HEYBRYAN LTD
Privacy Policy
Last updated: August 8, 2026
Who We Are
HEYBRYAN LTD (“we”, “us”, or “our”) operates the HeyBryan service and is responsible for the personal information described in this Privacy Policy. HEYBRYAN LTD is registered in England and Wales under company number 17297711.
What We Collect
HeyBryan collects the information you provide while using the service, including your email address, profile name, tasks, notes, lists, calendar planning details, Control Centre settings, and feedback you send to us.
If you send a WhatsApp voice note, HeyBryan processes the audio and transcript so Bryan can respond in the same WhatsApp conversation.
If you connect calendars, HeyBryan stores calendar connection metadata, imported calendar events, and encrypted OAuth tokens or subscribed ICS feed details needed to sync your schedule.
How We Use It
We use your information to provide the app, keep you signed in, sync your planning data, generate AI-assisted suggestions, troubleshoot bugs, improve the app, and respond to support requests.
We do not sell your personal information.
We do not use your personal information or Google user data for advertising, creditworthiness, lending eligibility, employment eligibility, insurance eligibility, or other sensitive eligibility decisions.
Service Providers
HeyBryan uses Supabase for authentication, database services, and Bryan memory records; Meta for WhatsApp delivery; OpenRouter and configured model providers for conversation generation; OpenAI for fallback AI processing, structured extraction, memory extraction, and audio transcription; Vercel for hosting and analytics; and Sentry if error monitoring is enabled.
Conversation requests sent through OpenRouter are restricted to routes marked for zero data retention, with provider data collection denied and required request parameters enforced.
These providers process data only as needed to operate the features you use.
Sharing, Transfer, And Disclosure
HeyBryan does not sell personal information or Google user data. We do not allow third parties to use Google user data for their own advertising, profiling, or unrelated purposes.
We may share, transfer, or disclose personal information and Google user data only to provide the HeyBryan service through trusted infrastructure and service providers; where you direct or consent to an action, such as creating, updating, summarising, or sending information through a connected service; where required by law, regulation, legal process, or enforceable governmental request; or as part of a merger, acquisition, financing, reorganisation, or sale of assets subject to appropriate confidentiality and data protection obligations.
Service providers are permitted to process data only on our behalf and only for the purpose of operating, securing, supporting, or improving the HeyBryan features you use.
Security And Data Protection
We use administrative, technical, and organisational safeguards designed to protect personal information, Google user data, and sensitive data from unauthorised access, loss, misuse, disclosure, alteration, or destruction.
These safeguards include HTTPS/TLS encryption in transit, secure cloud infrastructure, access controls, least-privilege access practices, secure authentication, operational logging and monitoring, and retention controls designed to keep data only for as long as needed to provide the service, comply with legal obligations, resolve disputes, or enforce agreements.
Where sensitive data is processed, we limit access, reduce unnecessary retention, and use trusted service providers with appropriate security controls.
Calendar And WhatsApp Voice-Note Data
Calendar connections and imported calendar items are used to show your schedule inside HeyBryan. WhatsApp voice notes may be transcribed so Bryan can understand and respond to the message.
Raw voice-note audio is not retained by HeyBryan after transcription unless explicit retention is enabled in a future opt-in setting. Voice notes are not exported or used for training without explicit opt-in.
Avoid entering highly sensitive personal, financial, medical, or legal information. Bryan is designed for life admin support, not emergency, legal, financial, or medical advice.
Google User Data
If you connect your Google account, HeyBryan may request access to Google user data only where needed to provide the features you enable, such as helping you manage calendar events, reminders, tasks, notes, email-related actions, or other life-admin workflows.
HeyBryan uses Google user data only to provide and improve user-facing features you request or enable. For example, we may use Google Calendar data to help you create, update, summarise, or manage calendar events, and Gmail-related data only where you have explicitly granted access for supported life-admin workflows.
HeyBryan does not use Google user data for advertising, does not sell Google user data, and does not use Google Workspace API data to develop, improve, or train generalised AI or machine learning models.
You can revoke HeyBryan’s Google account access at any time from your Google Account permissions page.
Retention And Deletion
Tasks, notes, lists, calendar events, Bryan memory, calendar connections, WhatsApp conversation records, and Control Centre notification records are kept while your account is active unless you delete them from Settings.
You can delete Bryan memory, revoke the private task calendar ICS link, or delete your account from Settings. Account deletion removes local Supabase-owned planner data, notes, events, calendar tokens, historical notification-device records, Bryan memory, and matching launch-signup data where applicable.
Control Centre notification records are local operational records and are removed during account deletion. Usage and spend audit events may be retained without your user id for up to 90 days for abuse, reliability, and cost investigation.
Backups and provider logs may persist for a limited period after deletion. Local Settings controls create a deletion job for operator follow-up where processor-side deletion is available across OpenAI, OpenRouter, Meta, Vercel, and other external processors. Historical Mem0 or legacy voice-provider records may also require operator follow-up where you used those retired features previously.
Contact
For privacy questions, support, external processor deletion follow-up, or deletion requests you cannot complete in Settings, contact hello@heybryan.ai.
Google API Limited Use
HeyBryan’s use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. For Workspace APIs, HeyBryan also complies with the Google Workspace API User Data and Developer Policy.
You can revoke HeyBryan’s Google access from your Google Account permissions.
