Scribe Technologies Limited ("HERO", "we", "us" or "our"), a private limited company incorporated in England and Wales under company number 14017176, with its registered office at First Floor, 690 Great West Road, Osterley Village, Isleworth, England, TW7 4PU, operates the HERO platform at myhero.so and app.myhero.so, the HERO desktop application, the HERO REST API and the HERO Model Context Protocol ("MCP") server (together, the "Services").
This policy explains what personal data we collect, how we use it, who we share it with, how long we keep it, and what rights you have. It forms part of, and is incorporated by reference into, our Terms of Use.
1. Scope of this Policy
1.1 Who this applies to
(a) This policy applies to individuals who use the Services, whether as an account holder, as an authorised user under a customer organisation's account, or as a visitor to our websites.
(b) Where an organisation subscribes to the Services and its personnel use them, that organisation is the controller of the content held in its workspaces and we act as its processor. We are the controller of the account, billing, recruitment and website data described in this policy.
(c) Documents created in HERO frequently contain personal data about people who are not our users — counterparties, employees, signatories, individuals named in a contract. For that data the customer organisation is the controller. It, not us, is responsible for having a lawful basis, for telling those individuals how their data is used, and for answering their requests. If you believe a HERO customer holds data about you, contact that organisation; if you cannot identify it, write to us at privacy@myhero.so and we will pass your request on.
2. Data We Collect
2.1 Data you give us
(a) Account data: name, email address, profile picture, organisation name, and role. Authentication and password credentials are handled by Google Firebase Authentication; we never see or store your password. Where you sign in with Google, we receive your Google account identifier and email address from Google rather than a password.
(b) Billing data: billing contact, billing address, VAT number, and subscription plan. Card details are collected and processed by Stripe and are not stored by us.
(c) Customer content: the documents, pages, databases, tables, clauses, defined terms, comments, snapshots, templates and files you create in or upload to your workspaces, including prompts you submit to AI features and the output generated in response.
(d) Signature data: where you use the signature features, the signature you draw or type is stored against your account so that you can reuse it. See section 2.5 for what these features are and are not.
(e) Support and communications: the content of messages you send us, including support requests, demo requests, waitlist and newsletter sign-ups.
(f) Recruitment data: if you apply for a role through our careers page, the name, email address and LinkedIn profile you submit, together with anything else you send us in support of your application. We use it to assess your application (legal basis: steps taken at your request prior to entering a contract, and our legitimate interest in recruiting). We keep it for twelve months after the recruitment round closes so we can consider you for similar roles, unless you ask us to delete it sooner.
2.2 Data we collect automatically
(a) Server access logs: our application servers write a standard access log for every request, containing IP address, timestamp, request method and path, response status, response size, referring URL and user-agent string.
(b) Error and performance data: when something goes wrong, an error report is sent to Sentry, our error-monitoring provider. Reports include the error, a stack trace, the request URL and method, and whether the request was authenticated. Authentication tokens, OAuth tokens, encryption material and client secrets are stripped before the report leaves our servers. We sample a proportion of requests for performance tracing.
(c) Abuse-prevention data: we count requests per IP address to enforce rate limits on sign-in, document creation, exports, table operations and OAuth endpoints.
(d) Local storage on your device: the editor keeps a copy of documents you have opened in your browser's IndexedDB store (and, in the desktop application, on your device) so that the editor loads instantly and tolerates brief network loss. This data stays on your device. Clearing your browser storage, or signing out of the desktop application, removes it.
(e) We do not use third-party product-analytics or advertising trackers, on the HERO application or on our marketing website. The only telemetry leaving our systems is the error monitoring described above. We do not build behavioural profiles of you, and we do not sell or share personal data for advertising. Our marketing website carries a consent banner covering analytics, advertising and personalisation categories, which default to denied — see our Cookie Policy.
(f) Cookies and similar technologies, as described in our Cookie Policy.
2.3 Data from connected accounts
(a) Where you choose to connect a third-party account to HERO, we receive data from that service in accordance with the permissions you grant. Section 3 sets out every account you can connect, every permission we request, and what we do with the data. Google Workspace connections are additionally governed by section 4, which takes precedence over any inconsistent statement in this policy.
2.4 Data reaching third-party AI clients you authorise
(a) HERO can be connected to external AI tools — for example Claude Desktop, Cursor or Claude Code — through the HERO MCP server or an API key you generate in Settings. When you authorise such a client, it can read and write the documents, projects and tables in your workspaces, and the content it reads leaves HERO and is handled by that client and its own model provider under their terms, not ours.
(b) We record an audit entry each time such a client is authorised, refreshed or revoked. You can revoke a client's access at any time in Settings; revoking stops further access but does not reach content the client already received.
2.5 What the signature features are not
(a) The signature features let you draw or type a signature and place it in a document. They do not verify identity, authenticate signers, seal documents against tampering, or produce a signing audit trail or certificate of completion. A signature captured this way is an image or a piece of text stored in your account, not a qualified or advanced electronic signature. Where you need a verified or auditable signature, use a dedicated electronic signature service.
3. Connected Accounts
3.1 How connection works
(a) HERO never accesses a third-party account unless you explicitly authorise it through that provider's own consent screen, which shows exactly which permissions are being requested before you grant them.
(b) Most of what HERO does with a connected account is read-only, searching and reading. Some connections also allow HERO to write: with Gmail, you can save a draft or send a message, and with Google Drive you can save a HERO document into your Drive. The exact permissions requested for each provider, and whether they include write access, are listed in the table below.
(c) HERO never sends a message or writes a file without you confirming that specific action in the moment. Nothing is sent or saved automatically, and neither the AI assistant nor any HERO agent can send from your mailbox or write to your Drive without that confirmation.
(d) HERO never deletes anything in a connected account.
(e) We request only the permissions necessary to deliver the features listed below, and we do not request access for features that are not yet available.
(f) Connections are made by an individual user and apply to that user's account. If you connect a personal account, data from it can be brought into your organisation's workspaces.
3.2 Providers, permissions and what they power
| Provider |
Permission requested |
What HERO accesses |
The feature it powers |
Why a narrower permission is insufficient |
| Google (Gmail) |
https://www.googleapis.com/auth/gmail.readonly |
Read-only access to your messages and threads — headers, snippets, plain-text bodies, labels, and attachment contents. |
HERO's AI assistant can search your mailbox, open a message or a whole thread, and read an attachment, so you can pull the substance of a negotiation or an attached document straight into a draft without leaving HERO. |
gmail.metadata returns headers only and cannot return message bodies or attachments, which is the entire point of the feature. The gmail.addons.* scopes apply only to Google Workspace Add-ons and are not available to a web application. Google offers no read scope between metadata and full read. |
| Google (Gmail) |
https://www.googleapis.com/auth/gmail.compose |
Creating, updating and deleting drafts in your mailbox, and sending messages you have confirmed. |
After the assistant drafts a reply from the context in your HERO document, you can save it as a Gmail draft to finish later, or send it — in both cases only after you review the message and confirm the action. |
gmail.send sends but cannot save a draft, so it cannot support reviewing and finishing a message later. gmail.modify grants read, write and label management across the whole mailbox, which is far broader than composing. gmail.compose is the narrowest scope covering both drafting and sending. |
| Google (Drive) |
https://www.googleapis.com/auth/drive.readonly |
Read-only access to file and folder metadata, and to the text content of Google Docs, Sheets and Slides (exported as text or CSV) and plain-text files. |
HERO's AI assistant can search your Drive, browse folders, and read a document into a draft — for example pulling an existing agreement or a schedule of data into a new HERO document. |
drive.file limits access to files the app itself created or that you pick one at a time through the Google Picker, so it cannot search across the Drive you already have — which is the feature. drive.metadata.readonly returns names and properties but no content. |
| Google (Drive) |
https://www.googleapis.com/auth/drive.file |
Creating files in your Drive, and reading or updating only those files HERO itself created or that you explicitly opened with HERO. |
Saving a finished HERO document into a Drive folder you choose, and updating it there when you revise it in HERO. |
This is already the narrowest write permission Google offers, and we request it in addition to — not instead of — the read permission above, which covers a different feature. drive.file deliberately gives HERO no write access to anything else in your Drive: files it did not create, and that you did not hand to it, cannot be modified. |
| Google (both) |
openid, email |
Your Google account identifier and email address. |
Labels the connection in Settings → Integrations so you can see which account is connected and disconnect the right one. |
Nothing narrower identifies the connected account. We do not request profile. |
| Microsoft (Outlook) |
Mail.Read |
Read-only access to your Outlook messages and their attachments. |
The same mailbox search-and-read features as Gmail, for Outlook and Microsoft 365 accounts. |
Microsoft offers no read scope that returns bodies and attachments without Mail.Read. |
| Microsoft (OneDrive) |
Files.Read.All |
Read-only access to files and folders in your OneDrive and the SharePoint sites you can reach. |
Searching, browsing and reading OneDrive files into a HERO draft. |
Files.Read covers only your own OneDrive and excludes shared and SharePoint-hosted files, which is where most organisational documents sit. |
| Microsoft (both) |
User.Read, openid, email, profile, offline_access |
Your Microsoft account identifier, name and email address; a refresh token. |
Labels the connection in Settings, and keeps it working without asking you to reconnect every hour. |
Microsoft requires offline_access for refresh tokens; the rest is the minimum sign-in set. |
| Dropbox |
files.metadata.read, files.content.read |
Read-only access to file and folder metadata and file contents. |
Searching, browsing and reading Dropbox files into a HERO draft. |
Metadata alone cannot return file content. These are the narrowest read permissions Dropbox offers. |
| Notion |
workspace.read |
Read-only access to the specific pages and databases you select during Notion's own authorisation flow. |
Searching and reading Notion pages into a HERO draft. |
Notion scopes access at the page level during authorisation; you choose what HERO can see, and HERO cannot widen it afterwards. |
3.3 How connected-account data is stored and disconnected
(a) We store the authorisation tokens for each connection, encrypted (see section 9). We do not copy or index the contents of your connected accounts into our own storage. Content is fetched from the provider at the moment the assistant needs it.
(b) Content the assistant fetches does become part of that AI conversation's history, which is stored for a limited period — see section 5.3.
(c) You can disconnect at any time in Settings → Integrations, or from the provider's own account settings. On disconnection we delete the stored tokens immediately and, where the provider supports revocation, revoke them with the provider. Anything you already saved into a document stays in your workspace until you delete it.
3.4 What we do and do not do with connected-account data
(a) These commitments apply to data from every account you connect — Google, Microsoft, Dropbox and Notion alike — and to any data aggregated, anonymised or derived from it.
(b) Limited use. We use it only to provide and improve user-facing features that are visible and prominent within HERO, and only in the ways described in this policy and authorised by you.
(c) No model training. We do not use it to train, fine-tune, develop or improve any artificial intelligence or machine-learning model, whether generalised or personalised, and whether our own or a third party's. There is no exception to this — not for feedback you send us, and not by permission. Where an AI feature processes it to deliver something you asked for, it is sent to our model provider solely to produce that response; we configure those providers not to retain it beyond the request, and our contracts prohibit its use for training.
(d) No sale, no advertising. We do not sell it. We do not transfer or use it for advertising of any kind, including retargeting and personalised or interest-based advertising. We do not use it to determine credit-worthiness or for lending purposes.
(e) No onward transfer, except: to provide or improve user-facing features that are visible and prominent within HERO, and then only with your consent; for security purposes, including investigating abuse; where required to comply with applicable law; or as part of a merger, acquisition or sale of assets, and then only after obtaining your explicit prior consent.
(f) Limited human access. Our personnel do not read it except: where you have given affirmative agreement to us viewing specific messages, files or other data; where necessary for security purposes, including investigating a bug or abuse; where necessary to comply with applicable law; or where the data is aggregated and used for internal operations in accordance with applicable privacy and legal requirements.
(g) Retention. Anything the assistant retrieves becomes part of that conversation's history and is deleted automatically seven days after the conversation was last used, or sooner if you delete it. Every restriction above applies for as long as we hold it. Anything you save into a document is yours and stays in your workspace until you delete it.
3.5 Writing to a connected account
(a) Where a connection includes write access, HERO writes only what you have confirmed, at the moment you confirm it. There is no background or scheduled writing.
(b) A message is only ever sent to the recipients shown to you before you confirm, and a file is only ever written to the location shown to you before you confirm.
(c) Content HERO writes into a connected account is content you created in HERO or approved there. Once written it lives in that account and is governed by that provider's terms, not this policy.
(d) HERO does not delete anything in a connected account, and does not modify anything it did not itself create or that you did not explicitly hand to it.
4. Google User Data
4.1 What this section covers
(a) This section describes how HERO accesses, uses, stores, writes and shares data obtained through Google APIs ("Google User Data"). It applies whenever you authorise HERO to connect to your Google account. Where anything in this section conflicts with another part of this policy, this section prevails.
(b) Google User Data is connected-account data, so every commitment in section 3.4 applies to it in full. This section restates those commitments as they apply to Google and adds what the Google API Services User Data Policy specifically requires. It exists because Google requires this disclosure, not because we protect Google data more than data from any other account you connect.
4.2 Limited use of Google User Data
(a) HERO's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
(b) We use Google User Data only to provide and improve user-facing features that are visible and prominent within HERO, and only in the ways described in this policy and consented to by you.
(c) We do not transfer Google User Data to any third party except: to provide or improve user-facing features that are visible and prominent within HERO, and then only with your consent; for security purposes, including investigating abuse; where required to comply with applicable law; or as part of a merger, acquisition or sale of assets, and then only after obtaining your explicit prior consent.
(d) We do not sell Google User Data. We do not transfer or use it for advertising of any kind, including retargeting and personalised or interest-based advertising. We do not use it to determine credit-worthiness or for lending purposes.
(e) These restrictions apply equally to Google User Data in raw form and to any data aggregated, anonymised or derived from it.
(f) Where you authorise write access, anything HERO writes into Gmail or Drive is written only on your confirmation and only as described in section 3.5. Write access is not used to derive, copy or retain additional Google User Data beyond what section 4.5 permits.
4.3 Google User Data and artificial intelligence
(a) We do not use Google User Data to train, fine-tune, develop or improve any artificial intelligence or machine-learning model, whether generalised or personalised, and whether our own or a third party's. There is no exception to this, including for feedback you send us.
(b) HERO's AI assistant does process Google User Data, because that is what the Gmail and Drive features are for: when you ask the assistant to find or read an email, an attachment or a Drive file, the content it retrieves is sent to our model provider (Anthropic or OpenAI — see section 7) so that a response can be produced. We configure those providers so that the content is not retained by them beyond producing that response, and our contracts with them prohibit its use for model training.
(c) So that you can carry on a conversation across several turns, the assistant's conversation history — including the content it retrieved from Gmail or Drive during that conversation — is stored against your account for seven days from the last time you used that conversation, and is then automatically and permanently deleted. You can delete a conversation sooner from within HERO. This is the only circumstance in which Google User Data is retained by us beyond the request that fetched it, and every restriction in section 4.2 applies to it while it is held.
4.4 Human access to Google User Data
(a) Our personnel do not read Google User Data except: where you have given affirmative agreement to us viewing specific messages, files or other data; where necessary for security purposes, including investigating a bug or abuse; where necessary to comply with applicable law; or where the data is aggregated and used for internal operations in accordance with applicable privacy and legal requirements.
4.5 Retention and revocation
(a) We retain Google User Data only for as long as necessary to deliver the features for which you authorised access, and in accordance with the retention periods in section 8.
(b) You may withdraw authorisation at any time, either within HERO or through the Google Account permissions page at myaccount.google.com/permissions. Withdrawal takes effect immediately and stops any further access by us.
(c) When you withdraw authorisation, disconnect the integration, delete your account, or your organisation's subscription terminates, we delete the stored Google tokens immediately and revoke them with Google. Google User Data held in AI conversation history is deleted on the seven-day cycle described in section 4.3(c), or sooner if you delete the conversation. Google User Data you have saved into a HERO document is yours and stays in your workspace until you delete it. We require any subcontractor to delete Google User Data in its possession, except where retention is required by law.
5. How We Use Personal Data
5.1 Purposes and legal bases
(a) To provide the Services and perform our contract with you: account creation, authentication, hosting your content, real-time collaborative editing, delivering the features you use, and providing support. Legal basis: performance of a contract.
(b) To deliver the AI features you invoke, including sending your prompts and the content you point the assistant at to our model providers. Legal basis: performance of a contract.
(c) To take payment and manage subscriptions. Legal basis: performance of a contract, and compliance with legal obligations for tax and accounting records.
(d) To secure the Services, prevent abuse, enforce rate limits, and investigate incidents. Legal basis: our legitimate interests in protecting the Services and our users.
(e) To diagnose and fix faults using error reports. Legal basis: our legitimate interests in operating a reliable service.
(f) To send service announcements, and marketing where you have consented or where we may lawfully do so. Legal basis: legitimate interests and consent. You can unsubscribe from marketing at any time using the link in the email.
5.2 What we do not do
(a) We do not use the content of your workspaces to train, fine-tune or develop generalised AI or machine-learning models, and we do not permit our model providers to do so. The only exceptions are content you voluntarily send us as feedback, and any use you give us specific prior permission for — and neither exception applies to data from a connected account, which is subject to the absolute prohibition in section 3.4(c).
(b) We do not sell personal data, and we do not use it for advertising.
5.3 AI conversation history
(a) Each conversation with the AI assistant is stored server-side against your account so it can be continued: your prompts, the assistant's replies, the tool calls it made and the results those returned, references to documents you pointed it at, and text extracted from PDFs during the conversation.
(b) Conversations are deleted automatically seven days after they were last used, and can be deleted sooner from within HERO.
(c) Where you supply your own model-provider API key in Settings, your content is sent to that provider under your own account and governed by your agreement with them rather than ours.
6. Sharing and Subprocessors
6.1 Who we share data with
(a) We share personal data with the service providers listed below, who process it on our behalf under written contract and only for the purposes described. We do not sell personal data. We also share data where you direct us to — with a connected account you authorise, or with a third-party AI client you authorise (section 2.4) — and where disclosure is required by law.
| Subprocessor |
Purpose |
Data involved |
Location of processing |
| OVHcloud (OVH US LLC) |
Application hosting — the HERO web app, API, collaboration server, document converter and document-AI service all run here |
All data in transit through the Services, and the primary database — which we run ourselves on this infrastructure using MongoDB Community Edition, not a managed database service |
United States — Vint Hill, Virginia and Hillsboro, Oregon |
| Supabase |
Object storage for uploaded files |
Images, video, audio, PDFs and .docx files you upload |
European Economic Area (Ireland) — this is the only provider not in the US, and is scheduled to migrate to the United States |
| Google (Firebase Authentication) |
Account authentication and password credential storage |
Email address, password credentials, sign-in provider, session tokens |
United States — Firebase Authentication runs only from US data centres and this cannot be changed |
| Google Cloud (Text-to-Speech) |
Read-aloud feature |
The document text you ask HERO to read aloud |
United States (global endpoint) |
| Google Maps Platform |
Address autocomplete and map rendering in location table cells |
The address text you type into a location cell; your IP address, because the Maps script loads in your browser |
United States |
| Anthropic PBC |
Large language model provider for AI features |
Prompts, and the document or connected-account content the assistant needs to answer them |
Stored in the United States; processing may occur in the US, Europe, Asia or Australia |
| OpenAI |
Large language model provider for AI features |
Prompts, and the document or connected-account content the assistant needs to answer them |
United States |
| Brave Software (Brave Search API) |
Web search for the AI assistant |
The search query the assistant constructs, which may contain text drawn from your document |
United States — queries retained by Brave for up to 90 days |
| DuckDuckGo |
Fallback web search for the AI assistant, used when the primary search provider is unavailable |
The search query the assistant constructs, which may contain text drawn from your document |
United States |
| Webflow |
Hosting for the myhero.so marketing website and its forms |
Website visitor logs; the name, email address and message you submit through the contact, demo-request, careers and newsletter forms |
United States |
| Stripe |
Payment processing and subscription billing |
Billing contact and address, card details (collected directly by Stripe), transaction records |
United States |
| Intuit Mailchimp (Marketing and Transactional / Mandrill) |
Transactional email (invitations, account notices) and marketing email |
Name, email address, and the contents of the emails we send you |
United States |
| Sentry (Functional Software, Inc.) |
Error and performance monitoring |
Error details, stack traces, request URL and method, whether the request was authenticated. Tokens and secrets are stripped before sending. |
United States |
(d) Every provider listed above processes personal data in the United States, with one exception: file storage currently sits in the European Economic Area. Our database is not a managed service — we run MongoDB Community Edition ourselves on the hosting infrastructure in the first row, so no database vendor has access to it. Section 6.2 explains what our processing locations mean for you.
(e) The services you can connect under section 3 - Gmail, Outlook, Google Drive, OneDrive, Dropbox, Notion, etc. - are not subprocessors and are deliberately not listed above. A subprocessor is a party we send your data to so it can do something for us. A connected account is the reverse: it is a service you already use, under your own relationship with that provider, which you authorise us to read from. Data flows from it to us, not from us to it, and we never instruct those providers to process anything on our behalf. What we do with what we read is set out in section 3.4.
(f) Google appears in both places, for two unrelated reasons. Google is a subprocessor for authentication, text-to-speech and maps, because we send data to Google for those. Google is separately a connected account for Gmail and Drive, because you can authorise us to read from your own Google account. The two relationships are governed by different sections of this policy.
(b) Real-time collaborative editing runs on servers we operate ourselves. It is not routed through a third-party collaboration service. Our document conversion and document-AI services also run on our own infrastructure.
(c) Two third parties are loaded by your browser rather than called by our servers, and therefore see your IP address when the relevant part of the interface renders: Google Maps Platform (address autocomplete and maps in location table cells) and ui-avatars.com (which draws the generic placeholder avatar shown before you upload a profile picture; we send it no name or other personal data).
(c) We will update this list before adding a new subprocessor that processes personal data.
6.2 International transfers
(a) The Services are hosted in the United States, and all of the providers listed in section 6.1 process personal data there, with one exception: uploaded files are currently stored in the European Economic Area. All other personal data we process — including your documents, tables and AI conversation history — is transferred outside the United Kingdom to the United States.
(b) Transfers to the European Economic Area are covered by the United Kingdom's adequacy regulations, so no additional safeguard is required for them.
(c) For transfers to the United States, we rely on one of the following for each provider, and we have a data processing agreement in place with all of them:
— the UK Extension to the EU–US Data Privacy Framework, where the provider is certified under it; or
— the UK Addendum to the European Commission's Standard Contractual Clauses, or the UK International Data Transfer Agreement, entered into as part of that provider's data processing agreement. Where we rely on this route we also carry out a transfer risk assessment.
(d) You may ask which safeguard applies to any particular provider at privacy@myhero.so.
(e) Our application hosting is provided by OVH US LLC, a US-incorporated entity operating data centres in Virginia and Oregon. It is a separate legal entity from OVHcloud's European operations and is subject to United States law, including the CLOUD Act.
(f) We intend to move file storage to the United States so that all processing sits in one place. When that happens this section will be updated and, because it is a material change, we will give notice under section 12 before it takes effect.
7. AI Model Providers
(a) The AI features are delivered using models operated by Anthropic and OpenAI. When you use an AI feature, the prompt and the content the assistant needs — document text, table data, and anything it retrieves from a connected account — is sent to whichever provider is serving that model.
(b) We configure these providers so that your content is not retained by them beyond producing a response, and our contracts with them prohibit using your content to train their models.
(c) We may change model providers. Where we do, we will update this policy before the change takes effect.
(d) If you supply your own model-provider API key in Settings, requests made with it go to that provider under your own account and are governed by your agreement with them.
(e) Web search and page fetching. The assistant can search the web and fetch the contents of a web page when a task calls for it. When it searches, the query it constructs is sent to our search provider — and because the assistant builds that query from what you asked it, the query can contain text drawn from your document. When it fetches a page, the operator of that website sees the request. Neither happens unless the assistant needs it to answer you.
8. Retention
(a) We keep personal data only for as long as necessary for the purposes described in this policy, and then delete or anonymise it, save where a longer period is required by law. Specific periods:
| Data |
Retention |
| Account, workspace and document content |
For as long as the account is open. After termination, exportable for 30 days, then deleted. |
| Content you delete inside HERO |
Marked deleted immediately and permanently removed from our production systems by an automated sweep that runs hourly and clears anything deleted more than 48 hours earlier. Associated uploaded files are removed at the same time. |
| AI conversation history (including anything retrieved from a connected account during the conversation) |
7 days from last use, then deleted automatically. Deletable sooner by you. |
| AI-generated interim files (for example a filled PDF awaiting download) |
A few hours, then swept automatically. |
| Undo history for changes made by AI or by an external MCP client |
7 days from the last change. |
| Connected-account authorisation tokens |
Until you disconnect, then deleted immediately and revoked with the provider where supported. |
| API keys and MCP tokens you issue |
Until you revoke them. Unused refresh tokens expire after 30 days; a third-party client registration that goes unused for 180 days is removed. |
| Authorisation audit records (which client was granted, refreshed or revoked access, and when) |
180 days. |
| Billing and tax records |
Six years after the end of the accounting period, as required by UK tax law. |
| Server access logs (including IP addresses) |
30 days, then rotated out and deleted. |
| Error and performance reports held by Sentry |
90 days, per Sentry’s retention for our plan. Not adjustable by us. |
| Encrypted database backups |
Taken daily and retained for 30 days, then overwritten. Content you delete is removed from production immediately (see above) but persists in backups until they roll over, so allow up to 30 days for it to disappear entirely. Backups are for disaster recovery and are not restorable per document. |
(b) Where you exercise your right to erasure, we remove the data from our live systems straight away. It may remain in an encrypted backup for up to 30 days until that backup is overwritten on the normal cycle. During that period it is isolated and not used for any purpose.
9. Security
(a) We implement administrative and technical safeguards designed to protect personal data, including:
— Encryption in transit. All traffic between your browser or desktop app and our servers, and between our servers and our providers, uses TLS.
— Encrypted integration tokens. The tokens that let HERO reach your connected accounts are encrypted at rest using AES-256-GCM envelope encryption: each record gets its own data key, which is itself encrypted with a master key held outside the database. Decrypted tokens exist only in memory for the duration of a single request and are never written to disk or logged.
— Hashed credentials. API keys and MCP tokens are stored only as hashes; we cannot recover a token you have lost, only revoke it and issue a new one.
— Secret scrubbing in telemetry. Authentication tokens, OAuth tokens, encryption material and client secrets are stripped from error reports before they leave our servers.
— Access controls on workspaces, projects and documents, enforced server-side on every request, including requests from AI agents and external MCP clients.
— Rate limiting on sign-in and on sensitive operations, to blunt credential-stuffing and abuse.
(b) No system is completely secure, and we cannot guarantee absolute security.
10. Your Rights
10.1 Rights under UK and EU data protection law
(a) You have the right to access your personal data, to have inaccurate data corrected, to have data erased, to restrict or object to processing, to data portability, and to withdraw consent at any time where processing is based on consent.
(b) To exercise any of these rights, or to request deletion of your account and its data, contact our privacy contact at privacy@myhero.so. Account deletion is handled by our team rather than by a self-service button; we will action a verified request within 30 days and will confirm when it is done. Deletion is permanent.
(c) Where your data sits within a customer organisation's workspace, that organisation is the controller of that content. We will direct your request to it, and content belonging to the organisation is not deleted by an individual user's request.
(d) We respond to rights requests within one month. If a request is complex or you have made several, we may extend that by up to two further months and will tell you if we do. We may ask you to verify your identity before we act, and we will not charge you unless a request is manifestly unfounded or excessive.
(e) You have the right to complain to the Information Commissioner's Office at ico.org.uk if you are unhappy with how we have handled your personal data.
11. Children
(a) The Services are intended for business and professional use and are not directed at children. We do not knowingly collect personal data from anyone under 16.
12. Changes to this Policy
(a) We may update this policy from time to time. Where a change is material, we will give notice by email or in-product notification before it takes effect. The date at the top of this page records the most recent update.
13. Contact
(a) Questions about this policy, requests to exercise your rights, and concerns about how we handle personal data all go to our privacy contact at privacy@myhero.so.
(b) We are not required to appoint a Data Protection Officer under Article 37 of the UK GDPR, and we have not appointed one. Privacy matters are handled directly by the company's management.
(c) For anything else, contact us at hello@myhero.so, or write to Scribe Technologies Limited, First Floor, 690 Great West Road, Osterley Village, Isleworth, England, TW7 4PU.