Privacy Policy
Last updated: pre-launch draft (under final review with counsel).
Hey Susan (“Susan,” “we,” “us”) is an AI assistant for pregnancy and new-parent life, delivered as a messaging-app chat. This policy explains what we collect, why, who processes it, and the choices you have. Plain-English summary first; detail below.
Short version
- We don't sell your data, and we don't use ad-tracking technology — no advertisers, no data brokers.
- What you tell Susan is used to provide the service to you — to track, remind, answer, and check in — nothing else.
- Susan is an AI assistant, not a medical service. See our medical disclaimer.
- You can delete your data at any time by emailing hi@heysusan.app.
Who we are
Hey Susan is operated by Humanoid AI Inc. (British Columbia, Canada), the data controller for the purposes of this policy. Contact: hi@heysusan.app.
What we collect
On the waitlist page (before you sign up):
- The email address you enter in the form.
- If you selected one, the parenting stage you are in (expecting / newborn / etc.).
- UTM parameters from the link you arrived on (so we know whether Reddit, search, or a friend sent you).
- Your browser user-agent and HTTP referer, stored alongside your waitlist row for spam investigation. Not shared.
When you use Susan (the chat assistant):
- Your messaging-app account identifier (e.g. your Telegram chat ID) and the name your account shows, so we can hold a conversation with you.
- The name or nickname you ask us to call you, and the name or nickname you choose for your baby, so messages and reminders can feel personal.
- The messages you send Susan, and her replies. (For HeyBeNice!
/tellrewrites, see the HeyBeNice! section below — the rewrite is processed in the moment and not stored as text; we keep only a kindness score and category flags.) - The baby- and parent-care information you choose to log — feeds, diapers, sleep, growth, milestones, medications, and similar — and the times you log them.
- Durable details you tell Susan about your baby — for example a condition you report (such as eczema or reflux), an allergy, a preference, or a development milestone — so she can remember them in future conversations instead of asking again. We store these as things you reported, never as a medical diagnosis, and they are removed when you reset or delete your data.
- Durable details you tell Susan about your household or routine, when you volunteer them — for example who else regularly cares for your baby (a partner, grandparent, or nanny), a recurring schedule (such as a daycare day), or a household pet — so she can remember them and follow up naturally, the same way she remembers a detail about your baby. We store only what you tell us, never infer a household member’s identity from anywhere else, and these are removed when you reset or delete your data.
- Durable patterns Susan learns from your OWN logs over time — for example a typical bottle size, nap count, or usual solids time — so she can remember your baby’s rhythms instead of recalculating them from scratch every time. These are ordinary patterns, not medical facts, always framed as “usually,” never a guarantee, and they are removed when you reset or delete your data.
- Your approximate location and/or time zone, so we can show times in your local clock and surface the right regional emergency and support resources.
- Usage metadata (e.g. counts of messages and features used) to operate the service and keep costs sustainable.
- If you send in-app feedback or a bug report, the note you write, any tags you select, your app build version, and — only if you choose to attach one — a screenshot of the app. Screenshots can incidentally contain visible baby or family information (for example a photo of a rash, or a screen showing a child’s name); we route the note (and any attached screenshot) to our internal team via a private Telegram channel so we can fix the issue, and we keep the underlying report on file for our own tracking.
- We may send limited account identifiers (such as your display name) to our internal team via a private Telegram channel to monitor new signups and operate the service.
HeyBeNice! (kinder-message drafting)
You type /tell followed by what you want to say; the AI rewrites your message into a kinder version and hands the draft back to you to copy and send yourself — Susan delivers nothing to anyone.
- What we store. The original and the rewrite are processed in the moment (by our LLM provider, below) and are not stored as text afterward. What we keep is numbers and flags only — a kindness score and safety/category flags, with timestamps — so Susan can reflect trends back to you.
- Crisis routing. If a draft signals threats, abuse, or crisis, Susan won’t coach it into a sendable message and routes you to support resources instead.
- Agreement records. When you accept our Terms of Service, we record the acceptance — account identifier, terms version, surface, and time. These records are proof of agreement and may be retained after account deletion as part of the minimal legal records described under “How long we keep it.”
How we use it
- To provide the service — track what you log, send reminders and check-ins, and answer your questions.
- To remember your conversations — Susan keeps your chat history so she can recall things you've talked about (for example, a topic you raised earlier in the week) and follow up helpfully. To search that memory by meaning, your messages are turned into numerical representations (embeddings) by our LLM provider (see sub-processors below) under the same paid, no-training terms. This memory is used only within your own chat — or your household's, if you choose to link a family member's account — and deleting your account deletes it.
- To generate Susan's replies, your messages are processed by our LLM provider (see sub-processors below). We use the paid API tier, whose terms exclude using customer data for model training.
- To keep you safe — if a message indicates a crisis, we route you to appropriate emergency and support resources.
- To operate, debug, and improve the service. We do not sell your data, share it with advertisers, or use ad-tracking technology.
Who processes your data (sub-processors)
We use a small set of vetted providers, each bound by a data-processing agreement:
- Telegram — the messaging platform Susan runs on (message transport).
- Google (Gemini / Vertex AI) — our LLM provider; your messages are processed to generate Susan's replies.
- Google (Search / Places) — used only if you ask Susan for local activities or classes near you. We send the city you told us and a generic activity keyword (for example "baby music class Vancouver BC"). We never send your child's name, birth date, health information, or your precise location. Results are unverified listings, not recommendations.
- Open-Meteo — a weather service, used only for the same local-activity feature, to suggest indoor options in bad weather. It receives a public city name and that city's centre coordinates — never your own location.
- Supabase — database hosting for your account and logged data.
- Vercel — application hosting.
- Stripe — payment processing, when paid plans launch (card details go directly to Stripe; we never store them).
How we protect it
Your data is stored in a database with row-level security enabled; application access uses a restricted service role, and the public web client cannot read or write your rows. We limit access to what is needed to run the service.
How long we keep it
We keep your account data while your account is active. When you ask us to delete it, we remove your account and associated data. Some minimal records may be retained where required for legal, security, or accounting reasons.
Your choices and rights
- Access / export — ask us for a copy of your data.
- Deletion — delete your account and all associated data at any time by emailing hi@heysusan.app.
- Correction — ask us to correct inaccurate information.
- Depending on where you live (e.g. EEA/UK, California, Canada), you may have additional rights; contact us to exercise them.
Children's privacy
Hey Susan is for parents and caregivers, who must be adults. The information you log is about your baby or child and is entered by you, the parent. We do not knowingly collect personal information directly from children.
International processing
We are based in Canada and our providers may process data in Canada, the United States, and other countries. Where required, transfers are covered by appropriate safeguards.
Changes to this policy
We'll update this page when our practices change and revise the “last updated” line above. Material changes will be communicated before they take effect.
Contact
Questions about privacy → hi@heysusan.app.