Legal

Privacy Policy

Last updated: July 2026

Who this policy covers

Hype Insight Customer Alerts (“the app”) is a private internal workspace operated by Hype Insight for its own team. It is not offered as a public product, does not accept public signups, and is used solely by invited team members to coordinate responses to inbound customer communications.

What data the app accesses

When a team member connects one of their own mailboxes or chat accounts to the app, the app reads recent messages from that account with the member's explicit consent through the provider's OAuth flow. The categories of data read are:
  • Message metadata: sender name and address, recipient list, subject, timestamp, thread identifiers, and per-message provider identifiers.
  • Message body content: plain text and HTML bodies of received messages, so team members can see the full message inside the app instead of switching to the original provider.
  • Attachment metadata: filename, MIME type, and size. Attachment bytes themselves are fetched from the provider on demand when a team member clicks to view or download an attachment; they are not permanently stored by the app.
  • Call recording metadata and transcripts, when a member connects a compatible call-recording account.
  • Account profile info sufficient to identify the connected mailbox: email address, display name.
The app does not read messages from mailboxes that have not been connected by a team member, and does not send messages, modify messages, or delete messages on any connected account.

How the data is used

Data is used solely to render inbound customer communications inside the app's dashboard for signed-in team members, to generate short AI-produced summaries and draft reply text as an aid to the responding team member, and to compute per-customer health signals used internally by the team. Data is not sold, rented, shared with third parties for their own purposes, or used to train third-party machine-learning models.

Where the data is stored

Data is stored in a private database hosted on our cloud infrastructure, encrypted in transit and at rest, and accessible only through authenticated sessions belonging to invited team members. OAuth refresh tokens are encrypted at the application layer before being written to the database.

Third-party subprocessors

To operate the app we use a small number of third-party services, each bound by their own privacy commitments:
  • Google (for Gmail access on connected Google mailboxes, and for delivering push notifications about newly received messages).
  • Microsoft (for Outlook and Teams DM access on connected Microsoft accounts).
  • A language-model provider used to generate the short summary and draft-reply text shown in the dashboard. Message content is sent to this provider only for the purpose of producing that summary/draft, and the provider is contractually prohibited from using the content to train models.
  • A cloud application-hosting provider that runs the app and stores its database.

Retention

Data is retained for as long as the connected mailbox remains connected and the connecting team member has not requested deletion. When a mailbox is disconnected from the app, the associated OAuth tokens are deleted immediately. Message and attachment metadata previously synced from that mailbox can be deleted on request by emailing the address below.

Revoking access

Team members can revoke the app's access to their Google account at any time from myaccount.google.com/permissions, or their Microsoft account from account.microsoft.com/consent. Doing so immediately stops the app from reading any further messages from that account.

Contact

Questions about this policy, or requests to delete data, can be sent to [email protected].