Wweekhaven
  • Pricing
  • FAQ
Sign In
Sign Up
Wweekhaven

WeekHaven is your AI-powered weekly digest — turning email and calendar overload into clear priorities so you never miss what matters.

© Copyright 2026 WeekHaven. All Rights Reserved.

Get Started
  • Sign In
  • Sign Up
Product
  • Pricing
  • FAQ
  • Support
Legal
  • Terms of Service
  • Privacy Policy
  • Cookie Policy

Privacy Policy

How WeekHaven handles your data — and what we never do with it.

Last updated: 2026-05-24

1. Who We Are

WeekHaven is the data controller for personal data collected through this service. We are incorporated in the United States and can be reached at support@weekhaven.com .

2. Information We Collect

We collect the following categories of personal data:

  • Account data: Your name, email address, and authentication credentials when you create an account or sign in via a third-party OAuth provider.
  • Email metadata: Sender, recipient, subject line, date, and a short preview (up to 200 characters) of message body for emails in connected Gmail or Outlook accounts. We do not store full email bodies.
  • Calendar metadata: Event titles, start and end times, attendees, and meeting links from connected Google Calendar or Microsoft calendar accounts. Calendar body/description text is not stored.
  • Slack message metadata: See the dedicated Slack section below.
  • Usage data: Pages visited, feature usage, and error logs collected to operate and improve the service.

3. Slack Data Handling

When you connect your Slack account to WeekHaven, we request the following OAuth user-token scopes on your behalf:

  • channels:read — enumerate the public channels you are a member of
  • channels:history — read message history from those public channels
  • im:read — enumerate your direct message conversations
  • im:history — read message history from direct message conversations you explicitly include
  • users:read — resolve Slack user IDs to display names so that message metadata is human-readable

Token type

We request a user token (xoxp-*) via user_scope, not a bot token. This means the token operates with your personal permissions — it can only access channels and DMs that you yourself can access. We do not request any bot scopes.

What we read

During a weekly review generation, WeekHaven fetches messages from your joined public channels (all, unless you narrow the selection in Settings) and from direct message conversations that you explicitly include. Messages are fetched over a bounded recency window (the period covered by your current review).

For each message we read, we extract only a lightweight metadata recordin memory: the channel or DM name, the sender's display name, the message timestamp, and a preview of the message text capped at 200 characters. We never read the full message body beyond that 200-character cap. We skip bot messages, system events (channel joins/leaves, topic changes, etc.), and empty messages.

These previews are processed in memory only and passed directly to the AI inference provider that generates your weekly review. They are not written to any WeekHaven database table and are discarded as soon as the review is generated. Only the AI-generated review summary is persisted (see Retention, below).

Token storage

Your Slack user token is stored encrypted at rest in our database (connected_accounts table, via Supabase). The encryption key is held separately from the data store. Slack user tokens do not expire by default; they remain active until you revoke access.

Retention

Raw Slack message previews are not retained. They live only in memory during a single review generation and are discarded once the review is produced. The weekly review summary that we generate from those previews is retained until you delete your WeekHaven account. Once you disconnect your Slack account, no further data is fetched and your stored Slack token is removed.

How to revoke Slack access

You can disconnect your Slack account at any time from Settings → Connections inside WeekHaven. You can also remove WeekHaven from your Slack workspace by navigating to Slack → Settings & administration → Manage apps and revoking the app. Either action immediately invalidates the stored token and stops any further data collection.

4. How We Use Your Data

  • Weekly review generation: We pass message metadata (including Slack previews) to AI inference providers to produce your weekly review email. We do not sell your data to third parties.
  • Service operation: Account data is used to authenticate you and manage your subscription.
  • Product improvement: Aggregated, anonymized usage data helps us understand how the product is used and prioritize improvements.

5. Processors and Sub-processors

We share data with the following categories of sub-processors:

  • Database / infrastructure (Supabase): Stores your account data, connected account tokens (encrypted), and weekly review summaries.
  • AI inference providers: Receive message metadata (including Slack previews, transiently and in memory) to generate your weekly review. The previews are not stored by WeekHaven after the review is produced. We work with one or more providers; the current list is available on request.
  • Payments (Stripe): Processes subscription payments. We do not store payment card data ourselves.

All sub-processors are contractually bound to process data only as instructed and to maintain appropriate security measures.

6. Data Retention

  • Slack message previews: not retained — processed in memory only during review generation, then discarded
  • Email metadata: retained for up to 60 days, then automatically and permanently deleted
  • Calendar metadata: retained for up to 60 days after we read it, then automatically and permanently deleted
  • Forwarded messages (e.g. school emails): retained for up to 60 days, then automatically and permanently deleted
  • Weekly review summaries: until account deletion. These are the reviews we generate for you (the product output you return to), not the raw inbox/calendar/forwarded data we read to produce them — that input data is deleted on the 60-day schedule above.
  • Connected account tokens (encrypted): until you disconnect that account
  • Account data: until you delete your account or request erasure

7. Your Rights

Depending on your jurisdiction (including under GDPR and CCPA), you have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request erasure of your data ("right to be forgotten")
  • Request portability of your data in a machine-readable format
  • Withdraw consent or object to processing at any time

To exercise any of these rights, email us at support@weekhaven.com . We will respond within 30 days.

8. Contact

For privacy questions or data requests, contact: support@weekhaven.com .