Legal

Privacy Policy

Effective date: 8 April 2026 · Last updated: 8 April 2026

1. Introduction

Hi Joanna ("we", "our", or "us") is committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Hi Joanna mobile application and website located at https://hijoanna.app (collectively, the "Service").

Please read this policy carefully. If you disagree with its terms, please discontinue use of the Service. By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.

2. Information We Collect

2.1 Account Information

When you create an account, we collect your name and email address. Authentication is handled securely via Google OAuth or email/password sign-in. We do not store your authentication password in plain text.

2.2 Voice Data

When you use voice features, your speech is transmitted to AI service providers for speech-to-text transcription and response generation. Voice audio is processed in real time and is not stored on our servers beyond the duration required to complete the task. Transcribed text from your voice sessions is stored as part of your conversation history.

2.3 Email Content

If you connect an email account (Gmail, Outlook, Yahoo, iCloud, or other IMAP/SMTP providers), we access your emails solely to provide AI-powered summaries, daily recaps, and intelligent assistance. Your email credentials are encrypted using AES-256-GCM and stored securely on our servers — they are never transmitted to third parties or stored in plain text.

Email messages processed by the Service are protected by Row-Level Security (RLS) — meaning only you can access your own email data. No other user or unauthorised party can access your emails through our systems. You may revoke email access at any time from the Settings screen within the App.

We do not use your email content to train AI models.

2.4 Calendar Data

If you connect a calendar account (Google Calendar or device calendar), we access your calendar events solely to help Joanna provide scheduling assistance, reminders, and to add calendar entries on your behalf when you request it. Calendar data is processed in real time and is not permanently stored on our servers beyond what is necessary to fulfil your request.

2.5 Conversation History

Your conversations with Joanna are stored to provide continuity across sessions. Conversation history is retained according to your subscription plan:

PlanMonthly PriceRetention Period
TrialFree7 days
Basic$9.9930 days
Professional$29.9090 days
Executive$99.99Unlimited

You may delete your conversation history at any time from the Settings screen.

2.6 User Preferences

Joanna learns your preferences (such as dietary preferences, travel preferences, and communication style) from your conversations. These preferences are stored and used to personalise Joanna's responses across sessions. You may view and delete individual preferences from the Settings screen.

2.7 Subscription and Billing Data

Subscription and billing information is handled by RevenueCat and the Apple App Store / Google Play Store. We do not store your payment card details. We receive information about your subscription status, plan type, and usage from RevenueCat.

2.8 Usage Data

We collect data about your use of voice minutes, including minutes consumed and remaining balance. This data is used to enforce subscription limits and display your usage statement within the App.

2.9 Device and Technical Data

We may collect technical information such as your device type, operating system version, app version, IP address, and crash reports for the purpose of diagnosing technical issues and improving the Service.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service;
  • Process and complete tasks you request through voice or text commands;
  • Generate AI-powered email summaries and daily recaps;
  • Manage low-priority sender preferences for email recaps;
  • Provide scheduling assistance using your calendar data and create calendar events on your behalf when requested;
  • Personalise Joanna's responses based on your stored preferences;
  • Manage your subscription and voice minute balance;
  • Send transactional communications (e.g., account confirmations, subscription receipts);
  • Respond to your support requests and enquiries;
  • Monitor and analyse usage patterns to improve the Service;
  • Detect, prevent, and address technical issues, fraud, or abuse;
  • Comply with legal obligations.

We do not sell, rent, or trade your personal information to third parties for marketing purposes.

4. Email Data and AI Processing

When you connect your email account to Hi Joanna, the Service accesses your inbox solely to fulfil tasks you explicitly request — such as summarising emails, flagging important messages, identifying invoices or deadlines, or drafting replies. The following principles govern how we handle email data:

  • Email content is processed transiently for AI summarisation and is not retained on our servers beyond the immediate task.
  • Your email credentials are encrypted using AES-256-GCM and stored securely on our servers.
  • We do not use your email content to train AI models.
  • You may disconnect your email account at any time from within the App settings.

5. AI-Generated Content and Accuracy

Hi Joanna uses artificial intelligence to generate responses, summaries, and task outputs. AI-generated content may contain errors, inaccuracies, or outdated information. We do not warrant the accuracy, completeness, or reliability of any AI-generated output. You should independently verify any information provided by the Service before relying on it for important decisions. Please refer to our Disclaimer for further detail.

6. Data Sharing and Disclosure

We do not sell your personal data. We share data only with the following third-party service providers, solely to operate the Service:

ProviderPurpose
Google Gemini AISpeech-to-text, text-to-speech, AI responses, email summarisation
SupabaseEmail data storage with Row-Level Security
Google Calendar APICalendar access for scheduling features
RevenueCatSubscription management
Apple App Store / Google PlayPayment processing
TavilyWeb search for agentic tasks

Each of these providers has its own privacy policy governing their use of data. These parties are contractually obligated to keep your information confidential and use it only for the purposes we specify. AI model providers are bound by data processing agreements that prohibit them from using your data for their own training purposes.

We may also disclose your information in the following limited circumstances:

  • Legal requirements: If required to do so by law or in response to valid legal process (e.g., a court order or government request).
  • Business transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information is transferred and becomes subject to a different privacy policy.
  • Protection of rights: Where we believe it is necessary to investigate, prevent, or take action regarding illegal activities, suspected fraud, or threats to the safety of any person.

7. Data Security

We implement industry-standard technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. These measures include:

  • AES-256-GCM encryption for sensitive credentials (email passwords, IMAP tokens);
  • Row-Level Security (RLS) on all database tables, ensuring each user can only access their own data;
  • HTTPS/TLS encryption for all data transmission;
  • Access controls and regular security reviews.

However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.

8. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Service. Conversation history is retained according to your subscription plan (see Section 2.5). Email credentials are deleted immediately when you remove an email account. If you delete your account, we will delete or anonymise your personal information within 30 days, except where we are required to retain it for legal, regulatory, or legitimate business purposes (e.g., fraud prevention, dispute resolution).

Voice recordings are deleted immediately after the task is completed. Email content processed by the Service is not retained beyond the session. User preference data (persistent memory) is retained until you delete it within the App or delete your account.

You may request deletion of all your data by contacting us at [email protected].

9. Your Rights and Choices

Depending on your jurisdiction, you may have the following rights regarding your personal information:

  • Access: Request a copy of the personal information we hold about you.
  • Correction: Request that we correct inaccurate or incomplete information.
  • Deletion: Request that we delete your personal information, subject to certain legal exceptions.
  • Portability: Request a machine-readable copy of your data.
  • Objection / Restriction: Object to or request restriction of certain processing activities.
  • Withdraw consent: Where processing is based on consent, withdraw that consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, please contact us at [email protected]. We will respond within 30 days. We may need to verify your identity before processing your request.

10. Children's Privacy

The Service is not directed to children under the age of 13 (or 16 in the European Economic Area). We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal information without parental consent, please contact us at [email protected] and we will take steps to delete such information.

11. International Data Transfers

Your information may be transferred to and processed in countries other than the country in which you reside. These countries may have data protection laws that are different from the laws of your country. We ensure that appropriate safeguards are in place for such transfers, including Standard Contractual Clauses for transfers from the European Economic Area.

12. Third-Party Links and Services

The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review the privacy policies of any third-party services you access through the Service.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the effective date. For significant changes, we will provide additional notice (e.g., an in-app notification or email). Your continued use of the Service after the effective date of the revised policy constitutes your acceptance of the changes.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us: