← hYYa ai

Privacy Policy

Last updated: June 2026 · hYYa ai by Hassaan (hYYa Apps)

Overview

Privacy is built into hYYa ai at the architecture level — not as an afterthought. hYYa Vault mode never sends any data anywhere. hYYa Cloud mode transmits only what is necessary to produce your AI response, nothing more. hYYa Cloud is encrypted in transit (TLS 1.3) and at rest, but it is not end-to-end encrypted — cloud AI requires the model provider to read your prompt to generate a reply. For fully on-device privacy with nothing sent anywhere, use hYYa Vault.

1. hYYa Vault Mode — What hYYa Collects

Nothing. All AI inference, conversation history, memory, and documents are processed and stored entirely on your device. No data is transmitted to hYYa servers or any third party. Deleting the app removes everything.

hYYa Vault and Google user data

hYYa Vault is the native app (in development — coming to macOS first) that runs AI entirely on your device. Its optional Local Connections feature can link your own Google account — Gmail (read-only), Google Calendar (read-only), and the Google Drive files you select.

hYYa Vault's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

  • Data accessed via Local Connections is retrieved directly from Google to your device and processed by an on-device AI model.
  • It is never transmitted to or stored on hYYa servers, never used for advertising, and never shared with anyone.
  • Connected-account content is never included in any web search query or any other outbound request from the app.
  • You can revoke access at any time in your Google Account settings or from within the app.

2. hYYa Cloud Mode — What hYYa Collects

When you use hYYa Cloud mode, hYYa collects:
  • Email address — stored in Supabase to manage your account and send sign-in links.
  • Conversation messages — routed via OpenRouter to the AI model provider that generates your response (e.g. Anthropic, Google, xAI, DeepSeek). These providers do not use your messages to train their models. If you add your own provider API key (BYOK), that key is encrypted at rest on hYYa’s servers (AES-256), never shown again after you save it, and used only to send your messages directly to that provider under your own key — across chat and DataLens. You can remove a saved key at any time in Settings → API Keys.
  • DataLens documents — if you upload documents to a DataLens, their text is stored in Supabase and sent to Google’s embedding API so hYYa can search and reason over them. Used only to power your DataLens.
hYYa does not collect your photo library, contacts, location, or any data you have not explicitly shared in a conversation.

3. Payments

All billing is handled by Polar as Merchant of Record. hYYa ai never sees or stores your card number, bank details, or payment credentials. Polar collects and processes payment data under their own privacy policy. You will receive receipts directly from Polar.

4. Third-Party Services

  • Vercel — hosts the hYYa web app and processes your requests in transit; it does not retain your conversation content.
  • Supabase — hYYa’s database and file storage: your account, conversations, memory, and DataLens documents are stored here, protected by row-level security.
  • OpenRouter — routes your hYYa Cloud conversation messages to the AI model provider that generates your response. OpenRouter does not retain your prompts, and hYYa configures routing to exclude providers that train on your data.
  • AI model providers (such as Anthropic, Google, xAI, DeepSeek, and Moonshot) — receive your message content in order to generate the response. They are not sent your hYYa account identity, and do not use your messages to train their models.
  • Google — for DataLens, generates embeddings for the documents you upload and reads (OCR) any images you add, so they can be searched. Used for that processing only.
  • Composio — only if you turn on Connections: securely stores the authorization for the apps you connect (e.g. Gmail, Calendar, Outlook, Notion, Drive) and relays read-only data into your chat at your request. SOC 2 Type 2; tokens are encrypted and isolated per user. Inactive unless you connect an app.
  • Google (Gemini Live) — only if you use voice: real-time voice runs through Google’s Gemini Live service. Audio streams directly between your browser and Google and does not pass through hYYa’s servers; the voice assistant also uses Google Search to answer real-time questions. Active only during a voice session.
  • Polar — processes subscription payments as Merchant of Record. No card data touches hYYa servers.
  • Resend — delivers account and billing emails (sign-in links, subscription notices).

5. Data hYYa Never Sells

Your data is never sold, rented, or shared with third parties for marketing or advertising purposes. Ever.

6. Security

All data in transit uses TLS 1.3. Authentication is passwordless — sign-in uses a one-time code emailed to you, and no passwords are stored. Supabase enforces row-level security so each user can only access their own data.

7. Your Rights

You can delete your account and all associated data at any time from the Settings screen, or by emailing h [at] hyya.com. Deletion from the Settings screen is immediate — your conversations, files, and account data are erased right away and your subscription is cancelled; emailed requests are actioned promptly.

8. Subscription End & Data Retention

If your paid subscription ends — whether you cancel or it lapses — you can still sign in; your account simply moves to the free tier. Your conversations and DataLenses are retained for 60 days so you can resume exactly where you left off if you reactivate, and hYYa sends reminder emails during that window, including a final notice before deletion. After 60 days without reactivation, your conversations and DataLenses are permanently deleted. You can reactivate anytime from the pricing page, or delete your data sooner from the Settings screen.

9. Age Requirement

hYYa ai is intended for users 18 years of age or older. hYYa does not knowingly collect data from anyone under 18. If hYYa learns it has collected data from a user under 18, that data is deleted promptly.

10. Changes to This Policy

This policy may be updated as the service evolves. Material changes will be notified via email or in-app notice. Continued use after changes constitutes acceptance.

11. Contact

Privacy questions or data requests: h [at] hyya.com.
Terms of ServiceRefund PolicyHome