Privacy Policy

Effective date: 2026-09-08

HypoOS LLC ("HypoOS," "we," "us," "our"). Applies to: hypoos.com and the HypoOS application.

1. What HypoOS is

A conversational personal-assistant app for tasks, reminders, notes, expenses, a personal profile, a daily summary, and — if connected — Google Calendar.

2. Information we collect

Account

Email address and authentication identifiers.

Provided directly

Tasks, reminders, notes, expenses you create; optional profile details (name, wake/sleep time, work schedule, recurring responsibilities, reminder preferences, daily-summary preference); the text of your conversations with the assistant.

Google Calendar events (only if you connect it)

HypoOS requests these Google OAuth scopes, nothing broader:

ScopeWhat it allows
https://www.googleapis.com/auth/calendar.eventsView, create, update, and delete events on your Google calendars. HypoOS only reads and writes your primary calendar. This scope does not grant access to your calendar settings, Gmail, Drive, Contacts, or any other Google service.
https://www.googleapis.com/auth/userinfo.email, openidConfirm which Google account is connected.

Specifically accessed: Google Calendar event titles, descriptions, locations, and start/end times. We do not access Gmail, Drive, Contacts, or any other Google service.

3. Why it's accessed

Solely to power the calendar feature: answering "what's on my calendar today?" and creating/updating/deleting events you describe in chat. Never for advertising or profiling.

4. How it's used

  • To carry out the specific action you asked for (read, create, update, or delete an event).
  • To generate the assistant's reply: HypoOS uses OpenAI's API to understand your request and compose a response. When your request involves your calendar, the relevant event details are sent to OpenAI's API as part of that one request, solely to generate that response. Per OpenAI's API terms, this data is not used to train their models. OpenAI acts only as our data processor for this purpose.

5. How it's stored

WhatWhereHow longEncrypted?
Google access & refresh tokensOur database (Supabase/PostgreSQL). Stored in a table with no direct client access at all — only our server-side code can read it, and that code always scopes every query to your own account.Until you disconnect Google Calendar or delete your accountEncrypted at rest by our database provider's underlying storage (standard for our infrastructure); we do not apply a separate layer of encryption on top of that
Calendar event data used to answer a read request (e.g. "what's on my calendar today?")Processed in-memory to generate that one response; not stored afterwardNot retained beyond that requestTransmitted over HTTPS/TLS
Calendar events HypoOS creates on your behalfA small local record (title, time, etc.) kept alongside the tokens above, only so HypoOS can later edit or delete that same eventDeleted automatically when the event itself is deleted, or when you disconnect Google CalendarEncrypted at rest by our database provider's underlying storage; row-level security scoped to your account
Your account data (tasks, reminders, notes, expenses, profile)Our database (Supabase/PostgreSQL)Until you delete the item or accountEncrypted at rest

6. Is it shared with anyone?

We do not sell it, and we do not share it with advertisers or data brokers. It is shared only with:

  • Google — the Calendar API itself is how we read/write your events, with your consent.
  • OpenAI — strictly to generate the assistant's response, as our data processor (Section 4).
  • Supabase — our database provider, storing the data above on our behalf.

No other disclosure, except where required by law.

7. Limited Use disclosure

HypoOS's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

8. Revoke access / delete data

  • Disconnect Google Calendar anytime from HypoOS account settings — immediately and permanently deletes your stored Google tokens.
  • Or revoke directly from your Google Account permissions page.
  • Delete your account and data: email founder@hypoos.com. Deleted within 30 days of a verified request.

9. Contact

Privacy questions: founder@hypoos.com