Last updated: 2026-08-21
1. Who We Are
WeekHaven LLC is the data controller for personal data collected through this service. We are incorporated in the United States and can be reached at support@weekhaven.com
.
2. Information We Collect
We collect the following categories of personal data:
- Account data: Your name, email address, and authentication credentials when you create an account or sign in via a third-party OAuth provider.
- Email metadata: Sender, recipient, subject line, date, and a short preview (up to 200 characters) of message body for emails in connected Gmail or Outlook accounts. We do not store full email bodies.
- Calendar metadata: Event titles, start and end times, attendees, and meeting links from connected Google Calendar or Microsoft calendar accounts. Calendar body/description text is not stored.
- Usage data: Pages visited, feature usage, and error logs collected to operate and improve the service.
- Security event records: When something security-relevant happens to your account — your password is changed, your email address is changed, a two-factor authentication method is added or removed, or you complete two-factor authentication while signing in — we record what type of event it was and when it happened, together with your network address (IP address) and device and browser information. We email you when your account is changed; we do not email you for a routine two-factor sign-in.
- Action items and follow-ups: generated from your email and calendar data.
- Captured photo and file records: When you use the capture button to photograph a document or choose a PDF, we read it once, in that moment, to find the deadlines and tasks it contains. We do not store the image or the file, and we do not keep a transcript of the page. What we keep is a record of the capture itself: when it happened, whether it was a photo or a PDF, its size, the draft items we offered you, which of those became items, and the processing counters we use to measure what the feature costs us to run.
3. How We Use Your Data
- Weekly review generation: We pass message metadata to AI inference providers to produce your weekly review email. We do not sell your data to third parties.
- Service operation: Account data is used to authenticate you and manage your subscription.
- Product improvement: Aggregated, anonymized usage data helps us understand how the product is used and prioritize improvements.
- Account security: Security event records are used for account security and for the detection of unauthorized access — so that you are told when your account changes, and so that a security question can be answered afterwards. Where GDPR applies, we process this data on the basis of our legitimate interest in securing user accounts.
4. Processors and Sub-processors
We share data with the following categories of sub-processors:
- Database / infrastructure (Supabase): Stores your account data, connected account tokens (encrypted), and weekly review summaries.
- AI inference providers: Receive message metadata (transiently) to generate your weekly review, and — when you use capture — the photo or file you chose, also transiently, to find the deadlines and tasks on it. We do not keep the photo or the file after that. We work with one or more providers; the current list is available on request.
- Payments (Stripe): Processes subscription payments. We do not store payment card data ourselves.
All sub-processors are contractually bound to process data only as instructed and to maintain appropriate security measures.
5. Data Retention
- Email metadata: retained for up to 60 days, then automatically and permanently deleted
- Calendar metadata: retained for up to 60 days after we read it, then automatically and permanently deleted
- Action items and follow-ups: kept while active, and for 60 days after you mark one done or dismiss it — then automatically and permanently deleted.
- Weekly review summaries: until account deletion. These are the reviews we generate for you (the product output you return to), not the raw inbox/calendar data we read to produce them — that input data is deleted on the 60-day schedule above.
- Security event records: the full record — including your network address (IP address) and device and browser information — is retained for 90 days. At 90 days the network address and the device and browser information are erased, leaving a minimized record of which account, what type of event, and when, with no network identifiers. That minimized record is kept until 13 months after the event, then automatically and permanently deleted.
- Captured photo and file records: retained for 180 days, then automatically and permanently deleted. The photo or file itself is never stored on our servers — it is read once and discarded when you finish reviewing what we found, and no transcript of the page is kept. The 180-day record is the capture's details, the draft items, and our own processing counters. Items you chose to keep are action items or awareness items (Family / Don't Forget), and follow the 60-day rule above once you mark them done or dismiss them.
- Connected account tokens (encrypted): until you disconnect that account
- Account data: until you delete your account or request erasure
- All security event records for an account are deleted when that account is deleted.
6. Your Rights
Depending on your jurisdiction (including under GDPR and CCPA), you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request erasure of your data ("right to be forgotten")
- Request portability of your data in a machine-readable format
- Withdraw consent or object to processing at any time
To exercise any of these rights, email us at support@weekhaven.com
. We will respond within 30 days.
7. Contact
For privacy questions or data requests, contact: support@weekhaven.com
.