Skip to legal information
How It Works Features Pricing Login
Home How It Works Features Pricing Login
Legal Overview Terms Privacy AI & Voice Subscriptions Cookies Account deletion Support

Hey Bean LLC privacy notice

Privacy Policy

Effective date: August 13, 2026

This Privacy Policy explains how Hey Bean LLC (“Hey Bean,” “we,” “us,” or “our”) collects, uses, discloses, and retains personal information when you use HeyBean websites, web and mobile apps, connected services, subscriptions, and the branded Bean assistant (the “Service”). Hey Bean LLC is the controller or business responsible for the practices described here unless another notice says otherwise.

1. Scope

This Policy applies to information processed by Hey Bean LLC through the Service. It does not govern a third-party website, app, calendar, marketplace, or other service operating under its own privacy policy. A workspace owner or organization may separately control information it asks you to submit; contact that party about its practices.

2. Information we collect

CategoryExamplesPrimary sources
Account and identifiers Name, email address, user and workspace identifiers, optional password hash, Google or Apple sign-in identifier, one-time login-code records, authentication tokens, profile image or initial, account status, preferences, and verification records. You; automatically from the Service; Google or Apple when you choose provider sign-in; an invited workspace owner.
Productivity and workspace content Tasks, reminders, calendar events, notes, folders, categories, sticky notes, workspaces, member roles, completion history, settings, and content about people you choose to include. You; workspace members; connected services; Bean actions you request.
Bean, AI, and voice data Typed prompts, conversation messages, AI responses, tool requests and results, saved conversational memory, microphone audio while voice mode is active, provider transcript data, usage measurements, and content-minimized voice lifecycle events. You; your device; AI and voice providers; account tools.
Connected-service data Calendar lists and events, provider account identifiers, encrypted OAuth credentials or calendar-link source URLs, workspace import/export choices, event-link and sync-run status, sync cursors, and other data within permissions you grant to Google, Microsoft, or another provider. You and the connected provider.
Billing and commercial data Plan, trial and renewal dates, price, currency, subscription and customer identifiers, purchased voice-time grants and usage, payment status, invoices, and limited card details such as brand and last four digits. We do not intentionally store full payment-card numbers. You; Stripe or an applicable marketplace/payment provider.
Device, network, and usage data IP address or one-way IP hash, browser and device type, operating system, app version, timestamps, page path, referring page, campaign parameters, random visitor identifier, request and response metadata, diagnostics, crashes, feature interactions, rate-limit events, and security logs. Automatically from your browser, app, device, and our systems.
Approximate or precise location Location you type, approximate location inferred from network or locality, or device location you choose to share for maps, places, weather, travel time, and time-zone features. You; your device; map, place, postal, or weather providers.
Communications Support messages, legal or privacy requests, survey responses, security reports, notification preferences, email delivery events, and early-access or waitlist submissions. You; email and support providers; our systems.
Inferences Plan eligibility, likely time zone, feature preferences, abuse or fraud risk, and contextual suggestions derived from information above. Generated by the Service.

Some information may be considered sensitive under local law, including message content, precise location, calendar details, voice input, or information you place in notes. We process it only for the purposes described here and recommend that you avoid entering sensitive data that is unnecessary for the feature.

3. How we use information

  • Provide and personalize the Service: authenticate accounts; display, search, sync, and organize content; run shared workspaces; process voice and typed requests; execute requested actions; deliver reminders and notifications; provide maps, places, weather, and connected calendars; and maintain settings and history.
  • Process subscriptions: offer trials, take payment, administer plans and limits, send receipts, manage renewal or cancellation, prevent payment fraud, and maintain transaction records.
  • Operate and improve: measure performance and use, troubleshoot errors, evaluate Bean quality, improve accessibility and product design, and develop features. Where practical, we use aggregated, de-identified, or content-minimized information.
  • Protect users and the Service: enforce rate limits and terms, detect abuse or unauthorized access, preserve integrity, investigate incidents, and keep systems reliable.
  • Communicate: send requested reminders, service messages, security notices, policy updates, launch or early-access messages, and responses to support or legal requests.
  • Comply with law: satisfy legal, tax, accounting, regulatory, and lawful-process obligations; establish or defend legal claims; and protect rights, safety, and property.

We do not use the contents of your private productivity records, calendars, or Bean conversations for third-party behavioral advertising. Hey Bean LLC does not sell personal information or share it for cross-context behavioral advertising, and does not use your private content to train a general-purpose AI model. We do not use voice input to identify you biometrically, create a voiceprint, or make eligibility or other high-impact decisions about you.

4. Bean, AI, and voice processing

Typed Bean messages, voice requests, and relevant account context may be sent to our conversational AI provider, currently ElevenLabs, and the model subprocessors configured within its hosted agent to understand requests, plan permitted actions, use scoped tools, and generate responses. Bean conversations, tool results, and user-specific conversational memory may be stored with your account so Bean can maintain continuity. Search queries, weather requests, place lookups, or other requests may be sent to the provider needed to answer them. Queries should be treated as potentially identifying if they contain personal details.

When you activate voice mode, microphone audio is transmitted to ElevenLabs for speech recognition, turn-taking, model processing, and speech generation. The current hosted-agent configuration disables saved voice recordings and requests transcript and audio deletion using a zero-day provider setting. This is scheduled deletion, not ElevenLabs’ separate “Zero Retention Mode,” and does not prevent transient processing or limited retention for security, abuse prevention, debugging, payment or usage reconciliation, or legal obligations. Provider settings and deletion requests reduce retention risk but cannot guarantee that no provider-held copy ever exists.

HeyBean’s authenticated voice lifecycle telemetry is designed to exclude prompts, transcripts, spoken answers, labels, and provider error text. It records identifiers, timing, status, duration, and generic outcome or length classifications needed for reliability and cost measurement, and is currently scheduled for deletion after 30 days. HeyBean does not use voice input to identify you biometrically or create a voiceprint.

For the public landing-page Bean demo, an ephemeral server-side conversation may be stored to maintain the demo and is currently scheduled for deletion after approximately 24 hours of inactivity. The public voice provider uses the voice retention configuration described above. See the AI & Voice Notice for important limitations.

5. Connected calendars and Google user data

When you connect a calendar, we process only scopes and data needed for the features you authorize. We encrypt OAuth credentials and retained calendar-link source URLs and use sync metadata to avoid repeatedly fetching the same data. Calendar links are import-only. Google and Microsoft events are sent only to writable calendars you enable for export. Unchecking a destination or deleting its HeyBean event does not delete the provider copy. Disconnecting stops new sync and keeps imported HeyBean copies by default unless you explicitly choose to remove those local mirrors; either choice leaves provider-held events unchanged.

HeyBean’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google Workspace API data for advertising, credit, lending, or training generalized AI or machine-learning models. Microsoft and other provider data is used for the user-facing integration you request, security, support, and legal compliance.

6. When we disclose information

We may disclose information in the following circumstances:

  • Service providers and processors: companies that provide hosting and infrastructure; conversational AI, model processing, and voice; payment processing; calendar, map, place, postal, weather, and search data; push notifications; email delivery; bot and abuse protection; diagnostics; and customer support. Current examples may include ElevenLabs and its disclosed model subprocessors, Stripe, Google, Microsoft, Firebase/Google Cloud, Cloudflare, OpenStreetMap contributors and related geocoding providers, and Open-Meteo. They receive information needed for their function and process it under our instructions where they act as our processors, or under their own terms when they act independently.
  • Workspace members and people you direct: content, profile details, and actions within a shared workspace are visible to people with access. Information may also be sent to a calendar or other destination you select.
  • Legal and safety: when we reasonably believe disclosure is required by law, subpoena, court order, or lawful process, or is necessary to protect rights, safety, property, users, the public, or the integrity of the Service.
  • Business transactions: in connection with a financing, merger, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality and legally required notice.
  • With your direction or consent: when you ask us to connect, export, share, or otherwise disclose information.

We may disclose aggregated or de-identified information that cannot reasonably identify you. We maintain de-identified information in de-identified form and do not attempt to reidentify it except to test whether our de-identification measures are effective or as otherwise permitted by law.

7. Cookies, local storage, and tracking

We use first-party cookies and similar storage for authentication, security, preferences, onboarding, continuity, and optional operational measurement. After you allow measurement, a random first-party visitor cookie may persist for up to one year and be associated with bounded page, referral, campaign, platform, app-version, status, and one-way IP-hash records. Product measurement excludes form values, task and calendar content, notes, and Bean conversations. You can decline on the web or turn measurement off in the mobile app under Settings → Account. If you select “Remember me,” the web app may keep an authentication token in local storage; otherwise it uses session storage. Clearing storage may sign you out or reset settings. We do not currently use third-party behavioral-advertising cookies. Details and controls appear in the Cookie Notice.

8. Legal bases for EEA and UK users

If European Economic Area or United Kingdom data-protection law applies, our legal bases are:

  • Contract: to create and administer your account, provide requested features, process a subscription, and respond to support requests.
  • Legitimate interests: to secure, operate, troubleshoot, measure, and improve the Service; prevent fraud and abuse; communicate about non-marketing service matters; and establish legal claims, balanced against your rights.
  • Consent: where required for microphone, precise location, optional communications, certain device permissions, or connected-service access. You may withdraw consent, but prior lawful processing remains valid.
  • Legal obligation and vital interests: to comply with law or protect a person in exceptional circumstances.

9. Retention

We retain personal information only for as long as reasonably necessary for the purposes described, considering account status, feature needs, plan history settings, contractual and legal obligations, dispute and fraud risk, security, backup cycles, and whether information is in a shared workspace. In general:

  • account and active productivity content remains while your account is active or until you delete it, subject to plan-specific history limits and user deletion;
  • typed Bean conversations and saved memory may remain for account continuity until deleted through available controls, account deletion, or an applicable retention process;
  • authenticated content-minimized voice lifecycle telemetry is currently scheduled for deletion after 30 days; public demo runtime data after about 24 hours of inactivity; and voice-provider transcript/audio under the zero-day scheduled-deletion setting described above;
  • billing, purchased voice-time ledger, tax, fraud-prevention, legal, consent, and transaction records may be kept for the applicable statutory or dispute period;
  • product analytics and page-view events are scheduled for deletion after 180 days; email sign-in codes after seven days; password-reset tokens after two days; and failed queue jobs after 30 days;
  • infrastructure logs have a 30-day operational target, subject to verified hosting configuration; and
  • encrypted backups may retain deleted data until overwritten in the normal backup cycle and are not restored except for disaster recovery.

De-identified information may be retained longer. When retention is no longer justified, we delete, anonymize, or isolate the information. The fixed-window deletion jobs described above are scheduled to run daily, but technical failures or legal holds may delay deletion. We monitor and investigate known failures.

10. Your choices and privacy rights

Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, receive a portable copy, withdraw consent, or appeal a denied request. You may also have the right not to receive discriminatory treatment for exercising privacy rights. HeyBean does not make decisions producing legal or similarly significant effects based solely on automated processing.

  • Update profile and preferences, disconnect integrations, manage permissions, or delete the account from Settings where available.
  • Request access, correction, deletion, restriction, objection, portability, or an appeal by emailing bean@heybeanapp.com.
  • Use the in-app export for account and productivity data, workspaces, notes, Bean conversations and completed actions, usage records, calendar metadata, and legal acceptance versions. Contact us for a broader verified privacy-access request.
  • Unsubscribe from optional email using the message link, while continuing to receive essential account, billing, security, and policy notices.
  • Revoke microphone, notification, or location permission in device settings and connected-calendar access with the provider.

We may verify your identity and authority before completing a request. An authorized agent may submit a request where local law permits, but we may require proof of authorization and direct verification. We respond within the period required by applicable law. We may deny or limit a request where an exception applies and will explain the reason and available appeal rights. EEA and UK users may complain to their local data-protection authority.

11. U.S. state disclosures

The categories collected, sources, purposes, and recipient categories are described in Sections 2, 3, and 6. We do not sell personal information or share it for cross-context behavioral advertising, and have not done so in the preceding 12 months. We do not knowingly sell or share personal information of people under 18. Because we do not conduct those activities, we do not offer a “Do Not Sell or Share” link. We treat a recognized opt-out preference signal as a request to opt out when applicable law requires it, although the signal does not change our current no-sale/no-share practice. Contact us if you believe these statements are incorrect.

We use sensitive information only to provide requested features, protect the Service, and meet legal obligations—not to infer characteristics for advertising. If our practices materially change, we will update this Policy and provide legally required notices and choices.

12. Security

We use administrative, technical, and organizational safeguards designed for the nature of the information, including HTTPS in transit, password hashing, encrypted connected-service tokens where supported, access controls, rate limits, scoped service tools, validation and confirmation for designated actions, monitoring, and deletion controls. No method is completely secure. Use a strong unique password, protect your devices, sign out of shared browsers, and contact us promptly about suspected compromise.

13. International transfers

Hey Bean LLC is based in the United States, and we and our providers may process information in the United States and other countries with different privacy laws. Where applicable law requires a transfer mechanism, we take steps designed to use an approved mechanism, such as standard contractual clauses, together with appropriate supplementary safeguards. You may request information about the mechanism applicable to a particular transfer.

14. Children

The Service is intended only for people age 18 or older. We do not knowingly collect personal information from children. If you believe a child provided information, contact us so we can investigate and delete it as appropriate.

15. Account deletion

You may delete your account in the app or follow the Account deletion instructions. Cancel any active subscription first. Deletion removes the account from active systems subject to shared-workspace ownership, security, legal, billing, backup, and fraud-prevention exceptions. Revoking or deleting HeyBean does not automatically delete information held independently by a connected provider.

16. Changes to this Policy

We may update this Policy as the Service or law changes. We will post the new Policy and effective date and provide additional notice for material changes where required. If we need consent for a new practice, we will request it.

17. Contact

Hey Bean LLC is responsible for this Policy. Email bean@heybeanapp.com for privacy questions, requests, or complaints. We may ask for information needed to verify your account and jurisdiction.

© 2026 Hey Bean LLC. HeyBean and Bean are product brands of Hey Bean LLC. Legal · bean@heybeanapp.com