Privacy
Privacy Policy
How Hey Taby handles data while keeping the core desktop app local-first and account-free.
Effective date: July 29, 2026
1. What this policy covers
This Privacy Policy explains how Hey Taby handles information for heytaby.com, Taby Digital, Taby Physical, downloads, updates, activation, order status pages, support, Discord app features, and linked role verification.
Taby is designed to be local-first. Core productivity content—including your tasks, notes, habits, timers, activity history, local AI answers, and follow-up messages—is stored on your computer by default. It leaves your device only when an optional online feature needs it or you deliberately share it, as described below.
2. Information you provide
- Checkout information, such as email address, name, shipping address, phone number when required for delivery, order details, payment status, and Stripe checkout identifiers.
- Support information, such as messages you send to support@heytaby.com, order lookup details, device details, screenshots, logs, or files you choose to share.
- Discord verification information, such as your Discord user ID, username, linked role status, and any order email or proof you choose to provide for verification.
- Community information you post or send in public communities, Discord, Reddit, Instagram, TikTok, YouTube, X, or similar channels.
3. Information collected automatically
The website may collect basic technical information such as pages visited, referrers, approximate location derived from IP address, device type, browser, operating system, timestamps, performance information, and product analytics events. These analytics are used to understand what works and improve the product.
In analytics-enabled app releases, anonymous app-usage sharing is enabled by default and can be turned off in Settings. It sends a limited set of reviewed product-usage events, such as whether a feature was opened or an item was created, together with app version, platform, timestamps, and a random installation identifier. It does not send task titles, note contents, reminder text, calendar details, AI answers, follow-up messages, email addresses, or account details.
The same setting controls a separate sample containing the first question that starts a local AI conversation. That question is sent verbatim with limited app, platform, locale, and time information under a separate random identifier. It does not include the AI answer, follow-up messages, the conversation history, account details, or the analytics installation identifier.
The website and hosting providers may also process server logs, security events, rate-limit data, API request metadata, and error information needed to keep the service reliable and secure.
4. Local app data
Taby desktop data such as tasks, notes, habits, focus timers, activity history, AI answers, and follow-up messages is stored locally by design. App usage sharing is optional and can be turned off in Settings.
Taby's local AI models and AI runtime operate offline on your device. Prompts, local app context, and model outputs processed by the local AI are not sent to the model developer or provider, and Hey Taby cannot remotely access that local processing.
If you choose Report response, Taby sends the visible conversation and the response-generation context needed to investigate that response. If you also choose to attach diagnostics or submit a diagnostics report, the submission may include app logs, device and update state, recent app context, and environment details. Taby sends this information only after you take the reporting action. Information you voluntarily submit is used only to provide support, investigate the reported problem, maintain security and reliability, and is not used to train or improve a foundational or generalized AI model.
Other online features—such as activation, order status, update checks and downloads, support, or an optional hosted feature—send only the information needed to provide the feature you request.
5. Google Calendar data
Google Calendar is an optional integration. When you connect it, Taby uses Google OAuth to receive your Google account name and email address, your calendar list and calendar metadata, and events from calendars you select. Event data can include titles, descriptions, locations, dates and times, availability and status, and Google event links.
Taby uses this data only to show your selected Google events in Taby's Schedule, help represent calendar availability, and provide the calendar-sync features you choose. If schedule-block sync is enabled, Taby can create, update, or delete corresponding events in the Google calendar you select as the sync target.
Taby connects directly from the desktop app to Google's OAuth and Calendar services. Google OAuth tokens, account details, selected-calendar settings, and cached calendar metadata and events are stored in Taby's local app database on your device; OAuth tokens use operating-system-backed encryption when it is available. Hey Taby does not route Google Calendar content through or store it on Hey Taby servers.
When Google Calendar information is used for AI-assisted planning or scheduling, it is processed by Taby's local, offline AI runtime on your device. The local runtime does not transmit Google Calendar information to the model developer or provider, and Hey Taby cannot remotely access the prompts, Calendar context, or outputs processed locally.
Hey Taby does not transfer raw, aggregated, anonymized, summarized, or otherwise derived Google Calendar data to third-party AI or machine-learning services. Google user data is not used to create, train, test, or improve any foundational or generalized AI or machine-learning model.
Hey Taby does not sell Google user data, share it with advertisers, use it for advertising, or include it in product analytics. Google user data is used only to provide the user-facing Calendar features you request. Hey Taby's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
If you deliberately include Google Calendar information in a support message, screenshot, response report, or diagnostic submission, Hey Taby receives only the information you choose to submit. It is used only to respond to your request or investigate the reported problem; it is not shared with a third-party AI service or used for model training.
You can disconnect Google Calendar in Taby at any time. Disconnecting stops future access and removes the stored Google access and refresh tokens from Taby. Previously cached calendar records may remain only in the local app database until you delete or reset Taby's local app data. You can also revoke Taby's access from your Google Account permissions.
6. How information is used
- To process purchases, preorders, refunds, activation codes, downloads, order status, shipping, and support.
- To operate the website, Discord app features, linked role verification, community support, and security checks.
- To improve landing pages, checkout flows, downloads, app reliability, product features, and support quality.
- To detect abuse, fraud, spam, broken endpoints, payment issues, and security problems.
- To comply with legal, tax, accounting, consumer protection, platform, and payment obligations.
7. Processors and sharing
Hey Taby does not sell your personal information. Information may be shared with service providers that help operate the product, including payment processors, hosting providers, analytics tools, email providers, activation services, Discord, shipping carriers, fraud prevention services, and support tools.
Examples include Stripe for payments, Vercel for hosting and analytics infrastructure, DataFast for website analytics, Resend for transactional email, Supabase or similar storage where used by product workflows, Discord for Discord app and linked role features, and carriers or fulfillment services for shipping.
Google Calendar data is exchanged directly between the Taby desktop app and Google as described in Section 5. Except for information a user deliberately includes in a support or diagnostic submission, it is not shared with the processors listed above or with third-party AI or machine-learning services.
8. Cookies and analytics
The website may use cookies, local storage, or similar technologies for checkout, security, preferences, analytics, and basic site functionality. Some third-party services may set their own cookies or identifiers when their features are used.
You can control cookies in your browser. Blocking some cookies may affect checkout, analytics opt-outs, embedded payment flows, or other site behavior.
9. Retention
Order, payment, tax, fulfillment, refund, activation, and support records are kept as long as needed for the transaction, support, legal compliance, fraud prevention, accounting, and product operations.
Website analytics, anonymous product-usage records, first-question samples, reports, and operational logs currently have no automatic age-based deletion schedule. Local app data—including locally cached Google Calendar data—remains on your device until you delete it or uninstall or reset the app, subject to your own backups and operating system behavior.
10. Security
Hey Taby uses reasonable technical and organizational safeguards for the size and nature of the service. No internet service, device, app, or payment flow can be guaranteed perfectly secure.
You are responsible for keeping your device, email account, Discord account, operating system, and backups secure.
11. International transfers
Hey Taby, customers, service providers, and infrastructure may be located in different countries. Information may be processed where we or our providers operate, subject to appropriate legal safeguards where required.
12. Your choices and rights
You can request access, correction, deletion, export, or restriction of personal information by emailing support@heytaby.com. You can also ask questions about refunds, orders, activation, and Discord verification from the same address.
You control Google Calendar access through Taby's integration settings and your Google Account permissions. Because Google Calendar data is stored locally by Taby rather than in a Hey Taby account, deleting it generally requires disconnecting the integration and deleting or resetting the app's local data on your device.
Some information may need to be retained for legal, security, accounting, payment, tax, dispute, or fraud-prevention reasons. Mandatory privacy rights under your local law still apply.
13. Children
Taby is not directed to children under 13. If you believe a child provided personal information without appropriate permission, contact support@heytaby.com so it can be reviewed.
14. Changes
This Privacy Policy may be updated as Taby, Google Calendar, Discord features, hosted options, analytics, checkout, or support workflows change. The effective date above shows when this version took effect.