Hey Fable · last updated 3 October 2026
Privacy policy
Hey Fable writes account briefings for B2B sellers from public sources. This page explains what we collect about you to do that, and what we do with it. The short version: only what the product needs, no advertising, no selling of data, and usage analytics and session recordings with credentials excluded.
Who we are
Hey Fable (“we”) decides how your data is used. Questions or requests: privacy@heyfable.app.
What we collect
- Your account. Your email address. If you sign in with Microsoft, Google or LinkedIn, we also receive your name and profile picture from that provider. We never receive your password for those services, and we do not ask for access to your mailbox, calendar or contacts.
- Sign-in sessions. A session cookie, and the IP address and browser type stored with each session, used to keep you signed in and to protect your account.
- What you tell us. Your company’s website, the product profile you confirm, the companies you want briefed, your workspace name, the email addresses of teammates you invite, and any message you send us through the contact form.
- AI operation records. Model names, timing, token counts, estimated costs, errors and report/workspace identifiers. Our technical monitoring also includes AI prompts, responses and tool activity, which can contain company and user information. Passwords, API keys and access tokens are redacted.
- Product events. Page visits, acquisition sources and campaign tags, clicked controls and labels, onboarding steps, and report actions, linked to your account, workspace and browser session.
- Your Account Points of View. The points of view we write for you and their status.
- Report sharing. Recipient email addresses and access grants when you share a report, including when access is revoked.
Briefings are built from public information about the companies you choose: their SEC filings, their websites and news coverage. That material is about companies, and may name their executives as they appear in those public sources. It is not information about you.
How we use it
- To sign you in, including emailing you sign-in links.
- To draft your product profile from your company’s website, and to generate the briefings you ask for.
- To email you when your briefings are ready, and to answer you when you contact us.
- To understand and improve the product from the onboarding events above.
We do not sell your data or use it for advertising. Essential cookies keep you signed in and remember whether the sidebar is open. Analytics uses local storage and a session cookie to connect browser activity with server actions and report generation.
Who processes it for us
If you create a public report link, anyone with that link can read that report until access is revoked. Email sharing requires the recipient to sign in with the invited, verified address. Sharing a report does not add the recipient to your workspace.
- Hetzner (Germany) hosts the application and its database.
- Anthropic and OpenAI (United States) provide the AI models that read your product profile and the public sources to write briefings. Neither uses this data to train its models.
- Resend (United States) delivers our emails.
- PostHog (EU cloud) is our data subprocessor for usage analytics, session recordings and technical monitoring, including account and workspace identifiers. Recordings show page content, ordinary form inputs, styles and report content. Monitoring includes console messages, readable errors, performance measurements and request metadata; request bodies and headers are excluded. Password fields, access links, API keys and access tokens are excluded or redacted.
- Cloudflare answers DNS queries for our domain.
- Microsoft, Google and LinkedIn handle sign-in, only if you choose one of them.
Some of these providers process data in the United States under their standard data processing terms.
How long we keep it
Account, workspace and point-of-view data stay while your account is active. Sign-in links expire after ten minutes and sessions expire on their own. You can delete your account yourself under Settings → My account, or ask us to; we then delete your data from the live system, and copies in database backups taken before updates are removed within 30 days. Workspaces you share with others stay with them. Operational AI records are retained independently of report deletion for cost accounting and reliability. To enforce the included report allowance per person, we keep a one-way hash of your email address after deletion; it cannot be turned back into the address and is used for nothing else.
Your rights
You can ask us to access, correct, export or delete your data, or object to how we use it, by writing to privacy@heyfable.app. If you are in the EU or UK you can also complain to your data protection authority. Hey Fable is a professional tool and is not meant for anyone under 16.
Changes
If we change this policy in a way that matters, we will update the date above and tell signed-in users.