Privacy Policy
Effective date: 2026-09-08
HypoOS LLC ("HypoOS," "we," "us," "our"). Applies to: hypoos.com and the HypoOS application.
1. What HypoOS is
A conversational personal-assistant app for tasks, reminders, notes, expenses, a personal profile, a daily summary, and — if connected — Google Calendar.
2. Information we collect
Account
Email address and authentication identifiers.
Provided directly
Tasks, reminders, notes, expenses you create; optional profile details (name, wake/sleep time, work schedule, recurring responsibilities, reminder preferences, daily-summary preference); the text of your conversations with the assistant.
Google Calendar events (only if you connect it)
HypoOS requests these Google OAuth scopes, nothing broader:
| Scope | What it allows |
|---|---|
| https://www.googleapis.com/auth/calendar.events | View, create, update, and delete events on your Google calendars. HypoOS only reads and writes your primary calendar. This scope does not grant access to your calendar settings, Gmail, Drive, Contacts, or any other Google service. |
| https://www.googleapis.com/auth/userinfo.email, openid | Confirm which Google account is connected. |
Specifically accessed: Google Calendar event titles, descriptions, locations, and start/end times. We do not access Gmail, Drive, Contacts, or any other Google service.
3. Why it's accessed
Solely to power the calendar feature: answering "what's on my calendar today?" and creating/updating/deleting events you describe in chat. Never for advertising or profiling.
4. How it's used
- To carry out the specific action you asked for (read, create, update, or delete an event).
- To generate the assistant's reply: HypoOS uses OpenAI's API to understand your request and compose a response. When your request involves your calendar, the relevant event details are sent to OpenAI's API as part of that one request, solely to generate that response. Per OpenAI's API terms, this data is not used to train their models. OpenAI acts only as our data processor for this purpose.
5. How it's stored
| What | Where | How long | Encrypted? |
|---|---|---|---|
| Google access & refresh tokens | Our database (Supabase/PostgreSQL). Stored in a table with no direct client access at all — only our server-side code can read it, and that code always scopes every query to your own account. | Until you disconnect Google Calendar or delete your account | Encrypted at rest by our database provider's underlying storage (standard for our infrastructure); we do not apply a separate layer of encryption on top of that |
| Calendar event data used to answer a read request (e.g. "what's on my calendar today?") | Processed in-memory to generate that one response; not stored afterward | Not retained beyond that request | Transmitted over HTTPS/TLS |
| Calendar events HypoOS creates on your behalf | A small local record (title, time, etc.) kept alongside the tokens above, only so HypoOS can later edit or delete that same event | Deleted automatically when the event itself is deleted, or when you disconnect Google Calendar | Encrypted at rest by our database provider's underlying storage; row-level security scoped to your account |
| Your account data (tasks, reminders, notes, expenses, profile) | Our database (Supabase/PostgreSQL) | Until you delete the item or account | Encrypted at rest |
6. Is it shared with anyone?
We do not sell it, and we do not share it with advertisers or data brokers. It is shared only with:
- Google — the Calendar API itself is how we read/write your events, with your consent.
- OpenAI — strictly to generate the assistant's response, as our data processor (Section 4).
- Supabase — our database provider, storing the data above on our behalf.
No other disclosure, except where required by law.
7. Limited Use disclosure
HypoOS's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
8. Revoke access / delete data
- Disconnect Google Calendar anytime from HypoOS account settings — immediately and permanently deletes your stored Google tokens.
- Or revoke directly from your Google Account permissions page.
- Delete your account and data: email founder@hypoos.com. Deleted within 30 days of a verified request.
9. Contact
Privacy questions: founder@hypoos.com