Herofy
How it worksTrustBecome a design partner
Legal

Privacy Policy

Effective July 24, 2026 · Last updated July 24, 2026

How DriftlineAI, Inc. collects, uses, and protects information in Herofy — including exactly what we do with data you connect from Google.

On this page
  1. Who we are and what this covers
  2. Information we collect
  3. Google user data
  4. How we use information
  5. Artificial intelligence
  6. How we share information
  7. Data retention and deletion
  8. Security
  9. Your rights and choices
  10. International data transfers
  11. Cookies and similar technologies
  12. Children's privacy
  13. Changes to this policy
  14. Contact us

1Who we are and what this covers

Herofy is a customer onboarding product operated by DriftlineAI, Inc., a Delaware corporation registered as a foreign entity in California ("we", "us", or "our").

This Privacy Policy explains what information we collect, why we collect it, how we use and share it, and the choices you have. It applies to:

  • our public website at herofy.ai;
  • the Herofy application at app.herofy.ai; and
  • any data we receive from services you choose to connect to Herofy, including Google, HubSpot, Slack, and Notion.

It does not apply to the third-party services themselves. When Herofy reads data from your HubSpot portal or your Google account, that provider's own privacy policy continues to govern their handling of your data.

A note on roles. For information about your own account (your name, your login, your billing contact) we act as a controller. For the customer records, email content, and calendar data that Herofy reads from the systems you connect, we act as a processor on your behalf — you decide what Herofy may see, and you can withdraw that access at any time.

2Information we collect

Information you give us

Contact details
If you request early access or ask to become a design partner, we collect the email address you submit and any other details you choose to send us.
Account information
When you create a Herofy account we collect your name, work email address, company name, and authentication identifiers. If you sign in with Google, we receive your name, email address, language preference, and profile picture from Google rather than asking you to create a password.
Support and correspondence
Messages you send us, and our replies, including anything you attach.

Information from the services you connect

Herofy is only useful because it reads the systems where your onboarding work already lives. You choose which of these to connect, and you can disconnect any of them at any time. Depending on what you connect, we may receive:

HubSpot
Companies, contacts, deals, deal notes, associated activity, pipeline and lifecycle stages, and owner assignments for the records you authorize.
Google
See section 3 below, which describes Google data specifically and in detail.
Slack
Messages and channel metadata from the channels you explicitly connect, used to identify onboarding commitments and blockers.
Notion
Content and metadata from the pages and databases you explicitly connect, used to read onboarding plans, notes, and commitments that live in your workspace.

This data will frequently contain personal information about your customers and prospects — their names, email addresses, job titles, and whatever they happened to write in an email thread. We handle that information as your processor and only to provide the service to you.

Information we collect automatically

Server logs
Our hosting provider records standard request data — IP address, user agent, requested URL, referrer, and timestamp — for delivery, security, and abuse prevention.
Product usage
Within the application, we record which features are used and when, so we can find what is broken and what is not working well. We do not use this to build advertising profiles.

3Google user data

This section describes our use of data obtained through Google APIs. It supplements, and where there is any conflict it overrides, the rest of this policy.

The scopes we request, and why

We request the narrowest set of scopes that makes the product work. Each one is requested for the specific purpose stated here and for nothing else:

openid, userinfo.email, userinfo.profile
To authenticate you and create your Herofy account. We use your Google account identifier, email address, name, and profile picture to sign you in and display who you are inside the product.
gmail.readonly
To read the email threads associated with an account you are onboarding, so Sidekick can identify what was committed to during the sales cycle, draft the onboarding plan from those commitments, and detect when an account has gone quiet. Every claim Sidekick makes links back to the specific message it came from, which is why read access is required rather than optional.
Google Calendar (calendar.events, calendar.readonly)
To read and, where you ask us to, write onboarding milestones, kickoff calls, and check-ins, and to keep the onboarding plan aligned with what is actually scheduled.
gmail.send (only if you enable outbound sending)
To deliver a message that you have written or reviewed and explicitly chosen to send from within Herofy, so that you do not have to copy a draft into another tab. This scope is not requested unless outbound sending is enabled for your workspace.
Sidekick does not send email on its own

Our AI assistant drafts messages; it never sends them. A message leaves your Google account only after a person has reviewed it and clicked send. There is no automated, scheduled, or AI-initiated sending path in Herofy, and the assistant has no ability to contact your customers on its own initiative.

How we store and protect Google user data

  • OAuth tokens are encrypted at rest and are never exposed to your browser or to any other customer.
  • We retain the minimum message content needed to show you the evidence behind a plan or a flag — typically message metadata, the extracted commitment or blocker, and the quoted excerpt it came from — rather than mirroring your full mailbox.
  • Google user data is logically separated per workspace and is accessible only to authenticated members of your workspace.
  • Data is encrypted in transit (TLS) and at rest.
Limited Use disclosure

Herofy's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Artificial intelligence and Google user data

Herofy uses large language models to draft onboarding plans and messages from the data you connect. With respect to Google user data specifically:

  • We do not use Google user data to develop, improve, or train generalized or non-personalized artificial intelligence or machine learning models.
  • Google user data is processed by AI models only to produce the output you asked for — your onboarding plan, your status summary, your draft message — and only within your workspace.
  • Where a third-party model provider processes this data on our behalf, we do so under terms that contractually prohibit the provider from training or improving their models on it.
  • Output generated from Google user data is never shown to another customer or used to improve another customer's results.

Human access to Google user data

We do not allow humans to read your Google user data unless one of the following applies:

  • we have your specific, affirmative consent to view specific data;
  • it is necessary for security purposes, such as investigating abuse or a suspected compromise;
  • it is required to comply with applicable law; or
  • the data has been aggregated and anonymized so that it no longer identifies any individual, and is used only for internal operations.

What we never do with Google user data

  • We do not sell it, and we do not transfer it for advertising purposes.
  • We do not use it for credit assessment, lending, or any determination about an individual's eligibility for a product or service.
  • We do not serve advertising in Herofy, targeted or otherwise.
  • We do not transfer it to data brokers, information resellers, or any other party except the service providers described in section 6 who process it on our behalf.

Revoking access and deleting Google user data

You can disconnect Google from Herofy at any time from your workspace settings, or revoke our access directly from your Google Account at myaccount.google.com/permissions.

Revoking access stops all further collection immediately. To have the Google user data we already hold deleted, email us at privacy@herofy.ai. We will delete it within 30 days, except where we are required to retain something to comply with a legal obligation.

4How we use information

We use the information described above to:

  • provide the service — draft onboarding plans, surface stalled accounts, generate evidence-linked summaries, and prepare drafts for your review;
  • authenticate you and keep your workspace secure;
  • respond to your support requests and communicate with you about the service;
  • monitor reliability, debug failures, and improve the product's features and usability;
  • detect, investigate, and prevent fraud, abuse, and security incidents; and
  • comply with legal obligations and enforce our terms.

If you are in the European Economic Area or the United Kingdom, our lawful bases are: performance of a contract (providing the service you signed up for), legitimate interests (security, product improvement, and direct communication with existing customers), consent (where you have given it, such as when authorizing a data source), and compliance with legal obligations.

5Artificial intelligence

Herofy's assistant, Sidekick, uses large language models to read the data you connect and produce drafts, plans, and summaries. Two commitments govern that processing:

  • Your data does not train anyone's model. We do not train models on your content, and our model providers are contractually prohibited from training or improving their models on data we send them.
  • A person stays in the loop. Sidekick prepares; you decide. It has no ability to contact your customers on its own, and nothing reaches a customer without a human reviewing and sending it.

AI output can be wrong. Herofy links every claim back to the source material precisely so that you can check it, and you should — particularly before acting on a plan or sending a drafted message.

6How we share information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share information only in these circumstances:

Service providers (subprocessors)
Vendors who process data on our behalf under written terms that restrict them to our instructions — cloud hosting and infrastructure (Google Cloud Platform and Firebase, United States), AI model providers, error monitoring, and email delivery. A current list of our subprocessors is available on request.
At your direction
When you connect a service or ask us to send something on your behalf, we exchange data with that service to do what you asked.
Within your workspace
Other members of your Herofy workspace can see the accounts, plans, and evidence in that workspace. Choose your workspace members accordingly.
Legal and safety
Where we are legally required to, or where we reasonably believe disclosure is necessary to investigate or prevent fraud, abuse, or harm. Where we are permitted to notify you first, we will.
Business transfers
If we are involved in a merger, acquisition, financing, or sale of assets, information may transfer as part of that transaction. It stays subject to this policy until you are notified of any change.

Google user data is subject to the additional restrictions in section 3, which take precedence over this section.

7Data retention and deletion

We keep information for as long as your account is active and for as long as we need it for the purposes described in this policy.

  • Connected-source data (HubSpot, Google, Slack, Notion) is deleted or de-identified within 30 days of you disconnecting that source or closing your account.
  • Account and billing records are retained for as long as required by tax and accounting obligations.
  • Server logs are retained for a limited period for security and operational purposes.
  • Backups may retain deleted data for a short additional period before they expire on their normal rotation.

You can request deletion at any time by emailing privacy@herofy.ai.

8Security

We encrypt data in transit and at rest, encrypt OAuth tokens with separately managed keys, isolate each workspace's data, restrict internal access to the smallest number of people who need it, and require multi-factor authentication for administrative access to our systems.

No system is perfectly secure, and we will not claim otherwise. If you believe you have found a vulnerability, please report it to security@herofy.ai and we will respond promptly. If a breach affects your personal information, we will notify you and any relevant regulator as required by law.

9Your rights and choices

Depending on where you live, you may have the right to:

  • access the personal information we hold about you and receive a copy;
  • correct information that is inaccurate or incomplete;
  • delete your personal information;
  • restrict or object to certain processing, including processing based on legitimate interests;
  • receive your data in a portable format;
  • withdraw consent at any time, without affecting processing already carried out; and
  • lodge a complaint with your local data protection authority.

To exercise any of these, email privacy@herofy.ai. We will respond within the time required by applicable law and will not discriminate against you for exercising a right. If your data reached us through a Herofy customer's connected account, we will refer your request to that customer, who controls it.

California residents

Under the California Consumer Privacy Act, as amended, California residents have the rights to know, delete, correct, and opt out of sale or sharing, and to limit the use of sensitive personal information. We do not sell personal information and we do not share it for cross-context behavioral advertising, so there is nothing to opt out of — but you may still exercise your other rights using the contact address above, and you may designate an authorized agent to do so on your behalf.

10International data transfers

We are based in the United States and our infrastructure is hosted there. If you access Herofy from outside the United States, your information will be transferred to and processed in the United States, where privacy laws may differ from those in your country. Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses or another lawful transfer mechanism.

11Cookies and similar technologies

Our marketing website does not set advertising or cross-site tracking cookies. The Herofy application uses cookies and local browser storage that are strictly necessary to keep you signed in, maintain your session, and protect against request forgery.

You can block or delete cookies in your browser settings, but the application will not keep you signed in without them.

12Children's privacy

Herofy is a business product and is not directed to anyone under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact privacy@herofy.ai and we will delete it.

13Changes to this policy

We may update this policy as the product changes. When we do, we will revise the "last updated" date at the top of this page. If a change materially affects how we handle your personal information — including any change to the Google scopes we request or how we use Google user data — we will notify you by email or through the application before it takes effect.

14Contact us

Questions, requests, or complaints about this policy or about how we handle your data:

DriftlineAI, Inc.
Attn: Privacy
privacy@herofy.ai

Herofy
PrivacyTerms
© 2026 DriftlineAI, Inc. Onboarding is chapter one.