Privacy
This page explains what Hedwig collects when you use it, why, who processes it, how long it's kept, and how to delete it. "We" means the people who run Hedwig.
What we collect
- Your Hedwig sign-in: the email address and name of the Google account you sign in with.
- For each Google account you connect: its email address, name, and profile picture address, the permissions you granted, and its Google tokens, which are encrypted.
- Mail from the last 180 days when you connect an account, and new mail as it arrives: senders, recipients, subjects, dates, labels, message text, and the names and sizes of attachments.
- Your Google Calendars and their events, including titles, times, guests, locations, descriptions, and meeting links.
- Your Google contacts and the people you've emailed: names, email addresses, and photo addresses, used to complete addresses as you type.
- Your Gmail labels, send-as addresses, and signatures.
- What you create in Hedwig: settings, splits, snippets, scheduled mail, snoozes, reminders, the Posts Hedwig writes for you, and MCP tokens, which are stored only as a hash.
- When semantic search is on: embeddings of synced messages, which are lists of numbers that describe what a message is about.
- Sync records: when each sync ran, how many items it changed, and any error. They never contain subjects, message text, or tokens.
- If you request access: the email address you enter.
How we use it
Hedwig uses this data only to show you your mail, calendars, and contacts, to act on them when you ask (send, archive, reply to an invite, create an event), and to build The Post and the features you turn on.
Hedwig's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Hedwig does not use Google user data for advertising, does not sell it, and does not use it to train general-purpose AI models.
No person at Hedwig reads your mail unless you ask us to for support, it's needed for security, or the law requires it.
AI features
Summaries, reply drafts, sorting new mail, spotting replies you owe, plain-language search, and parts of The Post send the text they need, such as one thread, to Anthropic's API.
Semantic search sends message text to OpenAI's API to create embeddings.
Each AI feature can be turned off in Settings, under AI. Hedwig works fully without them.
Under their API terms, Anthropic and OpenAI don't train their models on this data. They may keep it for up to 30 days to detect abuse, then delete it.
Processors
These companies process data for us, only to run Hedwig:
- Supabase stores the database and handles sign-in. The database is hosted on AWS in the United States (us-east-1).
- Vercel hosts the app and runs its server code.
- Anthropic runs the AI features listed above.
- OpenAI creates the embeddings for semantic search.
- Google provides your mail, calendar, and contacts. Google Cloud Pub/Sub tells Hedwig when new mail arrives; those notices carry only the account's address and a change number.
- Stripe processes payments when you subscribe. Card numbers go straight to Stripe; Hedwig never sees or stores them.
How long we keep it
Hedwig copies the last 180 days of mail when you connect an account, up to 2,500 threads, then adds new mail as it arrives. Older mail stays in Gmail and isn't copied.
Everything else is kept while the account it came from is connected and follows Google: when you delete something in Gmail or Google Calendar, Hedwig deletes its copy at the next sync.
Deleting your data
Disconnect an account in Settings, under Accounts. Hedwig revokes its access at Google and immediately deletes that account's mail, events, contacts, labels, and signatures from the database.
Delete your Hedwig account in Settings, under Data. Hedwig does the same for every account, then deletes your profile, settings, Posts, and sign-in. Nothing in Gmail or Google Calendar is changed.
Deleted data can remain in encrypted database backups until they expire, within 7 days.
You can also remove Hedwig's access from your Google Account's third-party connections page. Hedwig then stops syncing that account until you reconnect it.
Settings, under Data, also lets you download a JSON copy of everything Hedwig stores about you, except Google tokens.
Contact
Questions about privacy, or a request about your data: edwardhkim2025@gmail.com.