Privacy notice

Your memory is not an advertising profile.

This plain-language notice describes the current product behavior. It will be updated when providers, retention, account controls or legal terms materially change. Last updated 4 September 2026.

What hippoOS stores

Account and authentication information; the sources you deliberately submit; derived readings, wiki pages, structured observations and provenance; owner corrections and settings; connected-app grants; metadata from mail and calendar accounts you choose to connect (described below); and limited operational events.

Capture telemetry is designed to contain counts, booleans, timings and random identifiers—not note text, titles, instructions or filenames. Retrieval history and optional feedback remain owner-scoped.

Why it is processed

To preserve, convert, search, organize and answer from your material; sync it across your devices; deliver features you enable; secure the service; diagnose failures; and improve retrieval quality from explicit owner feedback.

hippoOS does not use a public feed or advertising system and does not sell your personal knowledge.

Connected mail and calendar accounts (Google, Microsoft)

You may connect one or more Google or Microsoft accounts so hippoOS can show who is waiting on you. This is optional, off by default, and started only by you from Apps & connections. You choose per account whether to connect mail, calendar, or both, and you can connect several accounts at once.

What we ask for. From Google we request read-only access to Gmail (the gmail.readonly scope: the sync stores message metadata, and the ask feature described below may read the text of an unanswered message you received), read-only access to calendar events (the calendar.events.readonly scope), and your email address so the account can be labelled. From Microsoft we request the equivalent delegated Mail.Read and Calendars.Read permissions. hippoOS never requests permission to send, modify, delete or move mail or events.

What we store. For mail: sender and recipient names and addresses, subject line, date, direction, whether attachments exist, provider message and thread identifiers, whether the provider flagged it as bulk mail, and a link back to the message in your provider. For an inbound message you have not answered, additionally a short derived record: the kind of ask (meeting, introduction, request, information), a one-sentence summary, and a date if the message named one. For calendar: event title, start and end times, attendee addresses, status and a link back to the event. hippoOS does not store message bodies, snippets, attachments or event descriptions. The metadata sync only requests header and metadata fields from the provider; the ask feature fetches the text of an unanswered inbound message once, passes it to the model, and discards it — it is never written to a database, file or log.

How it is used. Solely to show you your own correspondence and meetings, to surface follow-ups you may owe or be owed, and to tell you in one line what an unanswered email asks of you. Messages and events from people recorded in a Cortex are tracked against that contact; other people who wrote you are listed by name and address on Apps & connections so you can decide whether to record them, and nothing about them is tracked until you do. The metadata sync makes no model calls. The ask feature sends the text of an unanswered inbound message (never sent mail, answered mail, or bulk mail) to the AI model configured for your account to classify it; the model provider processes it under its own terms and hippoOS keeps only the derived one-line result. It is never used for advertising, never sold, never used to train models, and never shared with anyone other than the infrastructure providers named below that host the service.

How it is protected. Your provider refresh token is encrypted with AES-256-GCM and is readable only by the background sync service; the web application never sees or stores a token. Indexed metadata is a rolling window: rows older than 120 days are pruned automatically. The provider remains the system of record; hippoOS holds a disposable index.

How to stop. Disconnect any account from Apps & connections. This revokes the grant at the provider, deletes our copy of the token and every indexed row for that account, and leaves only a content-free record that a disconnection happened and when. You can also revoke access at any time from your Google account permissions or Microsoft account settings. Deleting your hippoOS account removes all connector data with it.

hippoOS’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Service providers

Supabase provides authentication, Postgres and object storage; Railway hosts product services; OpenRouter routes configured model tasks; and Resend handles enabled inbound or outbound email. Google and Microsoft are the sources of any mail and calendar metadata you choose to connect; they receive only the authorization request you approve. Each provider receives the information needed for its role.

A fuller subprocessor and data-flow register is part of the approved public Trust work. Provider-specific retention and model-training terms depend on the configured accounts and will not be overstated here.

Retention and control

Retained source originals remain until the owner explicitly Discards them. Unkept Ask conversation payloads expire 30 days after their latest turn; Keep exempts a conversation. Disposable capture and retrieval events are pruned after 30 days. Connected mail and calendar metadata is pruned after 120 days and removed entirely on disconnect.

Account deletion is recoverable for 30 days: after you request it, your account keeps working and can be restored until the deadline, when everything — every Cortex, retained original, correction, derived index entry, connected-account token and index, and your sign-in — is physically purged. A separately confirmed “Delete now” skips the wait. Deleted data can therefore persist up to 30 days after a deletion request; only a content-free completion receipt (counts and dates, never content) outlives the purge.

Owners can export any Cortex or download an account-wide portable ZIP, delete Ask sessions, revoke connected apps, disconnect mail and calendar accounts, Discard selected sources and request, restore or immediately complete account deletion from the account page.

Questions and requests

Contact support@hippoos.co about access, correction, export, deletion or privacy. Where an in-product control already exists, using it is normally the fastest path.