HeyTim

Privacy Policy

Effective October 1, 2026

This policy explains what HeyTim collects, why we use it, and the choices available to you.

Information we collect

We collect the email address used for passwordless authentication, bot configurations, conversation messages, and basic service records needed to operate and secure HeyTim.

Our API keeps access logs for 30 days. These records include the request time and route, your IP address, response status and latency, and technical errors. We use them to maintain service reliability and security.

Bot inboxes are unavailable in the current fresh beta. If enabled later, we would collect email sent to a bot’s address, including the sender and recipient addresses, subject, message text, and attachment names. We would briefly store the original email, including any attachments, while processing it. You could review and delete inbox messages. New conversations would wait for review by default; if you selected automatic mode, authenticated incoming mail could start bot work. Authenticated replies to an existing bot email conversation could continue automatically.

Phone-number sign-in is unavailable in the current beta, so we do not collect a mobile number or SMS consent for sign-in. If offered later, we would collect the number and consent record only if you chose that optional sign-in method. Email sign-in would remain available.

If you allow reply notifications, we store a device push token and a delivery identifier. The current iPhone and Mac apps register Apple device tokens with Amazon Simple Notification Service (SNS), which sends notifications through Apple Push Notification service (APNs). Older app versions that use Expo may still receive notifications through Expo. On supported Apple devices, dictation is requested as on-device speech recognition; HeyTim does not intentionally upload or retain the audio recording.

How we use information

We use this information to authenticate you, save bots and conversations, run requested agents, deliver notifications, prevent abuse, and maintain the service. If SMS sign-in is introduced, mobile numbers would be used only to send user-requested one-time passcodes and related verification messages.

HeyTim does not sell personal information. Mobile numbers and SMS opt-in or consent data are not shared with third parties or affiliates for their own marketing or promotional purposes.

AI processing and connected accounts

When you ask a bot to work, your message and relevant conversation history, files, and connected-service results may be processed by HeyTim’s agent service on Amazon Web Services and sent through OpenRouter to AI model providers for an answer, draft, or generated content. The model provider can vary by request or fallback. This processing can include personal information.

Before a bot can use third-party AI processing, HeyTim asks for your permission. You can turn it off in Settings → Data & Privacy → Turn Off AI Processing. This stops new AI work and stops a running task before its next model-provider request. Turning it off does not delete content already saved in conversations, files, memory, or tool results.

On iPhone, you can choose View Health Summary in Settings to grant read-only Apple Health access to steps and workouts, including running workouts. The current app calculates and displays the summary on that iPhone. New Health readings are not sent to HeyTim servers, bots, OpenRouter, or other AI providers. You can change access in iOS Settings or the Health app. Health summaries shared with a bot in an earlier app version may remain in previously saved conversations, files, or memory until you delete that content.

When Google connections are available, you can connect Gmail or YouTube and assign each connection to bots you choose. Google Workspace connections are unavailable in the current production environment. HeyTim stores the connection record and refresh credential in AWS Secrets Manager. An assigned bot may read information permitted by the grant to respond to your request; Gmail bots may also create drafts for your review.

Information returned by a connected service can appear in saved conversations, generated files, bot memory, and stored tool results. If you use a connected bot in a group, its answers or shared files can make some of that information visible to other group members.

Disconnecting an account prevents new bot requests from using that connection. HeyTim attempts to revoke the provider grant and schedules its stored credential for deletion. Disconnecting does not erase information already included in conversations, files, stored tool results, or memories.

Connected Google accounts

With Gmail, an assigned bot can search and read messages, threads, labels, and drafts, and create a draft for you to review in Gmail. HeyTim’s current Gmail tools do not send, delete, archive, or relabel messages. The Gmail compose permission itself can permit sending, although HeyTim’s tools only create drafts. With YouTube, an assigned bot can search videos and read your channel details and uploaded-video list; its current tools do not change your channel.

When an assigned bot uses a Google connection for your request, relevant Google data is processed by HeyTim’s agent service on Amazon Web Services. It may be included in a request through OpenRouter to the selected AI model provider to generate an answer or draft. We do not sell information received from Google services or use it for advertising.

Google data returned to a bot can appear in saved conversations, generated files, or information derived from conversations for bot memory. Larger retrieved results can be saved in HeyTim’s file storage so the bot can use them. If you use a connected bot in a group, other group members may see Google information included in its answers or shared files.

Removing a Google connection stops future access. HeyTim attempts to revoke the Google grant and schedules its stored credential for deletion with a seven-day recovery period. You can also revoke access in your Google Account. Removing a connection does not erase earlier conversations, generated files, memories, or stored tool results containing information the bot already used. You can delete saved content with HeyTim’s content controls. Account deletion starts broader cleanup; content shared into a group owned by someone else may remain available to that group.

Google publishes an API Services User Data Policy and Workspace API data-use requirements. We are reviewing Google data retention and onward processing controls before enabling Google connections in this production environment.

Connected financial accounts

When Plaid connections are available, connecting a financial institution is optional. You choose the institution in Plaid Link and which accounts and HeyTim bots can use the connection. Your bank sign-in happens with Plaid or your financial institution; HeyTim does not receive your bank username or password.

HeyTim stores a scoped Plaid access token in AWS Secrets Manager, plus your connection and account details. We import and update your transactions in private, account-scoped storage. Assigned bots can read those transactions and request account details, balances, and supported credit liabilities. Financial information used in a bot request may be sent through OpenRouter to the selected AI model provider and may appear in saved conversations, files, or bot memory. If you use the bot in a group, information included in its answers or shared files may be visible to other group members.

Disconnecting the institution stops future access, requests removal of the Plaid connection, schedules deletion of its stored access token with a seven-day recovery period, and queues deletion of the stored transaction history, including its saved versions. Financial information already included in conversations, files, or bot memory remains until you delete that content. Account deletion starts broader cleanup of your account data.

Service providers and sharing

HeyTim uses Amazon Web Services for account services, agent processing, data storage, and native notification delivery through Amazon SNS; Apple APNs to deliver notifications to current iPhone and Mac apps; Plaid for optional financial connections when available; and OpenRouter and AI model providers for requested bot output. Stripe handles paid subscription billing where applicable; new paid checkout is unavailable in the current fresh beta. Older app versions may use Expo for notification delivery. Relevant user text and connected-service content can be included in requests routed through OpenRouter.

When you use paid billing, HeyTim stores your Stripe customer and subscription identifiers, subscription status and renewal period, and work-credit usage. Stripe processes payment details; HeyTim does not receive or store your full card number.

If you create a share link, anyone with a valid link may be able to import its content, so treat share links as private. Group members can see messages and files shared in their group, including information in a bot’s response even though the underlying account connection belongs to you.

SMS choices

HeyTim does not currently offer SMS sign-in or send verification texts. If it becomes available, a transactional verification code would be sent only after you request one. Message frequency would vary, and message and data rates may apply. You could reply STOP to opt out or HELP for help. For US toll-free messages, text START or UNSTOP to the sending number to re-enable messages after opting out. See the proposed HeyTim SMS program and Terms of Use for details.

Retention and choices

We retain account content and consent records while needed to provide HeyTim, comply with legal obligations, resolve disputes, or protect the service. If bot inboxes become available, inbox previews would remain until you delete them or your account, while original received email would be stored temporarily for processing. You could turn off or replace a bot’s email address from its inbox. You can stop notifications in device settings and sign out at any time.

You can request permanent account deletion from Account settings in the iPhone or Mac app. This starts cleanup of your account and the content it owns. Content shared into a group owned by someone else may remain available to that group. Operational backups expire on their limited recovery schedule. Our storage lifecycle schedules noncurrent versions of user files for expiration after 30 days; account deletion attempts to remove owned versions sooner. AWS security audit records can remain for up to seven years. Learn how account deletion works.

Security, children, and changes

We use administrative and technical safeguards designed to protect information, but no online service can guarantee absolute security. HeyTim is not directed to children under 13.

Questions about this policy or your account can be sent to support@heytim.ai. We may update this policy as the service changes. The effective date identifies the current version.