes, or processed for any use unrelated to providing the Service.
Microsoft Graph data use. Data received via Microsoft Graph — User.Read, Calendars.ReadWrite, OnlineMeetings.ReadWrite, and, on enterprise plans, Mail.Send and Mail.ReadWrite restricted to your organization's designated assistant mailbox — is used solely to identify your account, read your calendar availability, create and update calendar events at your direction, generate Microsoft Teams meeting links you authorize, and send and receive assistant email through the mailbox your organization designates. It is not used for advertising, shared with third parties for independent purposes, or processed for any use unrelated to providing the Service.
Zoom data use. Zoom authorization is used solely to create meeting links for meetings you authorize. We do not access Zoom recordings, transcripts, meeting content, participant lists, or your Zoom meeting history. Zoom data is not used for advertising, shared with third parties for independent purposes, or processed for any use unrelated to providing the Service.
6. Who we share it with
We use third-party service providers ("sub-processors") to deliver the product. Each sub-processor receives only the data necessary for its function:
| Sub-processor | Purpose |
|---|---|
| Anthropic | AI model inference for your assistant's reasoning |
| Supabase | Database storage |
| Vercel | Application hosting and compute |
| Postmark | Outbound email delivery |
| Resend | Inbound email receiving |
| Calendar API and Drive API (when you connect Google services) | |
| Microsoft | Microsoft Graph — Microsoft 365 calendar API (when you connect Microsoft 365), Teams meeting link generation, and assistant mailbox email on your corporate domain (enterprise plans) |
| Slack | Messaging (when connected) |
| Photon | iMessage relay between you and your assistant (when connected, where available) |
| Zoom | Video meeting link generation (when you connect Zoom) |
A complete vendor data flow document with security certifications, retention details, and DPA links is available on request to legal@heyaria.cc.
We do not share your data with any third party other than the above sub-processors, except as required by law (e.g., subpoena or court order) or with your explicit consent.
7. How long we keep it
| Data category | Retention |
|---|---|
| OAuth tokens (calendar, Drive, mail, Zoom) | Until you disconnect the integration, remove the app from the provider's side, or delete your account |
| Email and direct-message content | 120 days (configurable per contract) |
| Saved Weekend Read items | Raw source email purged per your message-content retention window (120 days by default); the saved item, summary, and Drive links are retained until you delete them. Attachments saved to your Google Drive remain in your Drive under your control. |
| Phone sheet, to-do, contact, and project records | Until account deletion (individual items until you delete them) |
| Expense records and expense reports | Until account deletion (individual items until you delete or void them). Receipt files and report PDFs saved to your Google Drive remain in your Drive under your control. Raw source emails containing receipts purge per your message-content retention window (120 days by default) |
| Outstanding follow-ups | Until you mark them done |
| Exec profile data (relationships, projects, schedule rules) | Until account deletion |
| Calendar event references | Until account deletion |
| System logs | 30 days |
| Postmark delivery records | ~45 days (per Postmark's policy) |
| Resend inbound records | ~30 days (per Resend's policy) |
| Photon iMessage relay records | Per Photon's retention policy while our account is active (when iMessage is connected) |
| Anthropic API logs | Max 7 days for abuse detection (per Anthropic's policy) |
Our message-content retention is enforced by an automated daily purge job. After expiration, the content is permanently deleted from our database. Retention applies to raw correspondence; records your assistant derives from it (such as contacts, notes, phone sheet entries, and read summaries) persist as described above so your working history remains intact.
8. Your rights
Depending on your jurisdiction, you may have the following rights regarding your data:
Access. You may request a copy of all data we hold about you.
Correction. You may request correction of inaccurate data.
Deletion. You may request full deletion of your account and all associated data. We will process deletion requests within 30 days. After deletion, we retain only the minimum information required by law (e.g., billing records if applicable). Email service provider logs (Postmark, Resend) will purge within 45 days per their respective retention policies. Files saved to your own Google Drive remain yours and are unaffected by our deletion.
Disconnection. You may revoke calendar, Drive, email, messaging, or video integration permissions at any time through the respective service provider's settings, through your HeyARIA settings, or by contacting us.
Portability. You may request your data in a machine-readable format.
Objection / restriction. You may object to specific processing activities or request restriction of processing.
Complaint. EU users have the right to lodge a complaint with their local data protection authority.
To exercise any right, email privacy@heyaria.cc. We will respond within 30 days.
Additional rights for California residents
If you are a California resident, you have the following specific rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):
- Right to know what personal information we collect, the purposes for collection, and the categories of sources and third parties involved.
- Right to delete your personal information (subject to certain exceptions, such as legal compliance).
- Right to correct inaccurate personal information.
- Right to opt out of sale or sharing of personal information. We do not sell your personal information, and we do not share your personal information for cross-context behavioral advertising.
- Right to limit use of sensitive personal information. Where we process information that may qualify as sensitive (such as the contents of communications), we use it only to provide the service you have requested, and not for inferring characteristics about you.
- Right to non-discrimination. We will not deny service, charge different prices, or provide a different quality of service because you exercised your privacy rights.
To exercise these rights, email privacy@heyaria.cc. We will verify your identity before fulfilling the request.
9. Security
We implement layered security to protect your data:
At rest:
- All data encrypted at the database disk layer (AES-256 via Supabase)
- OAuth tokens additionally encrypted at the application layer (AES-256-GCM) — even with database access, credentials cannot be extracted without our encryption key
- Encryption keys held in Vercel environment variables, never in the database
In transit:
- All API calls and webhooks use TLS 1.2 or higher
- All sub-processors enforce HTTPS
Access control:
- Backend-only access to the database; the dashboard authenticates every request with signed sessions, and no data is readable without a valid session for the owning account
- Production credentials accessible only to authorized personnel
- Service-role keys and API credentials rotated at least annually and on suspected compromise
- Multi-factor authentication required on all administrative accounts to our sub-processor consoles (Vercel, Supabase, GitHub, Anthropic, Postmark, Resend, Slack, Google Cloud, Microsoft Azure)
- Enterprise mailbox access is restricted by your organization's administrator to designated assistant mailboxes only, using Microsoft's application access controls
- Authorized personnel have administrative access to the underlying database for support, security incident response, and abuse investigation. Infrastructure-level access logging is provided by our hosting providers; as the team grows, we will implement role-based access controls and dedicated administrative audit logs.
Operational:
- Service operates on SOC 2-audited infrastructure. Our sub-processors either maintain their own SOC 2 attestations (Anthropic, Supabase, Vercel, Resend, Google, Microsoft, Slack, Zoom, Photon) or host on SOC 2 Type 2-accredited data center infrastructure (Postmark). Current attestation status for any sub-processor is available on request to legal@heyaria.cc
- Automated dependency vulnerability scanning on the application codebase
- Automated secrets scanning on all code commits to prevent accidental credential exposure
- Daily automated retention enforcement
- Versioned encryption format permits future key rotation without data loss
Breach notification: In the event of a personal data breach affecting your data, we will notify you within 72 hours of becoming aware of the breach. Notification will include the nature of the breach, the categories of data affected, the likely consequences, and the steps we are taking to remediate. Where required by law, we will also notify the relevant regulatory authorities and affected third parties.
10. International data transfers
HeyARIA operates from the United States. By using the service, you consent to your data being processed in the United States. For users in the European Economic Area or UK, our sub-processors offer GDPR-compliant data transfer mechanisms (Standard Contractual Clauses or equivalent).
11. Children's privacy
HeyARIA is intended for adult professional users in the entertainment industry. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided data, contact privacy@heyaria.cc and we will delete it.
12. Changes to this policy
We may update this Privacy Policy. Material changes will be communicated via email to active users at least 30 days before taking effect. Non-material changes (typos, clarifications, sub-processor updates) may be made without notice.
The "Last updated" date at the top reflects the most recent change.
13. Contact
Questions, requests, complaints, security disclosures:
- Privacy questions: privacy@heyaria.cc
- Security issues: security@heyaria.cc
- Legal: legal@heyaria.cc
- General inquiries: hello@heyaria.cc
Effective date: September 15, 2026.