heytappr.

privacy policy

effective 21 july 2026

the short version

your personal memory, routines, memos, goals, learned habits, lives on your phone. heytappr does not save conversation history, but it sends audio, screen text, interface structure, and screenshots when needed to openai to answer you or operate the phone. deep research can sync structured facts and reports to our convex backend. hosted reports delete within 24 hours, and the app's "wipe device data" control deletes other device-linked cloud research data. billing records are kept separately. we never sell your personal data and never see your card number or upi credentials.

permissions heytappr uses

heytappr asks for microphone access for voice input, accessibility access to read and operate visible app interfaces, display over other apps for the floating notch and visual guidance, and notification permission for proactive updates. android controls these permissions. you can revoke them in system settings, but the related features will stop working.

what stays on your phone

heytappr's personal memory, your routines, memos, goals, and the habits it learns, is stored on-device in the app's storage for proactive features. heytappr does not keep a conversation history on the device or in our convex backend. uninstalling the app deletes its on-device data. content sent to service providers is handled under their own retention terms, described below.

what leaves your phone and why

  • ai processing. to answer your questions and run the agent, heytappr sends your screen's structure and text, screenshots when needed, and your voice audio to openai for processing. openai states that api data is not used to train its models by default. its default api abuse-monitoring logs may retain inputs and outputs for up to 30 days, unless a longer period is legally required. see openai's api data controls.
  • cloud deep research. when you ask for a deep-research report, your question plus structured facts extracted on the phone are sent to heytappr's convex backend. depending on the task, those facts can include screen observations, marketplace listing statistics, subscription details, app-usage summaries, document titles and summaries, or investment holdings. raw screenshots are sent to openai when needed for AI processing, not stored in our convex backend. cloud data is keyed by a random per-install device id.
  • analytics. we collect product usage events via posthog, in the app and on this website, to understand reliability and feature usage. app telemetry includes the text of your voice conversations with heytappr (what you said and what it replied) and the text of proactive suggestions it showed you, so we can improve answer quality. it omits typed text in other apps and screen-extracted text. it can also include device or session identifiers, coarse app categories, action types, timing, token counts, errors, and interaction events. the website waitlist form stores the email you enter and the page it came from in heytappr's backend.
  • payments. if you subscribe to heytappr premium, checkout and payment data are processed by dodo payments as merchant of record, under dodo payments' own privacy policy. heytappr never sees or stores your card number or upi credentials.

what we store on our servers

  • deep-research requests and structured context keyed to your random device id, including the categories listed above. generated reports use hard-to-guess private links and the hosted report file auto-deletes within 24 hours.
  • the email you entered on the website waitlist, if any.
  • if you subscribe: your subscription status and checkout email, payment-provider customer and subscription references, amount, currency, renewal date, entitlement dates, and billing event records, keyed to your device id.

how long we keep it

  • hosted deep-research report files automatically delete within 24 hours. related questions and structured research context remain until you use "wipe device data" or ask us to delete them.
  • waitlist emails remain until they are no longer needed for access and product communications, or until you ask us to delete yours.
  • billing and transaction records are retained as needed to provide access, handle disputes, prevent fraud, and meet tax, accounting, and other legal obligations.
  • openai, posthog, dodo payments, and other service providers apply their own retention periods to data they process for us.

your controls

  • the app's "wipe device data" control deletes device-linked observations, listings, subscription findings, app-usage summaries, document summaries, holdings, research requests, and hosted reports from our convex backend. it does not delete your heytappr premium billing record, billing event history, waitlist email, provider-side logs, or on-device data.
  • uninstalling the app deletes all on-device data.
  • you can cancel your subscription anytime, and in india you can also cancel the upi autopay / e-mandate through your bank or upi app to stop future charges.
  • for any other deletion or data request, email shrit@heytappr.com.

what we never do

  • we never sell your personal data.
  • we never see or store card numbers or upi credentials.
  • we do not save a conversation history in the heytappr app or our convex backend. openai may retain api inputs and outputs under the provider policy described above.
  • we never store raw screenshots in our convex backend, though screenshots may be sent directly to openai for processing.

children

heytappr premium purchases are for adults, you must be 18 or older to subscribe. heytappr is not directed at children, and we don't knowingly collect personal data from children.

changes

if we change how we handle your data, we'll update this policy and its effective date here. material changes will be flagged more visibly.

contact

privacy questions, or a deletion request? email shrit@heytappr.com.