Privacy Policy

Last updated: July 23, 2026  ·  Effective: July 23, 2026  ·  Version 1.6

This Privacy Policy explains how HeyGro ("HeyGro," "we," "us," or "our") collects, uses, and protects your information when you use the HeyGro mobile, desktop, and web applications, the HeyGro websites, and related services (the "Service"). We've tried to write it in plain language. If anything is unclear, please reach out.

The short version:

1.Who We Are

HeyGro is operated by Ranjith Satheshkumar — the "data controller" responsible for your personal information under this policy. You can reach us at support@heygro.app for anything in this document.

2.Information We Collect

Information you provide

Information stored only on your device

Some data never leaves your device. It is kept in local app storage and is not synced to our servers:

Information collected automatically

What we do not collect

To be explicit, HeyGro does not collect: your precise location; your contacts; your photos; health records or any clinical health data; payment or card details; bank logins or account credentials of any kind (HeyGro never connects to your bank — any spending figures come only from amounts you type in yourself); or advertising identifiers. Our anonymized product analytics (see the provider table below) contain no identity and none of Your Content — they count events like “a task was completed”, never what the task said or what anything cost. We do not track you across other companies' apps or websites, so the app never shows Apple's App Tracking Transparency prompt.

3.On-Device AI

HeyGro's AI features are designed to run on your device:

The text you capture is not sent to a third-party AI service for categorization or processing. HeyGro's AI is an organizational tool — it is not a therapist, coach, counselor, or medical tool of any kind.

4.Shared Focus Rooms (Body Doubling)

HeyGro includes an optional "Focus with others" feature: shared focus rooms (such as "Deep work" or "Study") where you can see that other people are focusing at the same time as you. This feature is off by default — nothing is shared unless you turn it on and accept the community agreement shown before your first room.

If you opt in and start a focus session, we publish a single, minimal presence record that other signed-in users of HeyGro can see in real time. It contains only:

Your presence record never includes what you are working on — task names, money data, and all other content stay private to your account. The record is deleted when your session ends or you leave the room; if your device disconnects unexpectedly, other users stop seeing you within about two minutes, and any leftover record is replaced the next time you join. If someone has blocked you, your presence is hidden from them. If you prefer not to appear to others at all, simply leave "Focus with others" switched off — every other part of HeyGro works the same.

Community safety. Display names shown in rooms are screened by an automated filter. If you report another user from a shared room, we store the report (your account ID, the reported user's ID and displayed name, the room, an optional reason, and a timestamp) so we can review it — we review reports within 24 hours. If you block a user, your block list (the blocked account's ID and displayed name) is stored under your own account, visible only to you, and used solely to hide that person from your rooms; you can unblock them at any time in Settings.

5.Notifications

Reminders (such as the daily ritual reminder) are local notifications, scheduled by the app on your own device with your permission. We do not operate a push-notification server and cannot send remote push messages to your device. You can turn reminders off at any time in the app or in your device settings.

6.How We Use Your Information — and Our Legal Bases

We use your information only to run HeyGro. Where GDPR or UK GDPR applies, each purpose rests on a legal basis:

We do not use your personal content to serve advertising, we do not profile you for marketing, and we make no decisions about you by solely automated means that have legal or similarly significant effects.

7.How Your Information Is Stored and Shared

HeyGro is built on Google Firebase. Your account and content are stored using Firebase Authentication and Cloud Firestore, hosted on Google Cloud servers, and protected by security rules that restrict each user's data to their own account. Google processes this data on our behalf as a service provider under the Firebase privacy documentation and Google's Cloud Data Processing Addendum. The full list of providers we use:

ProviderPurposeData involvedWhere it applies
Firebase Authentication (Google)Account sign-in (email and password, or anonymous guest accounts)Email address, display name, hashed credentials, authentication tokens; guests: an anonymous account ID onlyAll platforms
Cloud Firestore (Google)Storing and syncing Your Content under your own account; hosting the opt-in focus-room presence record; storing community-safety reports and block lists; storing waitlist signups from the marketing siteYour Content (tasks, transactions, budgets, focus sessions, check-ins, Gro growth state); if you opt in, your focus-room presence (first name, room, session timers); reports you file and your block list; waitlist email addressesAll platforms
Firebase Hosting (Google)Serving the web app and these policy pagesLimited technical request data (such as IP address and timestamps)Web
Firebase Crashlytics (Google)Crash reporting, so we can find and fix bugsCrash traces, device model, and operating-system version, keyed to an install ID (not your identity)Native apps only (not web)
Firebase Performance Monitoring (Google)App performance diagnostics (such as startup and network timing)Performance timings and basic device information, keyed to an install ID (not your identity)Native apps only (not web)
TelemetryDeck (TelemetryDeck GmbH, Germany)Anonymous product analytics, so we can see which features help and where people get stuckAnonymized usage signals only — event names such as “a task was completed” or “a focus session finished”, plus basic device type and app version. Signals carry a one-way hashed, per-install random identifier generated on your device; we receive no name, email, device ID, advertising ID, IP-based profile, or any of Your Content — never the text of a task or the amount of an expense. TelemetryDeck is a privacy-first, GDPR-compliant service that cannot identify youNative apps only (not web)
Firebase App Check (Google)Verifying that requests come from a genuine copy of the appDevice-integrity attestation tokens (short-lived)Native apps only (not web)
Apple (App Store / TestFlight)Distributing the iOS and macOS apps and beta buildsYour App Store account and download data, handled by Apple under Apple's own terms and privacy policyiOS and macOS
NetlifyServing the heygro.app marketing siteLimited technical request data (such as IP address and timestamps)Marketing site only
Hugging Face (model host)One-time download of the optional on-device AI model fileLimited technical request data only — none of Your ContentNative apps only, and only if you enable on-device AI

We do not sell your personal information, and we do not share it for cross-context behavioral advertising (as those terms are defined in the California Consumer Privacy Act). There are no ads in HeyGro. Other users see only what the "Shared Focus Rooms" section describes, and only if you opt in.

We may also disclose information if required by law or legal process, to protect the rights, safety, or property of HeyGro, our users, or others (including investigating abuse of community features), or in connection with a merger, acquisition, or sale of assets — in which case we will notify you of any change in ownership or in how your personal information is used.

8.International Transfers

Your information is processed and stored in the United States, where our infrastructure provider (Google) hosts the Service, and may be processed in other countries where our providers operate. If you use HeyGro from the European Economic Area, the United Kingdom, or Switzerland, your information is transferred to the United States under appropriate safeguards — principally the Standard Contractual Clauses incorporated into Google's Cloud Data Processing Addendum, together with any applicable adequacy mechanisms (such as the EU–US Data Privacy Framework where our providers are certified).

9.Data Retention and Deletion

We keep personal information only as long as it is needed to run the Service for you:

Deleting your account in-app (Settings → Delete account) removes your account and all associated data. If keeping a specific record is required by law (for example, evidence relating to abuse reports), we keep only what the law requires, for only as long as it requires.

10.Your Rights

You are always in control inside the app: you can view and edit your content at any time, delete individual items, use "Reset all data" to erase your content, or use "Delete account" to erase your account and everything in it. You can also email support@heygro.app to exercise any right below. Because guest accounts have no email on file, we verify guest requests through the signed-in session that created the account.

If you are in the EEA or the UK (GDPR / UK GDPR)

You have the right to access your personal data, to rectify it, to have it erased, to restrict or object to processing (including any processing based on legitimate interests), to data portability, and to withdraw consent at any time for anything based on consent (withdrawal doesn't affect processing that already happened). We respond within one month. You also have the right to lodge a complaint with your local supervisory authority — though we'd appreciate the chance to resolve your concern first.

If you are a California resident (CCPA/CPRA)

You have the right to know what personal information we collect, use, and disclose (this policy is that disclosure — the categories are: identifiers such as email and account ID; the user content you enter, including user-entered financial figures; and technical diagnostics not linked to you); to delete it; to correct it; to opt out of sale or sharing (not applicable — we do not sell or share personal information as the CCPA defines those terms); to limit the use of sensitive personal information (the only sensitive personal information we collect is your log-in credentials, used solely to authenticate you — a purpose the CCPA permits without a limit-use option); and to non-discrimination for exercising any right. We respond within 45 days. You may use an authorized agent; we will verify the request through your account or email.

11.Children's Privacy

HeyGro is not directed to children under 13, and you must be at least 13 (or the age of digital consent where you live, if higher) to use it. When you first create an account or start guest mode, we ask you to confirm you meet the minimum age — only that yes/no confirmation is stored; no date of birth is requested or collected.

We do not knowingly collect personal information from anyone under 13. If we learn that we have collected personal information from a child under 13 (per the U.S. Children's Online Privacy Protection Act) or from anyone under the minimum age that applies to them (including under GDPR Article 8), we will delete that information and close the account. If you believe a child has provided us with personal information, contact support@heygro.app and we will act promptly.

Because focus rooms show first names between users, they are protected by a display-name filter, per-person reporting and blocking, and a community agreement — see "Shared Focus Rooms" above.

12.Security

We protect your information with encryption in transit (TLS), authenticated access, deny-by-default database security rules that restrict each user's data to their own account, and Firebase App Check device-integrity verification in the native apps. Our AI features run on-device, which keeps your captured text off third-party AI servers entirely. No method of transmission or storage is completely secure, so we cannot guarantee absolute security — but we work to protect your information and to address vulnerabilities promptly.

13.If a Data Breach Happens

If a security incident affects your personal information, we will notify you and any required regulator without undue delay, in accordance with applicable law (including GDPR Articles 33 and 34 where they apply, and any applicable U.S. federal or state breach-notification rules). The notice will describe what happened, what information was involved, and what we are doing about it.

14.Cookies and Local Storage

The HeyGro apps use only essential local storage on your device: your sign-in session, your preferences, and the other local-only items listed in "Information We Collect." The web app and our marketing site at https://heygro.app likewise use only what is needed to function — the waitlist form stores the email you submit, our hosting providers process standard technical request logs, and the marketing site loads its fonts from Google Fonts (a standard request to Google that does not set cookies). We use no advertising cookies, no analytics cookies, and no tracking pixels anywhere.

15.Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide prominent notice — such as a notice in the app — before the changes take effect, and we will always update the "Last updated" date and version above. Earlier versions are catalogued in our changelog so you can see what changed.

16.Contact Us

If you have questions, requests, or concerns about this Privacy Policy or your data, contact us at support@heygro.app. We read everything.