Heed

Privacy Policy

Last updated October 6, 2026

This policy explains what information Heed collects, how we use it and the choices you have. It covers the website at heed.sh, the Heed app, Atlas (the AI assistant inside Heed) and the public booking pages that Heed users share.

Heed is run by Arif Dogan, based in Germany ("Heed", "we", "us"). For anything in this policy, write to [email protected].

Who is responsible for your data

For your Heed account, your Google connection and the website, we are the data controller.

The records a team keeps in its workspace (companies, contacts, deals, notes and emails) belong to that team. For those records, the team's company is the controller and we process them on its behalf, only to run the service for it.

What we collect

Account information. Your name, work email, password (stored as a one-way hash), job title, phone number if you add it, time zone and profile photo. If you sign in with Google, we receive your name, email address and Google profile photo.

Workspace data. Everything you and your teammates add to Heed: companies, contacts, deals, pipelines, tasks, notes, comments, playbook cards, meeting notes and settings.

Gmail and Google Calendar data, only if you connect them. Connecting Google is optional and each person decides for themselves. What we read and keep is described in "How Heed uses Google user data" below.

People who book a meeting. When someone books a meeting through a Heed booking page, we collect their name, email address, the time they chose and their answers to the host's questions, and pass them to the host.

Waitlist. If you join the waitlist, we keep your name, email address and company.

Email open and click tracking. If a Heed user turns on "Track opens and clicks" for an email they send, the email contains a small image and its links go through heed.sh. We record when the email was opened and when a link was clicked, and show this to the sender.

Sequence emails. When a team sends an email sequence, we send it on the team's behalf through Amazon SES from a domain the team owns and has verified. For each email we keep the recipient's address, when it was sent and what Amazon SES reports back (delivered, bounced or marked as spam), never its content. Every sequence email has an unsubscribe link that opens a short page on heed.sh. We keep a suppression list of addresses that unsubscribed, bounced or complained, so they are never emailed again: unsubscribes apply to the team they came from, and bounces and spam complaints apply to every Heed workspace. Each team also enters its company postal address, which goes in the email footer.

Technical data. Our servers log requests (IP address, browser, pages requested and errors) to keep Heed secure and working.

How Heed uses Google user data

Heed asks for Google access in two separate steps.

Sign in with Google asks for your name, email address and profile photo (openid, email and profile). We use them to sign you in, to match you to your account and to show your photo.

Connect Gmail and Calendar is a separate, optional step in Settings. It asks for:

  • Gmail (gmail.modify). We read the email in your mailbox to show your inbox inside Heed, to log customer emails on the right company, contact and deal, and to suggest when a thread looks like a new deal. When a contact answers one of your sequence emails, we use the reply to stop that sequence, and Atlas reads it once to sort it (for example interested or out of office) and keeps only that label and a one-line reason. We send the emails and replies you write or approve in Heed. We archive, mark as read or unread, and label messages when you choose those actions in Heed. We never delete your email.
  • Google Calendar (calendar.readonly and calendar.events). We read your events to show your meetings, prepare meeting briefs, log meetings with customers and check when you are free for your booking pages. We create, update and cancel events, with Google Meet links, when someone books, reschedules or cancels through your booking page.

What we store from Gmail: for each email we log on a record, we keep the sender and recipients, the subject, Gmail's short preview of the message, the date and the Gmail message and thread IDs. Full messages are read from Gmail when you open them in Heed and are not stored. If you turn on writing style learning, we read some of your sent emails once to write a short description of how you write, and we keep only that description.

You stay in control:

  • You can exclude email domains and Gmail labels, or mark a single thread private. Excluded email that was already logged is removed from Heed.
  • Admins can't read anyone else's inbox, private threads or privacy settings.
  • You can disconnect Google at any time in Settings. We then revoke Heed's access with Google and stop reading your mail and calendar. Emails and meetings already logged on records stay in your workspace until you or your team delete them.

Limited Use. Heed's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:

  • We use Google user data only to provide and improve the features you use in Heed that you can see.
  • We don't use Google user data for advertising, and we don't sell it.
  • We don't use Google user data to train or improve general AI or machine learning models, ours or anyone else's.
  • We don't transfer Google user data to others, except as needed to provide Heed's features (see "Who we share data with"), for security, to comply with the law, or as part of a merger or sale of the business with notice to you.
  • People at Heed don't read your Google user data unless you ask us to and agree, it is needed for security or to investigate abuse, or the law requires it.

How Atlas uses your data

Atlas is the AI assistant inside Heed. When you ask Atlas something or use an Atlas feature (for example a meeting wrap-up, an email draft, deal coaching or an AI teammate), Heed sends the records needed for that request to Anthropic's Claude models through Amazon Bedrock in the EU (Frankfurt). Amazon Bedrock does not store these prompts or use them to train models. Atlas's answers and drafts are saved in your workspace so you can review them.

Atlas proposes changes and waits for you to confirm them. AI teammates act within the permissions your team gives them, and every action they take is logged and can be undone. Each person has a daily Atlas limit.

How we use information

We use the information above to:

  • run Heed and the features you use, including Atlas;
  • keep accounts and workspaces secure and prevent abuse;
  • send service emails, such as password links, booking confirmations, notifications and the weekly brief you can turn off;
  • answer your questions and support requests;
  • understand, in aggregate, which features are used, so we can improve Heed.

Our legal bases under the GDPR are: performing our contract with you or your company, our legitimate interest in keeping Heed secure and improving it, and your consent where we ask for it (for example connecting Google or learning your writing style). You can withdraw consent at any time.

Who we share data with

We don't sell personal data. We use these providers to run Heed:

Provider What they do Where
Amazon Web Services Servers, database, file storage and backups, email delivery (Amazon SES), and AI models (Amazon Bedrock) Frankfurt, Germany
Cloudflare Network security and delivery of the website Global
Laravel Nightwatch Error and performance monitoring United States
Firecrawl Reads public company websites to fill in company details and research your company US
Google Gmail, Calendar and sign-in, when you connect them Global

Firecrawl only receives the address of public websites, never your email or workspace records. We may also disclose information if the law requires it, or to protect the rights and safety of our users and of Heed.

International transfers

Heed's servers, database and backups are in the EU (Frankfurt). Some providers above can process data outside the EU. When they do, the transfer is covered by the European Commission's Standard Contractual Clauses or another lawful transfer mechanism.

How long we keep data

  • Workspace data is kept while the workspace exists. A workspace owner can delete the whole workspace from Settings. Its data is then deleted from our servers right away and from backups when they expire.
  • You can delete your own account from Settings and hand your records to a teammate.
  • Data from Google stays only as described above and is removed when you exclude it, when the records are deleted, or when the workspace is deleted.
  • Booking details are kept with the host's workspace.
  • The suppression list is kept for as long as Heed sends email, so people who unsubscribed or bounced are never emailed again. A workspace's own unsubscribes are deleted with the workspace.
  • Waitlist entries are kept until you ask us to remove them or we open your workspace.
  • Server logs are kept for a short time, usually no longer than 30 days.

Security

All traffic to Heed runs over HTTPS. Each team's data is kept in its own workspace, and every request is checked against that workspace. Google access tokens are encrypted at rest. Access to production systems is limited to the people who run Heed.

Your rights

Depending on where you live, you can ask to access, correct, export or delete your personal data, to restrict or object to how we use it, and to withdraw consent. Most of this you can do yourself in Settings, including exporting your workspace as CSV files and deleting your account. For anything else, write to [email protected]. If your data is part of a team's workspace, we may pass your request to that team.

You also have the right to complain to a data protection authority, for example the one where you live.

Cookies

Heed only uses cookies that are needed for it to work: one to keep you signed in, one to protect forms against cross-site request forgery, and a "keep me logged in" cookie if you choose it. We don't use advertising or analytics cookies.

Children

Heed is a tool for businesses and is not meant for anyone under 16.

Changes to this policy

If we change this policy, we will update the date at the top. For important changes, we will tell you by email or in the app before they take effect.

Contact

Questions or requests about privacy: [email protected].