Privacy Policy

Last updated: September 18, 2026

Honeyjar AI Inc. (“Honeyjar,” “we,” “us,” or “our”) provides AI-powered tools that support public relations and communications workflows. This Privacy Policy describes how we collect, use, disclose, and safeguard personal information through our online and digital properties that link to this Privacy Policy, including our website, web application, mobile applications, electronic communications, and related services (collectively, the “Service”).

This Privacy Policy describes Honeyjar’s own collection, use, disclosure, and protection of personal information. When Honeyjar processes personal information in Customer Content on behalf of a customer, including while delivering Professional Services inside a customer’s Workspace, that processing is also governed by the applicable Terms of Service, Service Terms, and Data Processing Addendum.

Table of Contents

  1. Our Approach to Privacy and Confidentiality

  2. Personal Information We Collect

  3. Tracking Technologies

  4. How We Use Personal Information

  5. How We Share Personal Information

  6. Your Choices

  7. Other Sites and Services

  8. Security

  9. International Data Transfers

  10. Children and Teens

  11. Changes to This Privacy Policy

  12. Connected Sources and Third-Party Data

  13. How to Contact Us

  14. EU and UK Users

1. Our Approach to Privacy and Confidentiality

Because our customers often use Honeyjar for sensitive PR and client work, we apply privacy and confidentiality practices to support those workflows. These practices help explain how our system is designed and operate in addition to the legal protections described throughout this Privacy Policy:

  • Private data processing: Customer content is processed within each customer’s isolated workspace and is not mixed with other customers’ content.

  • No training on customer content: We use AI partners under agreements that prohibit using customer data to train their models.

  • No fine-tuning or enrichment: Customer files, drafts, media lists, and strategy documents are not used to fine-tune, retrain, or enrich any AI model.

  • Confidentiality by design: Honeyjar does not access or reuse customer content for other customers or for internal training, except as needed to provide the Service or comply with applicable law.

  • Compliance-ready controls: Workspace isolation, permissioning, and access logs allow customers to maintain a controlled environment suitable for sensitive materials.

  • Deletion controls: Customers may delete files or revoke integrations. Revoking a connected source integration removes the authorization credential and stops future ingestion; it does not automatically delete previously ingested data. Previously ingested data is retained in accordance with Honeyjar’s data retention practices described in Section 6.5. Data is permanently deleted within 90 days of a customer-initiated deletion request.

Honeyjar does not sell customer data or share customer content with advertisers or AI providers for their own use.

2. Personal Information We Collect

We may collect personal information in the following ways.

2.1 Information you provide to us

This may include:

  • Contact data such as name, email address, phone number, and billing or mailing address.

  • Demographic data such as city, state, country of residence, and postal code.

  • Profile data including account credentials, employer, job title, biographical details, photographs or avatars, preferences, and links to social media profiles.

  • Communications data from interactions through email, chat, support channels, or social media.

  • Marketing data including preferences for receiving communications and engagement metrics.

  • User-generated content such as prompts, drafts, notes, uploads, media lists, comments, or any other materials you submit through the Service.

  • Call or video recordings of support calls, demos, or similar interactions, if applicable.

  • Other information not specifically listed but used as described in this Privacy Policy or at the point of collection.

2.2 Information we receive from third parties

We may obtain personal information from:

  • Public sources

  • Data providers, brokers, and licensors

  • Service providers that support the Service

  • Joint marketing partners and event co-sponsors

  • Analytics and advertising partners

  • Connected account data from third-party services you authorize, including Gmail, Google Calendar, Outlook, Slack, and meeting transcript providers

  • External signal and public data from licensed data providers, including news sources, journalist and media contact databases, and social signal providers

  • Social media platforms

2.3 Information collected automatically

We, our service providers, and advertising partners may automatically collect:

  • Device data such as operating system, browser type, device model, unique identifiers, IP address, and language settings.

  • Location data (approximate), based on IP address or device settings.

  • Communication interaction data such as email opens or link clicks (using pixel tags or similar technology).

  • Online activity data such as pages viewed, time spent, referring URLs, navigation paths, and access times.

  • Connected Account Data: Gmail message content (subject, sender and recipient addresses, body up to 8,000 characters); Google Calendar event data (title, description, location, attendee email addresses up to 50, organizer address); Outlook mail and calendar data; Slack message text; and meeting audio, transcripts, and notes from meeting providers (transcripts up to 40,000 characters with participant lists).

  • External and Public Signal Data: news articles; journalist and media contact information including professional contact details discovered through platform searches and third-party providers such as RocketReach; social media content from platforms including X (Twitter), TikTok, and LinkedIn; URLs; engagement metrics; and AI-derived sentiment and enrichment data.

  • Derived Data: ambient signals, embeddings, classifications, summaries, action items, routine state, relationship and company context, spokesperson context, provenance and trust records, and activity and decision ledgers generated automatically by the Service.

3. Tracking Technologies

We use, and allow certain third parties to use, cookies, local storage technologies (such as HTML5), web beacons, pixel tags, chat technologies, and session-replay scripts. These technologies help operate, analyze, secure, and personalize the Service. More detail is available in your browser settings and in the “Your Choices” section.

4. How We Use Personal Information

We may use personal information for the purposes described below or as otherwise disclosed at the time of collection.

4.1 Service delivery and operations

To:

  • Provide, operate, and maintain the Service

  • Process subscriptions and transactions

  • Enable security features

  • Personalize the Service and remember preferences

  • Establish and maintain user profiles

  • Communicate about the Service and related events

  • Respond to questions, support requests, and feedback

  • Facilitate invitations and collaboration

  • Collect and publish testimonials (with consent)

  • Detect, prevent, or address fraud or security issues

  • Perform ongoing, automated background ingestion and processing of data from connected sources (Ambient Processing) to generate signals, summaries, tasks, notifications, and other Service outputs, not only when triggered by a user action

  • Provide Professional Services purchased by a customer, including permitting authorized Honeyjar personnel to access and use content in the customer’s Workspace as reasonably necessary to deliver those services.

Access by Honeyjar personnel providing Professional Services is limited to the applicable engagement, subject to role-based access controls, confidentiality obligations, and logging, and may be revoked by the customer. Unless separately authorized by the applicable member, this access does not include an individual member’s private connected Gmail, Slack, calendar, chat history, or other connected-source data.

4.2 Research and development

We may use personal information to analyze and improve the Service and to develop new products and features. We may create aggregated, de-identified, or anonymized data and use or share that data for lawful business purposes. We do not attempt to re-identify de-identified data except to test our processes.

Importantly: Customer files, drafts, and strategy materials are not used to train or adapt AI models.

4.3 Marketing and advertising

We may use personal information to:

  • Send marketing communications

  • Personalize marketing messages

  • Administer events, promotions, and programs

  • Conduct interest-based advertising with third-party ad partners

You can opt out of marketing communications at any time.

4.4 Compliance and protection

We may use personal information to:

  • Comply with laws and lawful requests

  • Protect rights, safety, and property

  • Enforce our terms and policies

  • Conduct internal audits

  • Detect, investigate, or prevent fraud or security incidents

4.5 With your consent

We may use personal information for additional purposes with your consent where required by law.

5. How We Share Personal Information

We may share personal information with the following parties, as well as as otherwise described in this Privacy Policy or at the time of collection.

5.1 Service providers

Third parties that help us operate the Service and our business (e.g., hosting, support, infrastructure, analytics, email delivery, chat functionality, IT, and related services).

5.2 Payment processors

Payment information is processed directly by providers such as Stripe, in accordance with their privacy policies.

5.3 AI infrastructure providers

We use the following third-party AI providers to power AI-assisted features:

  • OpenAI: used for model inference and embeddings, including embeddings of workspace content. Contractually prohibited from training on customer data.

  • Anthropic: used for model inference. Contractually prohibited from training on customer data.

  • xAI (Grok): used for model inference. Contractually prohibited from training on customer data.

  • ElevenLabs: used for voice mode. When a user uses voice mode, microphone audio streams directly from the user’s browser to ElevenLabs for processing. Training on customer audio is disabled in Honeyjar's account settings.

Content-level minimization does not apply to ambient processing pipelines. Gmail message content (up to 8,000 characters), calendar event details including attendee email addresses, Slack message text, and meeting transcripts (up to 40,000 characters with participant lists) are transmitted to AI providers substantially as received. Minimization applies only to the user-identity context block attached to chat turns, which transmits display name and preferred name only; the user’s raw email address and username are not transmitted in that context block.

5.4 Advertising and analytics partners

For interest-based advertising and analytics. We do not share workspace content or confidential materials with these partners.

5.5 Social networks

For integrations, login features, or advertising campaigns.

5.6 Third parties you authorize

If you choose to link or share information with a third-party service or integration.

5.7 Event partners

If you register for an event co-hosted with another organization.

5.8 Professional advisors

Such as lawyers, auditors, banks, and insurers, in connection with professional services.

5.9 Authorities and others

Where required to comply with laws, legal processes, or protect rights and safety.

5.10 Corporate transactions

In connection with a proposed or actual merger, financing, acquisition, sale, reorganization, or similar event.

5.11 Journalist and media contact database

Professional contact information discovered through searches performed on the Service and through third-party data providers (such as RocketReach) may be added to Honeyjar’s shared journalist and media contact database and used to fulfill requests for other Honeyjar customers. Customer-supplied contact data, including contacts imported, uploaded, or manually entered by a customer, is not used to enrich the shared database. Customer-specific notes, relationships, outreach history, media lists, and search history are never shared with other customers.

5.12 Personnel providing Professional Services

Authorized Honeyjar employees and contractors may access personal information and Workspace content as reasonably necessary to provide Professional Services purchased by a customer. Such personnel are subject to confidentiality, security, and use restrictions and may use the information only to perform the applicable services. Unless separately authorized, their access does not include an individual member’s private connected-source data.

6. Your Choices

6.1 Access and update information

You can access and update certain account information through your account settings.

6.2 Marketing communications

You may opt out of marketing emails by using the unsubscribe link in the message or by contacting us.

6.3 Cookies and similar technologies

Most browsers allow you to remove or reject cookies; however, the Service may not function properly without them.

6.4 Declining to provide information

Some information is required to use certain features. If you decline to provide it, those features may not be available.

6.5 Retention

We retain personal information and Customer data for the life of the account, including while the account is inactive, paused, or suspended. Deletion is triggered only by an explicit customer-initiated request, after which data is permanently removed within 90 days (or sooner if required by an executed customer agreement). The following category-specific notes apply:

  • Gmail, Outlook mail, Google Calendar, Outlook Calendar, and Slack data: retained for the life of the account. Disconnecting a connector removes the credential and stops future ingestion but does not delete previously ingested data.

  • Meeting transcripts (Honeyjar’s stored copy): retained for the life of the account.

  • Meeting recordings at Recall (provider copy): Recall currently retains new bot recordings for 7 days on its own systems; this is independent of Honeyjar’s account-level retention of the stored transcript.

  • Derived signals and embeddings: retained for the life of the account and included in the customer deletion lifecycle.

  • Exports: Honeyjar-controlled exports follow the account lifecycle; copies in the customer’s control are outside Honeyjar’s deletion scope.

  • Backup copies: age out per Honeyjar’s backup retention schedule; not restored for ordinary business use after deletion.

Data may be retained longer where required by applicable law, regulation, or an active legal hold.

7. Other Sites and Services

The Service may contain links to third-party websites or may integrate with third-party tools. We do not control these third parties and are not responsible for their practices. We encourage you to review their privacy policies.

8. Security

We implement administrative, technical, and physical safeguards designed to protect personal information, including:

  • Encryption in transit and at rest

  • Workspace isolation

  • Role-based access controls

  • Logging and monitoring

  • Secure development and deployment practices

  • Employee access controls

In addition, the following confidentiality practices apply:

  • Customer content stays within isolated workspaces

  • We do not train AI models on customer data

  • Customer content is not reused for other customers or internal model training

  • Customers can delete files or integrations at any time, subject to backup retention periods and legal obligations

While we work to protect your information, no system is entirely secure.

9. International Data Transfers

We are headquartered in the United States and may use service providers in other countries. This may require transferring personal information to jurisdictions with different data protection laws. Where required, we implement appropriate safeguards for such transfers. Users in Europe may contact us for more information.

10. Children and Teens

The Service is not intended for individuals under 18. If we learn that we have collected personal information from someone under 18 without appropriate consent, we will delete it as required by law.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The “Last updated” date reflects the latest revision. When required by law, we will provide additional notice or seek consent for material changes.

12. Connected Sources and Third-Party Data

When you connect Gmail, Google Calendar, Outlook, Slack, meeting providers, or other third-party sources, the Service ingests and processes data from those sources. That data may include information about individuals who have not directly signed up for Honeyjar, such as email counterparties, meeting attendees, calendar invitees, and Slack participants.

You are responsible for ensuring that you have the authority to connect each source and for providing any legally required notice or consent to third parties whose personal information is processed through connected sources. Recording and transcription consent obligations under applicable law are solely your responsibility.

The meeting bot appears as ’Honeyjar’ in the meeting interface, and platform-level recording and transcription notices remain enabled. Honeyjar does not provide additional notice to meeting participants or email counterparties beyond the product’s visible presence.

Honeyjar processes personal data from connected sources as a service provider acting on your instructions.

13. How to Contact Us

For information regarding our data processing practices, subprocessors, or Data Processing Addendum (DPA), please contact the Honeyjar team at info@honeyjar.ai.

14. EU and UK Users

For users in the European Union, European Economic Area, and United Kingdom, Honeyjar acts as a data processor with respect to personal data you submit or that is processed on your behalf through the Service. You act as the data controller for that personal data. The processing of personal data in connection with the Service is governed by the Data Processing Addendum (DPA) available from Honeyjar on request.

Ambient and continuous processing of connected account data is authorized by your OAuth connector grants and your acceptance of Honeyjar’s Terms of Service. You should ensure that your own privacy notices to end users and third parties accurately describe Honeyjar’s processing of their data.

International transfers of personal data from the EU/EEA and UK to the United States are covered by the applicable transfer mechanism set out in the DPA.

Honeyjar maintains a Subprocessor List covering all third-party sub-processors, including OpenAI, Anthropic, xAI, ElevenLabs, Recall, Granola, Stripe, Postmark, Auth0, and RocketReach. The current Subprocessor List is available from Honeyjar on request at info@honeyjar.ai. Honeyjar will provide reasonable advance notice of material changes to the Subprocessor List.

Privacy Policy

Last updated: September 18, 2026

Honeyjar AI Inc. (“Honeyjar,” “we,” “us,” or “our”) provides AI-powered tools that support public relations and communications workflows. This Privacy Policy describes how we collect, use, disclose, and safeguard personal information through our online and digital properties that link to this Privacy Policy, including our website, web application, mobile applications, electronic communications, and related services (collectively, the “Service”).

This Privacy Policy describes Honeyjar’s own collection, use, disclosure, and protection of personal information. When Honeyjar processes personal information in Customer Content on behalf of a customer, including while delivering Professional Services inside a customer’s Workspace, that processing is also governed by the applicable Terms of Service, Service Terms, and Data Processing Addendum.

Table of Contents

  1. Our Approach to Privacy and Confidentiality

  2. Personal Information We Collect

  3. Tracking Technologies

  4. How We Use Personal Information

  5. How We Share Personal Information

  6. Your Choices

  7. Other Sites and Services

  8. Security

  9. International Data Transfers

  10. Children and Teens

  11. Changes to This Privacy Policy

  12. Connected Sources and Third-Party Data

  13. How to Contact Us

  14. EU and UK Users

1. Our Approach to Privacy and Confidentiality

Because our customers often use Honeyjar for sensitive PR and client work, we apply privacy and confidentiality practices to support those workflows. These practices help explain how our system is designed and operate in addition to the legal protections described throughout this Privacy Policy:

  • Private data processing: Customer content is processed within each customer’s isolated workspace and is not mixed with other customers’ content.

  • No training on customer content: We use AI partners under agreements that prohibit using customer data to train their models.

  • No fine-tuning or enrichment: Customer files, drafts, media lists, and strategy documents are not used to fine-tune, retrain, or enrich any AI model.

  • Confidentiality by design: Honeyjar does not access or reuse customer content for other customers or for internal training, except as needed to provide the Service or comply with applicable law.

  • Compliance-ready controls: Workspace isolation, permissioning, and access logs allow customers to maintain a controlled environment suitable for sensitive materials.

  • Deletion controls: Customers may delete files or revoke integrations. Revoking a connected source integration removes the authorization credential and stops future ingestion; it does not automatically delete previously ingested data. Previously ingested data is retained in accordance with Honeyjar’s data retention practices described in Section 6.5. Data is permanently deleted within 90 days of a customer-initiated deletion request.

Honeyjar does not sell customer data or share customer content with advertisers or AI providers for their own use.

2. Personal Information We Collect

We may collect personal information in the following ways.

2.1 Information you provide to us

This may include:

  • Contact data such as name, email address, phone number, and billing or mailing address.

  • Demographic data such as city, state, country of residence, and postal code.

  • Profile data including account credentials, employer, job title, biographical details, photographs or avatars, preferences, and links to social media profiles.

  • Communications data from interactions through email, chat, support channels, or social media.

  • Marketing data including preferences for receiving communications and engagement metrics.

  • User-generated content such as prompts, drafts, notes, uploads, media lists, comments, or any other materials you submit through the Service.

  • Call or video recordings of support calls, demos, or similar interactions, if applicable.

  • Other information not specifically listed but used as described in this Privacy Policy or at the point of collection.

2.2 Information we receive from third parties

We may obtain personal information from:

  • Public sources

  • Data providers, brokers, and licensors

  • Service providers that support the Service

  • Joint marketing partners and event co-sponsors

  • Analytics and advertising partners

  • Connected account data from third-party services you authorize, including Gmail, Google Calendar, Outlook, Slack, and meeting transcript providers

  • External signal and public data from licensed data providers, including news sources, journalist and media contact databases, and social signal providers

  • Social media platforms

2.3 Information collected automatically

We, our service providers, and advertising partners may automatically collect:

  • Device data such as operating system, browser type, device model, unique identifiers, IP address, and language settings.

  • Location data (approximate), based on IP address or device settings.

  • Communication interaction data such as email opens or link clicks (using pixel tags or similar technology).

  • Online activity data such as pages viewed, time spent, referring URLs, navigation paths, and access times.

  • Connected Account Data: Gmail message content (subject, sender and recipient addresses, body up to 8,000 characters); Google Calendar event data (title, description, location, attendee email addresses up to 50, organizer address); Outlook mail and calendar data; Slack message text; and meeting audio, transcripts, and notes from meeting providers (transcripts up to 40,000 characters with participant lists).

  • External and Public Signal Data: news articles; journalist and media contact information including professional contact details discovered through platform searches and third-party providers such as RocketReach; social media content from platforms including X (Twitter), TikTok, and LinkedIn; URLs; engagement metrics; and AI-derived sentiment and enrichment data.

  • Derived Data: ambient signals, embeddings, classifications, summaries, action items, routine state, relationship and company context, spokesperson context, provenance and trust records, and activity and decision ledgers generated automatically by the Service.

3. Tracking Technologies

We use, and allow certain third parties to use, cookies, local storage technologies (such as HTML5), web beacons, pixel tags, chat technologies, and session-replay scripts. These technologies help operate, analyze, secure, and personalize the Service. More detail is available in your browser settings and in the “Your Choices” section.

4. How We Use Personal Information

We may use personal information for the purposes described below or as otherwise disclosed at the time of collection.

4.1 Service delivery and operations

To:

  • Provide, operate, and maintain the Service

  • Process subscriptions and transactions

  • Enable security features

  • Personalize the Service and remember preferences

  • Establish and maintain user profiles

  • Communicate about the Service and related events

  • Respond to questions, support requests, and feedback

  • Facilitate invitations and collaboration

  • Collect and publish testimonials (with consent)

  • Detect, prevent, or address fraud or security issues

  • Perform ongoing, automated background ingestion and processing of data from connected sources (Ambient Processing) to generate signals, summaries, tasks, notifications, and other Service outputs, not only when triggered by a user action

  • Provide Professional Services purchased by a customer, including permitting authorized Honeyjar personnel to access and use content in the customer’s Workspace as reasonably necessary to deliver those services.

Access by Honeyjar personnel providing Professional Services is limited to the applicable engagement, subject to role-based access controls, confidentiality obligations, and logging, and may be revoked by the customer. Unless separately authorized by the applicable member, this access does not include an individual member’s private connected Gmail, Slack, calendar, chat history, or other connected-source data.

4.2 Research and development

We may use personal information to analyze and improve the Service and to develop new products and features. We may create aggregated, de-identified, or anonymized data and use or share that data for lawful business purposes. We do not attempt to re-identify de-identified data except to test our processes.

Importantly: Customer files, drafts, and strategy materials are not used to train or adapt AI models.

4.3 Marketing and advertising

We may use personal information to:

  • Send marketing communications

  • Personalize marketing messages

  • Administer events, promotions, and programs

  • Conduct interest-based advertising with third-party ad partners

You can opt out of marketing communications at any time.

4.4 Compliance and protection

We may use personal information to:

  • Comply with laws and lawful requests

  • Protect rights, safety, and property

  • Enforce our terms and policies

  • Conduct internal audits

  • Detect, investigate, or prevent fraud or security incidents

4.5 With your consent

We may use personal information for additional purposes with your consent where required by law.

5. How We Share Personal Information

We may share personal information with the following parties, as well as as otherwise described in this Privacy Policy or at the time of collection.

5.1 Service providers

Third parties that help us operate the Service and our business (e.g., hosting, support, infrastructure, analytics, email delivery, chat functionality, IT, and related services).

5.2 Payment processors

Payment information is processed directly by providers such as Stripe, in accordance with their privacy policies.

5.3 AI infrastructure providers

We use the following third-party AI providers to power AI-assisted features:

  • OpenAI: used for model inference and embeddings, including embeddings of workspace content. Contractually prohibited from training on customer data.

  • Anthropic: used for model inference. Contractually prohibited from training on customer data.

  • xAI (Grok): used for model inference. Contractually prohibited from training on customer data.

  • ElevenLabs: used for voice mode. When a user uses voice mode, microphone audio streams directly from the user’s browser to ElevenLabs for processing. Training on customer audio is disabled in Honeyjar's account settings.

Content-level minimization does not apply to ambient processing pipelines. Gmail message content (up to 8,000 characters), calendar event details including attendee email addresses, Slack message text, and meeting transcripts (up to 40,000 characters with participant lists) are transmitted to AI providers substantially as received. Minimization applies only to the user-identity context block attached to chat turns, which transmits display name and preferred name only; the user’s raw email address and username are not transmitted in that context block.

5.4 Advertising and analytics partners

For interest-based advertising and analytics. We do not share workspace content or confidential materials with these partners.

5.5 Social networks

For integrations, login features, or advertising campaigns.

5.6 Third parties you authorize

If you choose to link or share information with a third-party service or integration.

5.7 Event partners

If you register for an event co-hosted with another organization.

5.8 Professional advisors

Such as lawyers, auditors, banks, and insurers, in connection with professional services.

5.9 Authorities and others

Where required to comply with laws, legal processes, or protect rights and safety.

5.10 Corporate transactions

In connection with a proposed or actual merger, financing, acquisition, sale, reorganization, or similar event.

5.11 Journalist and media contact database

Professional contact information discovered through searches performed on the Service and through third-party data providers (such as RocketReach) may be added to Honeyjar’s shared journalist and media contact database and used to fulfill requests for other Honeyjar customers. Customer-supplied contact data, including contacts imported, uploaded, or manually entered by a customer, is not used to enrich the shared database. Customer-specific notes, relationships, outreach history, media lists, and search history are never shared with other customers.

5.12 Personnel providing Professional Services

Authorized Honeyjar employees and contractors may access personal information and Workspace content as reasonably necessary to provide Professional Services purchased by a customer. Such personnel are subject to confidentiality, security, and use restrictions and may use the information only to perform the applicable services. Unless separately authorized, their access does not include an individual member’s private connected-source data.

6. Your Choices

6.1 Access and update information

You can access and update certain account information through your account settings.

6.2 Marketing communications

You may opt out of marketing emails by using the unsubscribe link in the message or by contacting us.

6.3 Cookies and similar technologies

Most browsers allow you to remove or reject cookies; however, the Service may not function properly without them.

6.4 Declining to provide information

Some information is required to use certain features. If you decline to provide it, those features may not be available.

6.5 Retention

We retain personal information and Customer data for the life of the account, including while the account is inactive, paused, or suspended. Deletion is triggered only by an explicit customer-initiated request, after which data is permanently removed within 90 days (or sooner if required by an executed customer agreement). The following category-specific notes apply:

  • Gmail, Outlook mail, Google Calendar, Outlook Calendar, and Slack data: retained for the life of the account. Disconnecting a connector removes the credential and stops future ingestion but does not delete previously ingested data.

  • Meeting transcripts (Honeyjar’s stored copy): retained for the life of the account.

  • Meeting recordings at Recall (provider copy): Recall currently retains new bot recordings for 7 days on its own systems; this is independent of Honeyjar’s account-level retention of the stored transcript.

  • Derived signals and embeddings: retained for the life of the account and included in the customer deletion lifecycle.

  • Exports: Honeyjar-controlled exports follow the account lifecycle; copies in the customer’s control are outside Honeyjar’s deletion scope.

  • Backup copies: age out per Honeyjar’s backup retention schedule; not restored for ordinary business use after deletion.

Data may be retained longer where required by applicable law, regulation, or an active legal hold.

7. Other Sites and Services

The Service may contain links to third-party websites or may integrate with third-party tools. We do not control these third parties and are not responsible for their practices. We encourage you to review their privacy policies.

8. Security

We implement administrative, technical, and physical safeguards designed to protect personal information, including:

  • Encryption in transit and at rest

  • Workspace isolation

  • Role-based access controls

  • Logging and monitoring

  • Secure development and deployment practices

  • Employee access controls

In addition, the following confidentiality practices apply:

  • Customer content stays within isolated workspaces

  • We do not train AI models on customer data

  • Customer content is not reused for other customers or internal model training

  • Customers can delete files or integrations at any time, subject to backup retention periods and legal obligations

While we work to protect your information, no system is entirely secure.

9. International Data Transfers

We are headquartered in the United States and may use service providers in other countries. This may require transferring personal information to jurisdictions with different data protection laws. Where required, we implement appropriate safeguards for such transfers. Users in Europe may contact us for more information.

10. Children and Teens

The Service is not intended for individuals under 18. If we learn that we have collected personal information from someone under 18 without appropriate consent, we will delete it as required by law.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The “Last updated” date reflects the latest revision. When required by law, we will provide additional notice or seek consent for material changes.

12. Connected Sources and Third-Party Data

When you connect Gmail, Google Calendar, Outlook, Slack, meeting providers, or other third-party sources, the Service ingests and processes data from those sources. That data may include information about individuals who have not directly signed up for Honeyjar, such as email counterparties, meeting attendees, calendar invitees, and Slack participants.

You are responsible for ensuring that you have the authority to connect each source and for providing any legally required notice or consent to third parties whose personal information is processed through connected sources. Recording and transcription consent obligations under applicable law are solely your responsibility.

The meeting bot appears as ’Honeyjar’ in the meeting interface, and platform-level recording and transcription notices remain enabled. Honeyjar does not provide additional notice to meeting participants or email counterparties beyond the product’s visible presence.

Honeyjar processes personal data from connected sources as a service provider acting on your instructions.

13. How to Contact Us

For information regarding our data processing practices, subprocessors, or Data Processing Addendum (DPA), please contact the Honeyjar team at info@honeyjar.ai.

14. EU and UK Users

For users in the European Union, European Economic Area, and United Kingdom, Honeyjar acts as a data processor with respect to personal data you submit or that is processed on your behalf through the Service. You act as the data controller for that personal data. The processing of personal data in connection with the Service is governed by the Data Processing Addendum (DPA) available from Honeyjar on request.

Ambient and continuous processing of connected account data is authorized by your OAuth connector grants and your acceptance of Honeyjar’s Terms of Service. You should ensure that your own privacy notices to end users and third parties accurately describe Honeyjar’s processing of their data.

International transfers of personal data from the EU/EEA and UK to the United States are covered by the applicable transfer mechanism set out in the DPA.

Honeyjar maintains a Subprocessor List covering all third-party sub-processors, including OpenAI, Anthropic, xAI, ElevenLabs, Recall, Granola, Stripe, Postmark, Auth0, and RocketReach. The current Subprocessor List is available from Honeyjar on request at info@honeyjar.ai. Honeyjar will provide reasonable advance notice of material changes to the Subprocessor List.