Privacy Policy
This Privacy Policy explains what Hearth collects, how we use it, and the choices you have. Hearth is provided by Daedalus Intelligence Works, Inc. (“we”, “us”) and this policy applies to ourhearth.ai and the Hearth service.
What we collect
- Account details. When you sign in with Google, we receive your name, email address, and basic profile information. If you add further email addresses to your profile, we store those too (and a short-lived verification code while we confirm you own them).
- Your content. The notes, files, apps, schedules, and messages you and Agent Heath create in your workspace, including images and documents you upload.
- Email you send to Heath. When you email your workspace’s Heath address, we receive the message — sender, recipients, subject, body, and threading headers — and it becomes part of a conversation in your workspace.
- Connected-account data. Data we fetch on your behalf from services you choose to connect (see Connected services).
- Notification subscriptions. If you turn on notifications, the push subscription your browser issues us (an endpoint URL at your browser vendor’s push service, plus its encryption keys).
- Payment records. If you connect a payment wallet, the record of what was authorized and spent (see Payments). We never receive your card number.
- Usage and device data. Logs such as IP address, browser type, and timestamps, used to run, secure, and debug the service.
How we use it
- Provide and maintain Hearth and your family workspace.
- Power Agent Heath and the tasks you ask it to perform.
- Keep Hearth secure, reliable, and free of abuse.
- Understand how Hearth is used and monitor, debug, and improve the service and Agent Heath.
- Communicate with you about your account and the service.
AI processing
To power Agent Heath, the content needed for a given task is sent to third-party AI model providers solely to generate a response. Which provider handles a given task depends on the model in use, and we change models as better ones become available; today they are Fireworks AI, OpenAI, and Google. We do not permit these providers to use your content to train their models. If a task involves an image or document you uploaded, we give the provider a short-lived link so it can read that file directly.
Agent Heath can also use tools that reach outside your workspace when a task calls for it. These send only what the tool needs — a search query, a URL, or the request an app makes — not your whole workspace:
- Web search and page fetching through Parallel, and the search tools built into the OpenAI and Google models.
- A managed browser (Cloudflare Browser Rendering) that Heath can drive to load and debug the apps in your workspace. When you ask for this in a live conversation, that browser is signed into your workspace on your behalf; runs that happen without you present are not signed in.
- Tool servers you connect. You can connect additional third-party tool (MCP) servers. Anything Heath sends such a server is governed by that server operator’s own privacy practices, not this policy.
Analytics and monitoring
We use PostHog as our analytics and error-tracking provider. We send it product events (for example that a chat or schedule was created), reports of errors and crashes, and records of Agent Heath’s activity — including the prompts sent to and responses received from the AI providers, together with metadata such as the model used, token counts, timing, cost, and errors — so we can monitor, debug, and improve the service. We do not send your name or email address to PostHog: records about a person are identified by a one-way hash, and records about a workspace as a whole are identified by that workspace’s name. Conversation content sent to PostHog is retained for a limited period (currently 30 days) and then deleted automatically.
Each workspace has an email address for Agent Heath. Mail you send there is received and delivered through Cloudflare’s email services, and Heath’s replies are sent the same way. Heath only exchanges email with people who are members of your workspace: mail from an address we don’t recognize is discarded without a reply, and non-members on a thread are dropped from the reply rather than written to. Email you send to Heath is stored in your workspace as a conversation and is processed like any other content, including by the AI providers described above.
Notifications
If you enable notifications, we send them through the push service your browser vendor operates (such as Apple, Google, or Mozilla). The contents of each notification are encrypted so that only your device can read them; the push service sees the delivery, not the message. You can turn notifications off in your settings or in your browser at any time, which revokes the subscription.
Payments
You can optionally connect a Stripe Link wallet so Agent Heath can pay for something you have asked it to buy. We never receive or store your payment details — the cards saved in your wallet — or your Link password. Your Link credentials are held in a separate, isolated vault that can use them but will not hand them back to the rest of Hearth. Every payment needs your approval in Link at the moment it happens. What Heath is given is a single-use virtual card that Stripe issues for that one purchase, locked to that amount and useless afterwards — never the payment method behind it. We keep a record of these payments (merchant, amount, date, the last four digits, and who authorized it) so your workspace has a ledger. You can disconnect your wallet at any time in your settings.
Where your data lives
Hearth runs on Cloudflare (Workers, Durable Objects, and R2 storage), and your data is encrypted in transit and at rest. Credentials for connected services and payment wallets are kept sealed in a separate vault, isolated from the rest of the service. Hearth is not end-to-end encrypted: to provide the service our systems process your content, and a limited number of authorized people may access it when necessary — for example to debug an issue or to comply with the law.
Who we share it with
We do not sell your data. We share it only with the providers that help us run Hearth, under contract and for these purposes:
- Cloudflare — hosting, storage, email delivery, and the managed browser.
- Google — sign-in, and AI features when a Google model is selected.
- Fireworks AI — AI features (see above).
- OpenAI — AI features (see above).
- Parallel — web search and page fetching for Agent Heath.
- PostHog — product analytics, error tracking, and AI monitoring (see Analytics and monitoring).
- Stripe — payments, if you connect a wallet (see Payments).
Beyond these, data goes to a third party only because you connected it — the accounts and tool servers you link yourself, described below.
We may also disclose data if required by law or to protect the rights, safety, and security of our users and Hearth.
Connected services
You can connect third-party accounts so the apps in your workspace can act on your behalf. Apps can work with any service that offers a standard connection, and we make a curated set — including YNAB (You Need A Budget) — a one-click choice in your integration settings, where you can see everything you have connected. Connecting anything is your choice, and we handle the data as follows:
- Access is by OAuth only. We never see or store your sign-in credentials for a connected service — only the access and refresh tokens it issues to us.
- Tokens are encrypted at rest (AES-256-GCM) in a separate vault, under a key separate from your session, and are scoped to your account alone. The vault uses them to make requests for you and does not release them — not to Agent Heath, and not to the apps in your workspace.
- We ask for the narrowest access that works. A connection starts with sign-in-level permission, and an app must ask you again before it can reach anything more.
- Data is fetched on demand. We retrieve data from a connected service’s API server-side, only when an app you have connected requests it, and only for the feature you are using. The app receives the data it asks for but never your tokens.
- We use it only to provide those features — we do not sell it, and we will not knowingly pass it to any third party. The only parties that may process it are the infrastructure and AI providers listed above, and only when a feature you use requires it.
- You can revoke access at any time from your integration settings. Disconnecting deletes the stored tokens immediately. You may also email privacy@ourhearth.ai to request deletion.
For YNAB specifically, we request read-only access — the minimum needed to show your plan and transactions in the apps you connect. We are not affiliated with, sponsored by, or endorsed by YNAB.
Retention and deletion
We keep your data while your workspace is active. You can ask us to export or delete your data, or close your workspace, at any time by emailing privacy@ourhearth.ai. We’ll delete it within a reasonable period, except where we must retain it by law.
Your choices
You can access, correct, export, or delete your data by contacting us. Depending on where you live, you may have additional rights under local law.
Families and children
Hearth is set up and controlled by an adult on behalf of their household. It is not directed to children under 13, and children should use a workspace only under the supervision of the adult who owns it.
International users
Hearth is operated from the United States, and your data is processed there.
Changes
We may update this policy; we’ll post the new version here and update the date above.
Contact
Questions about privacy? Email privacy@ourhearth.ai.