Legal

Privacy Policy.

Plain English. Short. Honest. The version your lawyer can rewrite, but won't have to.

Last updated · 13 June 2026

The short version

HeyOne AI doesn't see, store, or train on your data. We can't. Your agent runs on a machine you control, using an API key you own. The work the agent does goes from your machine to the AI provider you chose. None of it touches us.

This page explains the boring details, including the little bit of data we do collect when you visit this website or email us.

1 · Who we are

"HeyOne AI" is a private AI services business operated from India. The legal entity behind this site is reachable through the contact form. This page covers data practices for the website at heyone.ai and for our service engagements.

2 · What we collect when you visit this website

Almost nothing. This site:

  • Does not use cookies for tracking.
  • Does not run analytics that profile individuals (no GA, no Meta Pixel).
  • Serves every font from our own domain. No font request, and no part of your visit, is sent to Google or any third-party font service.
  • Saves your chosen theme (light / dark / e-ink) in your browser's local storage. That's stored on your device, not ours.

If we ever add aggregate analytics, it'll be a privacy-respecting service (Plausible-style: no cookies, no personal identifiers), and we'll update this page first.

3 · What we collect when you write to us

When you fill the contact form, you choose what to share. Typically: name, email, company, role, and the work you're trying to automate. We use it only to reply to you and run an engagement.

We don't add you to mailing lists. We don't sell, share, or syndicate this. It lives in our email account and our own notes.

4 · What happens during an engagement

While we build your agent, we may receive:

  • Examples you share with us deliberately, sample emails, redacted documents, descriptions of workflows. We store these in our own working notes for the duration of the project.
  • Access credentials only when strictly needed and only via your chosen secret-sharing method. We prefer you to set up agent credentials directly.

Once the agent is deployed on your machine, live data does not flow back to us. We are architecturally not in the loop.

5 · What happens during a Support layer

If you take the Support layer, the agent emits a weekly health report (uptime, accuracy stats, drift signals, usage summary). What's in those reports is your call, we set it up with you. Most customers send us aggregate numbers, not content.

If you ask us to debug a specific failure, you decide what excerpts to share. We don't poll your system. We don't have remote access by default.

6 · The AI provider you choose

Your agent sends prompts and receives responses from a third-party AI provider, OpenAI, Anthropic, Google, or an open-source model you run locally. That provider has its own privacy policy. Most of them, on their API tier, do not train on your inputs by default, but you should verify with your chosen provider directly.

If you need zero cloud LLM exposure, we deploy with a local open-source model on your hardware. No data leaves your building.

7 · How long we keep things

  • Contact emails & project notes: kept while an engagement is live, and for 12 months after, so we can help with follow-up questions. Deleted on request.
  • Working samples you shared with us: deleted within 30 days of engagement end, unless you ask us to keep them for ongoing tuning.
  • Invoices & tax records: kept as long as Indian tax law requires (typically 7 years).

8 · Your rights

You can ask us to:

  • Show you everything we have about you.
  • Correct anything that's wrong.
  • Delete it, except where retention is legally required.
  • Stop emailing you.

Write to us through the contact form. We respond within seven days.

9 · The laws we answer to

India. The Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 govern personal data here. In the Act's language, HeyOne AI is the data fiduciary for the little this website and our engagements collect, and you are the data principal. The notice, purpose limitation, retention and erasure practices on this page are how we meet it, and section 8 is how you exercise your rights. If you're ever unhappy with our answer, you can escalate to the Data Protection Board of India.

EU & UK. If you write to us from the EU or UK, the GDPR / UK GDPR applies. Our lawful basis is legitimate interest when replying to your enquiry, and contract once we work together. You have the same access, correction, erasure and portability rights described above, plus the right to complain to your local supervisory authority.

Everywhere else. From California's CCPA/CPRA to Singapore's PDPA and Australia's Privacy Act, the same promises hold, because we built for the strictest case: we collect almost nothing, we never sell or share personal data, and you can see, correct or delete what little exists by writing to us.

One structural note that makes all of this easier: your agent and your data live on your machines. For engagement data you remain the owner; we only process the samples you deliberately hand us, on your instructions.

10 · Security

Our internal notes live in encrypted-at-rest, MFA-protected accounts. We don't use shared logins. We don't keep customer data on unencrypted devices. We rotate any access we're given when an engagement ends.

See the Trust & security page for the full picture, including the big-name frameworks and what your security team can ask for.

11 · Changes to this policy

If we change anything material, the "Last updated" date at the top moves and we'll email existing customers. Older versions can be requested at any time.

12 · Questions

Write to us through the contact form. A human reads it.

Privacy is
the whole product.

If anything on this page is unclear, ask us. We'll explain, or fix the page.