Privacy Policy
Last updated: 2026-08-26.
Hey Susan (“Susan,” “we,” “us”) is an AI assistant for pregnancy and new-parent life, delivered as a chat experience in our native iOS/Android app and web app. Telegram is no longer a live way to chat with Susan; a very small number of legacy accounts may still have a stored Telegram identifier from before this change (see “What we collect” below). This policy explains what we collect, why, who processes it, and the choices you have. Plain-English summary first; detail below.
Short version
- We don't sell your data, and we don't use ad-tracking technology — no advertisers, no data brokers.
- What you tell Susan is used to provide the service to you — to track, remind, answer, and check in — nothing else.
- Susan is an AI assistant, not a medical service. See our medical disclaimer, and where her health information comes from.
- To write Susan's replies, we send your messages and a summary of your profile and logs to Google's Gemini API. We ask your permission in the app before anything is sent, and you can withdraw it at any time. See AI processing below for exactly what is sent.
- You can delete your data at any time by emailing hi@heysusan.app.
Who we are
Hey Susan is operated by Humanoid AI Inc. (British Columbia, Canada), the data controller for the purposes of this policy. Contact: hi@heysusan.app.
What we collect
On the waitlist page (before you sign up):
- The email address you enter in the form.
- If you selected one, the parenting stage you are in (expecting / newborn / etc.).
- UTM parameters from the link you arrived on (so we know whether Reddit, search, or a friend sent you).
- Your browser user-agent and HTTP referer, stored alongside your waitlist row for spam investigation. Not shared.
On our website, before you sign up or join the waitlist:
- Which pages you looked at, and when. When you open a page on our marketing site — the home page, the blog, and so on — we record the page address (without anything after the
?), the time, the UTM parameters from the link you arrived on, and the referring address your browser sends. We do not record your IP address and we do not record your browser user-agent for this. Pages inside the app itself are not counted here. - A random visitor number, stored in a cookie. To tell one visitor from another — and, if you later create an account, to connect that account to the visits that led to it — we set a first-party cookie called
hs_vidcontaining a randomly generated number. It is not derived from anything about you or your device, it means nothing outside our own records, it is never sent to anyone else, and page scripts cannot read it. It lasts 90 days, and clearing your cookies removes it. We use it only to work out how many people visit and what share of them go on to sign up. If you create an account, everything we recorded under that number is deleted when you delete your data. - Not if you are in the EU, the UK, or Quebec. Visitors located in those places are not counted and are not given the cookie at all. Nothing is stored for them.
- We also use Vercel Web Analytics for overall traffic totals. That one sets no cookie and identifies visitors by a hash discarded after 24 hours — see the sub-processor list below.
When you use Susan (the chat assistant):
- Your account identifier (an in-app account; a very small number of legacy accounts, no longer active, were identified by a Telegram chat ID) and the name your account shows, so we can hold a conversation with you.
- The name or nickname you ask us to call you, and the name or nickname you choose for your baby, so messages and reminders can feel personal.
- The messages you send Susan, and her replies. (For HeyBeNice!
/tellrewrites, see the HeyBeNice! section below — the rewrite itself is not stored as text; we keep only a kindness score and category flags. If you choose to have Susan deliver a rewrite to a linked partner, see “Delivering to a partner” below for what that involves.) - The baby- and parent-care information you choose to log — feeds, diapers, sleep, growth, milestones, medications, and similar — and the times you log them.
- Durable details you tell Susan about your baby — for example a condition you report (such as eczema or reflux), an allergy, a preference, or a development milestone — so she can remember them in future conversations instead of asking again, and occasionally note one on your Today screen alongside your own logs when it may be relevant. We store these as things you reported, never as a medical diagnosis, and they are removed when you reset or delete your data.
- Durable details you tell Susan about your household or routine, when you volunteer them — for example who else regularly cares for your baby (a partner, grandparent, or nanny), a recurring schedule (such as a daycare day), or a household pet — so she can remember them and follow up naturally, the same way she remembers a detail about your baby. We store only what you tell us, never infer a household member’s identity from anywhere else, and these are removed when you reset or delete your data.
- Durable patterns Susan learns from your OWN logs over time — for example a typical bottle size, nap count, or usual solids time — so she can remember your baby’s rhythms instead of recalculating them from scratch every time. These are ordinary patterns, not medical facts, always framed as “usually,” never a guarantee, and they are removed when you reset or delete your data.
- A record of feeling-words you use about yourself in conversation with Susan (for example if you say you feel overwhelmed, exhausted, or guilty), so she can follow up with more care and continuity over time. We store these as things you said, in your own words, never as a diagnosis or clinical assessment of any kind (we never label anything “depression,” “anxiety,” or similar), we keep them for about 180 days rather than indefinitely, and they are removed when you reset or delete your data.
- Your approximate location and/or time zone, so we can show times in your local clock and surface the right regional emergency and support resources.
- Usage metadata (e.g. counts of messages and features used) to operate the service and keep costs sustainable.
- How you first found us. This is recorded once, when your account is created — not only on the waitlist page: the UTM parameters from the link you originally arrived on (source, medium, campaign, content) and the first page you landed on, both read back from the first-touch cookies your browser already carried in, plus the referring address your browser sends with the sign-up request itself and the time we recorded it. We store it on your account record and keep it for as long as the account exists, so we can tell whether Reddit, search, an app store, or a friend sent you. We read it only ourselves and only in aggregate, to see which channels work; it is never sold, never shared with advertisers or data brokers, and it is removed when you delete your data. At the same moment we also record which version of Susan you signed up on — the iPhone or iPad app, the Android app, or a web browser — worked out from the browser user-agent (the identification line your device sends with the sign-up request). If your device sends nothing we recognise, we record that we could not tell, rather than guessing. We keep only that one word plus a short note of how we worked it out; we do not keep the user-agent line itself on your account record — it is read and discarded. (On the waitlist form described above, separately, the user-agent is stored with your waitlist row for spam investigation.) At the same moment we also store the
hs_vidvisitor number described above, if your browser carried one, so the pages you looked at before signing up are connected to your account. That link exists so we can tell what share of visitors become members; it is removed, along with those page records, when you delete your data. - How you move through the app — which screens you open, which buttons and menus you use, in what order, and where you stop partway through setup. We use this to see where the app is confusing, to fix it, and to work out what actually went wrong if you report a problem. We record the action, never what you typed or the values you chose — so we log that you opened the birthday picker, never the birthday itself. We keep this for about 30 days rather than indefinitely, and it is removed when you reset or delete your data.
- If you send in-app feedback or a bug report, the note you write, any tags you select, your app build version, and — only if you choose to attach one — a screenshot of the app. Screenshots can incidentally contain visible baby or family information (for example a photo of a rash, or a screen showing a child’s name); we route the note (and any attached screenshot) to our internal team via a private Telegram channel so we can fix the issue, and we keep the underlying report on file for our own tracking.
- We may send limited account identifiers (such as your display name) to our internal team via a private Telegram channel to monitor new signups and operate the service.
AI processing — Google's Gemini API
Susan is not a person. Her replies are generated by an artificial-intelligence model run by Google LLC (“Google”), which we access through the Gemini API. Google is a separate company acting as our service provider (a processor) for this purpose. This section sets out exactly what we send them, why, and what they may do with it.
We ask first
Before your first message is sent, the app shows you a screen naming Google and listing what will be shared, and you must tick a box and tap “Agree and continue” to proceed. Nothing is sent to Google until you do. If you decline, Susan's chat stays off and the rest of the app — tracking, reminders, charts, exports — keeps working. You can withdraw your permission at any time in the app under More → Privacy & AI; from that moment nothing further is sent.
What we send
- The message you send Susan, and up to your last 8 messages in that conversation, so her reply makes sense in context.
- A summary of your profile: the name you gave us, your baby's name, sex and age (or your pregnancy stage and due date), who else regularly helps care for your baby, the goals you selected, your chosen language, and the coaching style you picked.
- The last 24 hours of what you logged — feeds, sleep, diapers, growth, milestones, medications and similar — together with durable details you asked Susan to remember (for example a condition you reported, an allergy, or a usual bottle size).
- Separately, so Susan can search your own chat history by meaning, your messages are turned into numerical representations (embeddings) by the same provider under the same terms.
What we never send
- Your email address, your password, or any payment details.
- Your precise location. Susan may be told your city or time zone; she is never sent GPS coordinates.
- Photos, screenshots or files — including a screenshot you attach to a bug report, which goes only to our own support team and never to the model.
What Google may do with it
- Generate the reply, and produce the embeddings described above. That is the only purpose for which we send it.
- Hey Susan uses the paid tier of the Gemini API. Google's published Gemini API Additional Terms of Service state, under “Paid Services — How Google Uses Your Data,” that when you use Paid Services, including the paid quota of the Gemini API, Google does not use your prompts or responses to improve its products. Those terms describe limited retention for detecting and preventing violations of Google's Prohibited Use Policy and for any required legal or regulatory disclosures.
- Google processes this data as our processor under Google's Data Processing Addendum (Products Where Google is a Data Processor), which the Gemini API terms above apply to paid use. Under that addendum Google processes the data on our instructions and for no independent purpose of its own, maintains technical and organisational security measures, holds its personnel to confidentiality obligations, notifies us of a data incident promptly and without undue delay, and deletes the data at the end of the term. We have reviewed those commitments and consider them to provide protection for your data equivalent to the protection described in this policy.
- Google's own handling of data is described in the Google Privacy Policy.
- We do not sell your data, share it with advertisers, or use ad-tracking technology, and we do not permit Google to do so with what we send them.
Where it goes
Requests to the Gemini API are made to Google's servers, which may process the data outside Canada, including in the United States. See “International processing” below.
What this means for you
Susan can be wrong, and she is not a clinician. Please do not send information you would not want processed by a third-party AI service, and see our medical disclaimer and the sources behind her health information.
HeyBeNice! (kinder-message drafting)
You tap a “HeyBeNice: Tell <name>” shortcut in the app, which fills in the message composer for you (the underlying /tell text command still works if you type it directly, but the tap shortcut is the primary way to start a HeyBeNice! message today); the AI rewrites your message into a kinder version. By default, Susan hands that draft back to you to copy and send yourself.
- Delivering to a partner (optional). If you have a partner linked through Family sharing, you can ask Susan to deliver the kinder draft to them for you instead of copying it yourself. Nothing goes out until you tap to confirm sending. Delivery uses a two-step consent gate, both inside the app: first, the recipient must have separately given a one-time okay to receive messages this way at all; second, on top of that, every single message they receive is held back behind its own “Accept & read” tap — nothing is shown to them until they tap to accept that specific message, and every message names Susan as the go-between and lets them reveal exactly what you originally typed. They can decline any single message, or block all future ones, at any time. Delivery happens inside the app (as a push notification and an in-app card) — it no longer uses Telegram. Without a linked, consenting partner, HeyBeNice! stays copy-yourself only.
- What we store. The original and the rewrite are processed in the moment (by our LLM provider, below) and are not stored as text afterward, other than passing through the delivery message itself if you choose to have Susan deliver it. What we keep on our own systems is numbers and flags only — a kindness score and safety/category flags, with timestamps — so Susan can reflect trends back to you.
- Crisis routing. If a draft signals threats, abuse, or crisis, Susan won’t coach it into a sendable message and routes you to support resources instead.
- Agreement records. When you accept our Terms of Service, we record the acceptance — account identifier, terms version, surface, and time. The same applies to a partner’s one-time okay to receive relayed messages. These records are proof of agreement and may be retained after account deletion as part of the minimal legal records described under “How long we keep it.”
How we use it
- To provide the service — track what you log, send reminders and check-ins, and answer your questions.
- To remember your conversations — Susan keeps your chat history so she can recall things you've talked about (for example, a topic you raised earlier in the week) and follow up helpfully. To search that memory by meaning, your messages are turned into numerical representations (embeddings) by our LLM provider (see sub-processors below) under the same paid, no-training terms. This memory is used only within your own chat — or your household's, if you choose to link a family member's account — and deleting your account deletes it.
- To generate Susan's replies, your messages are processed by our LLM provider (see sub-processors below). We use the paid API tier, whose terms exclude using customer data for model training.
- To know when to back off — if you reply to one of Susan's proactive messages (a check-in or reflection she sends on her own, not in answer to something you asked), that reply may be automatically reviewed for signs you were upset or disagreed with it. We use this only to stop sending that kind of message to your household going forward; rarely, we may also pause the feature for everyone while we look into it. This review is done by our LLM provider (see sub-processors below), the same as your other messages.
- To keep you safe — if a message indicates a crisis, we route you to appropriate emergency and support resources.
- To operate, debug, and improve the service. We do not sell your data, share it with advertisers, or use ad-tracking technology.
Google Calendar (optional connection)
Connecting your Google Calendar is entirely optional. Hey Susan works fully without it, and nothing below applies unless you choose to connect it yourself from the app.
- What we ask for. One scope only:
https://www.googleapis.com/auth/calendar.events.owned— events you own on your own calendar. We never request access to your Gmail, contacts, files, or any other Google service, and we never request the broader calendar-management scopes. - What we access. Only your primary calendar. Reading happens solely when you tap “Yes” on a specific request in the chat (for example, to check whether a check-up is already booked), and only for the time window shown to you in that request. Writing happens solely when you tap “Yes” on a specific proposed event. There is no “always allow”: every read and every write needs its own tap, and Susan never reads or writes your calendar in the background.
- What we do with it. Calendar data is used only to show you the answer you asked for, or to create the one event you approved. We do not store copies of your calendar events beyond what is needed to complete the request you approved.
- What we never do. We never use Google user data to train, retrain, or improve any AI or machine-learning model — including generalised or foundation models. We never sell it, never transfer it to advertisers or data brokers, and never use it for advertising or profiling. We do not transfer Google user data to others except as needed to provide or improve this feature at your request, for security purposes, or to comply with applicable law.
- Limited Use. Hey Susan's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- How to disconnect. Disconnect at any time in the app (More tab → Google Calendar), which revokes our access and deletes the stored authorisation and any pending approval requests. You can also revoke it directly at myaccount.google.com/permissions. Disconnecting stops any further access; it does not delete events already on your calendar, because those are yours.
- How the authorisation is stored. Your Google authorisation tokens are stored encrypted, and are used only to act on a request you approved.
Who processes your data (sub-processors)
We use a small set of vetted providers, each bound by a data-processing agreement:
- Telegram — no longer used to chat with Susan or to deliver HeyBeNice! messages; it now serves only our internal team’s private channel for feedback, bug reports, and signup alerts (see above). A very small number of legacy accounts may still have a stored Telegram identifier from before this change.
- Google (Gemini API) — our LLM provider; your messages, a summary of your profile and logs, and embeddings of your messages are processed to generate Susan's replies. We ask your permission in the app before anything is sent. See AI processing — Google's Gemini API above for the full detail.
- Google (Search / Places) — used only if you ask Susan for local activities or classes near you. We send the city you told us and a generic activity keyword (for example "baby music class Vancouver BC"). We never send your child's name, birth date, health information, or your precise location. Results are unverified listings, not recommendations.
- Google (Calendar API) — used only if you choose to connect your Google Calendar, and only on a per-request tap. See “Google Calendar (optional connection)” above for exactly what is accessed and the Limited Use commitment.
- Open-Meteo — a weather service, used only for the same local-activity feature, to suggest indoor options in bad weather. It receives a public city name and that city's centre coordinates — never your own location.
- Supabase — database hosting for your account and logged data.
- Vercel — application hosting.
- Apple App Store / Google Play — no paid plans are live yet. When they launch, billing for the native app will go through Apple’s and Google’s own in-app purchase systems, as required by their store policies; Hey Susan does not see or store your card details.
How we protect it
Your data is stored in a database with row-level security enabled; application access uses a restricted service role, and the public web client cannot read or write your rows. We limit access to what is needed to run the service.
How long we keep it
We keep your account data while your account is active. When you ask us to delete it, we remove your account and associated data. Some minimal records may be retained where required for legal, security, or accounting reasons.
The website visit records described under “On our website, before you sign up” are kept for at most 180 days and then deleted automatically, whether or not you ever created an account. If you do have an account, they are also deleted immediately when you delete your data, without waiting for that window.
Your choices and rights
- Access / export — ask us for a copy of your data.
- Deletion — delete your account and all associated data at any time, right in the app: open the app, go to More → Delete account, and confirm. This permanently removes your account and logged data (feeds, sleep, growth records, milestones, conversation history, and more) — no email or phone call needed. If you'd rather not use the app, you can also ask us to delete your account by emailing hi@heysusan.app.
- Correction — ask us to correct inaccurate information.
- Depending on where you live (e.g. EEA/UK, California, Canada), you may have additional rights; contact us to exercise them.
Children's privacy
Hey Susan is for parents and caregivers, who must be adults. When you create an account you confirm that you are 18 or older (or the age of majority where you live, if that is older) and that you are a parent or caregiver. The information you log is about your baby or child and is entered by you, the parent. Hey Susan is not directed to children and we do not knowingly collect personal information from children under 13. If we learn that a child under 13 has created an account, we will delete that account and its data. If you believe a child has provided us with personal information, contact us at hi@heysusan.app and we will delete it.
International processing
We are based in Canada and our providers may process data in Canada, the United States, and other countries. Where required, transfers are covered by appropriate safeguards.
Changes to this policy
We'll update this page when our practices change and revise the “last updated” line above. Material changes will be communicated before they take effect.
Contact
Questions about privacy → hi@heysusan.app.