Privacy Policy

Last updated: September 2, 2026

This Privacy Policy explains how Henry AI Technologies LLC (“Henry,” “we,” “us”) collects, uses, shares, and protects information when you use the Henry AI assistant and everything it runs on: the web app at app.usehenry.ai, the Henry apps for iOS, Android, and macOS, the Henry apps for Slack and Microsoft Teams, the email channel, the texting channel (iMessage and SMS), the Agent Browser, and the usehenry.ai website (together, the “Service”). Capitalized terms not defined here have the meanings given in our Terms of Service.

The short version: Henry works by reading the context you allow it to see and acting on the tools you connect. We use that data only to run Henry for your Workspace. We do not sell personal information, we do not use your data to train AI models, and our own staff cannot read your conversations through our administrative tools. You can export or delete your data at any time.

1. Who is responsible for your data

Workspace data. When you use Henry through an organization's Workspace (for example your employer's Slack or Teams workspace), that organization (the “Customer”) decides what Henry may read, which tools it may use, and how long data is kept. For that Customer Content, the Customer is the controller (or “business” under U.S. state privacy laws) and Henry is a processor (or “service provider”) acting on the Customer's instructions under our Data Processing Addendum. If you have questions about how your organization uses Henry, or want to exercise rights over data in your organization's Workspace, contact your Workspace owner or admin first; we will help them respond.

Account, billing, website, and personal Workspace data. Henry is the controller for the information we collect to create and secure your account, bill Customers, operate our website, communicate with you, and run the Service, and for everything in a personal Workspace you create for yourself.

2. Information we collect

2.1 Information you provide

  • Account and profile: name, email address, avatar, password (if you set one), two-factor authentication factors, Workspace name and settings, and role in the Workspace.
  • Phone number and texting data: if you enable the texting channel, the phone number you verify, your consent record, your STOP/START status, and the messages, photos, files, and voice messages you exchange with Henry over iMessage or SMS.
  • Conversations with Henry: messages you send to Henry and Henry's replies on every surface, including files, images, PDFs, and audio you attach, and the thumbs up or thumbs down feedback you give on replies.
  • Memory, knowledge, skills, and projects: facts and preferences Henry remembers for you or your team, documents and knowledge you add, reusable instructions (skills), and project content.
  • Scheduled tasks: the instructions, schedules, and run history of tasks you ask Henry to perform.
  • Personal Workspace profiles and documents: in a personal Workspace, the people, vehicles, homes, pets, and documents you tell Henry about, the details and dates attached to them, the follow-ups Henry has promised you, your quiet hours and home timezone, and the photos and PDFs of documents you text to Henry. Henry extracts the facts from a document and keeps the original file in a private document wallet that belongs to your Workspace.
  • Agent Browser data: if you use the Agent Browser, the sites you save and what you use them for, the tasks you run and their status, screenshots of the pages Henry visited, the content of pages Henry read to complete a task (which becomes part of the conversation), a recording of each session held by our browser provider, and the browser profile for each site you sign in to (the cookies and signed-in state a browser normally keeps), also held by our browser provider. Henry never receives your passwords or verification codes; when a site needs a sign-in, you type them yourself on a live view of the browser.
  • Support and sales communications: what you send us by email, in the contact sales form (name, work email, team size, phone, company domain), in the waitlist form (name and email), or through the “report an issue” feature in Henry.
  • Payment information: handled by our payment processor, Stripe. We receive billing name, address, the last four digits and brand of your card, and transaction records, but never your full card number.

2.2 Information from platforms and tools you connect

  • Slack: your Slack user ID, profile name and email, workspace ID and name, and the messages, threads, reactions, and files in direct messages with Henry and in channels Henry has been invited to. In captured channels Henry reads history and follows new messages, not just messages that mention it. Admins choose which channels are captured, can turn capture off per channel, and can purge what Henry learned.
  • Microsoft Teams: your Microsoft identity (name, email, Entra ID object and tenant IDs) and the messages and files in personal chats, group chats, and team channels where Henry has been added, within the permissions your Teams administrator grants.
  • Google sign-in and SSO: your name, email, and identifier from Google or your organization's identity provider when you sign in with them.
  • Connected Tools: when you or your admin connect a third-party tool (for example a CRM, calendar, email account, project tracker, or code host), Henry reads and, with your confirmation, writes data in that tool within the permissions you grant. The data Henry reads is used to answer your request and may be retained as part of the conversation, memory, or task history in which it was used. For most integrations the OAuth credentials are held by our integration providers (Pipedream or Composio), not by Henry; for first-party connectors we encrypt credentials at rest.
  • Email channel: emails sent to your Workspace's Henry address from senders your admin has allowlisted, including headers, bodies, and attachments.

2.3 Information collected automatically

  • Usage and metering data: which features, models, tools, and surfaces you use, token counts and model costs per request, credits consumed, timestamps, and error events.
  • Device and log data: IP address, browser and operating system, device type and identifiers, app version, language, and server logs of requests to the Service.
  • Push notification tokens: if you allow notifications in the mobile app, the device token needed to deliver them.
  • Cookies and similar storage: in the signed-in app, strictly necessary cookies to keep you signed in and remember your active Workspace, and local storage for preferences such as theme; the app does not load analytics or advertising tags. On our public website, usehenry.ai, analytics cookies (Google Analytics, loaded through Google Tag Manager, and cookieless Vercel Web Analytics) and advertising attribution cookies (Cometly), subject to your consent where the law requires it. See our Cookie Policy.
  • Website analytics and advertising data: when you visit usehenry.ai, the pages you view, the site, campaign, ad, or link that brought you there, approximate location derived from your IP address, device and browser details, and, if you go on to join the waitlist or sign up, the fact that a conversion happened together with a hashed (one-way encoded) form of the email address you entered, which our attribution tool sends to Google Ads and Meta so they can match the conversion to an ad you saw. We use it to understand how people find Henry and which advertising works; it is never combined with your conversations or Customer Content.

2.4 Mobile app permissions

The Henry mobile app asks for permission before accessing your photo library (only the photos you choose to attach), before using the camera if you choose to take a photo to attach, and before sending notifications. Its permission declarations include the microphone because the photo picker supports it, but Henry does not record audio in the app; voice messages reach Henry only through iMessage or SMS, or as audio files you attach in Slack or Teams. The app does not collect precise location, contacts, or health data.

2.5 Information we do not want

Henry is not designed for protected health information, payment card numbers, government identification numbers, or other highly sensitive data, and our Terms prohibit submitting them unless an Enterprise Agreement permits it. The exception is a personal Workspace's document wallet, which is built for your own records such as a driver's license, insurance card, or vehicle registration; those files are stored in a private bucket, used only to serve you, and never used to infer characteristics about you. Where Henry detects API keys, tokens, or similar secrets in captured channel content, it redacts them before storage.

3. How we use information

We use the information described above to:

  • Provide the Service: generate replies, remember context, run tasks, take confirmed actions in Connected Tools and on websites through the Agent Browser, send the reminders a personal Workspace asks for, and deliver results on the surface you chose.
  • Create and secure accounts, authenticate sign-ins, verify phone numbers, detect and prevent fraud, abuse, and security incidents, and enforce our Terms and Acceptable Use Policy.
  • Meter usage, bill Customers, manage credits, and send billing and account notices.
  • Provide support and respond to your requests and issue reports.
  • Operate, maintain, debug, and improve the Service using aggregated or de-identified usage metrics (never by training models on Customer Content).
  • Send service and security announcements, and, with your consent where required, product news you can opt out of at any time.
  • Understand how people find and use our public website and measure our advertising, using the analytics and attribution tools in the Cookie Policy (website only, never the signed-in Service).
  • Comply with legal obligations and protect rights and safety.

3.1 Legal bases (EEA, UK, and Switzerland)

PurposeLegal basis
Providing the Service and support to youPerformance of a contract (Terms of Service); for Customer Content, the Customer's instructions under the DPA
Security, fraud and abuse prevention, service improvementLegitimate interests in keeping the Service secure and working well, balanced against your rights
Billing, tax, and accounting recordsPerformance of a contract; legal obligation
Personal Workspace features (profiles, reminders, document wallet, Agent Browser)Performance of a contract (Terms of Service)
Texting channel, product news, optional featuresConsent, which you can withdraw at any time
Website analytics and advertising cookiesConsent (EEA, UK, and Switzerland); elsewhere legitimate interests in measuring our website and advertising, with an opt-out at any time
Responding to legal requests and protecting rightsLegal obligation; legitimate interests

4. How AI processing works

Henry generates replies using large language models operated by third-party providers: Anthropic, OpenAI, xAI, and Moonshot AI (whose models we run only on U.S. inference hosts). Requests are routed through the Vercel AI Gateway. To answer you, Henry sends the model the relevant parts of your conversation, memory, knowledge, files, and Connected Tool data, and, in an Agent Browser task, the text of the pages Henry reads. Related processing includes: Voyage AI for search embeddings, ElevenLabs for transcribing voice messages and audio, and the gateway's web search provider when Henry searches the web for you.

  • No training. We do not train models on your data. Our providers process your data under commercial API terms that prohibit them from using it to train their models.
  • Provider retention. Providers process requests transiently to generate a response. Some may retain request data for a limited period (typically up to 30 days) for abuse and misuse monitoring under their terms, after which it is deleted.
  • Model choice. You or your admin can choose among the models Henry offers; when a provider is unavailable Henry may fall back to another provider so your request still completes. The current providers are listed at usehenry.ai/subprocessors.
  • Human review. Henry staff do not read your conversations. Our administrative tools are built so that message content, memories, knowledge, task instructions, email bodies, and tool payloads cannot be viewed through them. We would access content only with your consent, when legally compelled, or to prevent imminent harm, and any such access is logged.
  • Automated decisions. Henry does not make decisions about you that have legal or similarly significant effects without human involvement. Consequential actions in Connected Tools require a person to confirm them or to have set up a standing approval.

5. How we share information

We share personal information only as follows:

  • Subprocessors and service providers that host and run the Service on our behalf under contracts that limit their use of the data: hosting and database (Vercel, Supabase on AWS), AI and processing providers (Section 4), background job orchestration (Inngest), email delivery (Resend), texting relay (Sendblue), payments (Stripe), push notifications (Expo, Apple, Google), integration providers (Pipedream, Composio), and cloud browser infrastructure for the Agent Browser (Browserbase). The full list, with locations, is at usehenry.ai/subprocessors.
  • Connected Tools and platforms, on your instruction. When you ask Henry to act in a Connected Tool, or post in Slack or Teams, the relevant content is sent to that platform and is then governed by that platform's privacy policy.
  • Websites you direct the Agent Browser to. Those sites receive the requests any browser would send, made from our browser provider's infrastructure rather than your device, plus whatever you or Henry enter on them, under the site's own privacy policy.
  • Your Workspace. Team knowledge, shared threads, and task results are visible to other members according to your Workspace's settings. Workspace owners and admins can see members, usage and spend, integrations, and tasks, and can export the Workspace's data, which includes conversations with Henry. Private memories are visible only to the user they belong to.
  • Internal tools. Issue reports you file through Henry are sent to our issue tracker (Linear), and support emails are handled in Google Workspace.
  • Website analytics and advertising partners (website only). On usehenry.ai, Google (Google Analytics and Tag Manager) and Vercel (Web Analytics) receive page view and device data, and Cometly receives visit and conversion data and reports conversion events, including a hashed form of the email address you entered at sign-up or on the waitlist, to Google Ads and Meta for ad matching. The platforms receive the hash, not your readable address. None of these tools run in the signed-in Service, and none receive Customer Content, conversations, or phone numbers. You can opt out as described in Section 10.1 and the Cookie Policy.
  • Legal and safety. We may disclose information when required by law, subpoena, or court order, or when we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Henry, our users, or the public, or to enforce our Terms. Where permitted, we will notify the affected Customer before disclosing Customer Content in response to a legal request.
  • Business transfers. If Henry is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Policy or a policy at least as protective.
  • With your consent or at your direction.

We do not sell personal information. The only sharing for cross-context behavioral advertising we do is the reporting of website conversion events to advertising platforms described above, and you can opt out of it. We never share your phone number, texting opt-in data, consent information, conversations, or Customer Content with third parties for their marketing.

6. How long we keep information

We keep information for as long as needed to provide the Service to you and your Workspace, and afterwards only as needed for the purposes below.

DataRetention
Conversations, memory, knowledge, tasks, filesLife of the Workspace, or until you or your admin delete them. Deleted Workspaces are removed from production within 30 days; backups expire on their normal cycle within a further 30 days.
Captured channel contentKept while capture is on for that channel; purged on request or when the channel is turned off and purged.
Texting messages and phone numberWith your conversation history; your number and STOP record are kept while linked, and STOP records are retained as required to honor your opt-out.
Account dataUntil you delete your account or your last Workspace is deleted.
Billing and tax records7 years, as required by law.
Usage and metering recordsLife of the Workspace for itemized records; aggregated statistics indefinitely.
Personal Workspace profiles, commitments, and document wallet originalsLife of your personal Workspace, or until you ask Henry to forget them.
Agent Browser screenshots30 days, then deleted automatically.
Agent Browser saved sign-ins (browser profile at our browser provider)Until you sign out of that site, disconnect the browser, or your Workspace is deleted. We delete the profile at the provider and verify that it is gone.
Agent Browser session recordingsHeld by our browser provider for a limited period under its retention terms.
Workspace audit log (tool calls and settings changes)Life of the Workspace; append-only.
Workspace export archives7 days, then deleted automatically.
Task run replay logs14 days.
Staff administrative access logsRead logs 180 days; records of staff actions are kept in redacted form (no names, emails, or content) as a compliance record.
Server request logsUp to 30 days.
Deletion confirmation recordsRetained (counts and Workspace name only) as proof of deletion.

We may keep information longer where required by law, to resolve disputes, to enforce our agreements, or, in redacted or de-identified form, to prevent abuse of the Service.

7. How we protect information

We use administrative, technical, and physical safeguards designed to protect your information, including: encryption in transit (TLS 1.2 or higher) and at rest (AES-256); encryption of integration credentials, API keys, and other secrets with AES-256-GCM under per-Workspace keys; database-level tenant isolation so one Workspace can never read another's rows; isolated per-Workspace sandboxes for code execution; Agent Browser sessions isolated to a single user in which Henry never handles credentials; role-based access and per-member integration permissions; human confirmation for consequential actions; multi-factor authentication for staff, with staff administrative actions audited; and code review and automated testing before every deployment. We are preparing for a SOC 2 examination. No system is perfectly secure; if we learn of a breach affecting your personal information we will notify affected Customers without undue delay and within 72 hours of confirming it, and notify individuals and regulators as the law requires. More detail is on our Security page.

8. Where information is stored and international transfers

Henry is operated from the United States, and Customer Content is stored in data centers in the United States (Oregon). Our subprocessors may process data in the countries listed on the subprocessors page. If you use Henry from outside the United States, your information will be transferred to and processed in the United States, where privacy laws may differ from those in your country.

For transfers of personal data from the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum and Swiss adjustments), incorporated into our Data Processing Addendum, together with the supplementary measures described in the DPA and on our Security page. Henry is not currently certified under the EU-U.S. Data Privacy Framework.

9. Your rights and choices

Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, to withdraw consent, to opt out of certain uses, and to appeal a decision we make about your request. We will not discriminate against you for exercising these rights.

Controls built into Henry

  • Edit your profile, sign-in methods, and notification preferences in Settings.
  • Turn channel capture off or purge captured content per channel (Slack admins: /henry capture off and /henry capture purge).
  • Disconnect Connected Tools, delete memories, pause or delete tasks, and delete conversations.
  • Unlink your phone number in Settings or reply STOP to any text.
  • Turn the Agent Browser off, sign out of an individual site, or disconnect the browser to delete every saved sign-in, in Settings.
  • In a personal Workspace, ask Henry to forget a profile, a date, or a commitment, or to change your quiet hours and timezone.
  • Turn off push notifications in your device settings.
  • Workspace owners can request a full machine-readable export and verified deletion of the Workspace.

Making a request

To exercise your rights, email privacy@usehenry.ai from the email address on your account, or write to us at the address below. We will verify your identity (usually by confirming control of your account email or phone number) and respond within 30 days, or 45 days for requests under U.S. state laws, extending where the law allows and telling you if we do. You may use an authorized agent if they provide proof of your written permission. If we deny your request, you may appeal by replying to our decision. For data in an organization's Workspace, we may refer your request to that Customer and help them respond.

Because Henry's replies are generated by AI, we may not always be able to correct inaccurate statements about you in past Output, but you can delete the conversation or memory that contains them.

10. Additional information for specific regions

10.1 California and other U.S. states

This section supplements the rest of this Policy for residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other U.S. states with comprehensive privacy laws. In the past 12 months we have collected the categories of personal information listed below. We collect them from you, your devices, the platforms and tools you connect, and your Workspace, for the purposes in Section 3, and disclose them to the service providers and contractors in Section 5 for business purposes.

CategoryExamples
IdentifiersName, email, phone number, account and platform IDs, IP address
Customer recordsBilling name and address, transaction records
Commercial informationPlan, credits purchased and used
Internet or network activityUsage of the Service, device and log data
Audio, visual, or similar informationVoice messages, photos, and files you send to Henry; screenshots of pages the Agent Browser visited
Geolocation dataThe home timezone or city you tell a personal Workspace (coarse; we never collect precise device location)
Professional informationEmployer, role, team size (from your Workspace or the sales form)
InferencesPreferences and context Henry remembers to help you
Sensitive personal informationAccount credentials; documents you file in a personal Workspace's document wallet; and any sensitive content you choose to include in messages (we do not use it to infer characteristics about you)

We do not sell personal information. On our public website only, we “share” website visitor data (cookie identifiers, page views, and conversion events) with advertising partners for cross-context behavioral advertising, as described in Section 5 and the Cookie Policy; nothing from the signed-in Service is shared this way. To opt out, use the “Your Privacy Choices” link in the website footer or turn on Global Privacy Control in your browser, which we honor as an opt-out request. We do not use or disclose sensitive personal information other than to provide the Service you request and for the purposes permitted by law, and we do not knowingly sell or share the personal information of anyone under 16. You have the rights to know, access, correct, delete, port, limit, and opt out, and to non-discrimination, as described in Section 9. California residents may request a list of the categories of personal information disclosed for a business purpose in the prior 12 months.

10.2 European Economic Area, United Kingdom, and Switzerland

Henry AI Technologies LLC, 2810 N Church St STE 90844, Wilmington, DE 19802, USA, is the controller for the data described in Section 1 under “Account, billing, website, and personal Workspace data.” Our legal bases are in Section 3.1 and transfer mechanisms in Section 8. In addition to the rights in Section 9, you have the right to lodge a complaint with your local data protection authority (a list of EU authorities is published by the European Data Protection Board; in the UK, the Information Commissioner's Office; in Switzerland, the Federal Data Protection and Information Commissioner). We would appreciate the chance to address your concern first at privacy@usehenry.ai.

10.3 Canada

We collect, use, and disclose personal information with consent or as otherwise permitted by PIPEDA and applicable provincial laws. Your information may be processed in the United States and be accessible to U.S. authorities under U.S. law. You may request access to or correction of your information, or withdraw consent subject to legal and contractual restrictions, at privacy@usehenry.ai.

11. Children

The Service is for adults. We do not knowingly collect personal information from anyone under 18, and never from children under 13. If you believe a child has provided us personal information, contact privacy@usehenry.ai and we will delete it.

12. Platform-specific disclosures

  • Slack. Henry's use of Slack APIs is limited to providing the Service to the workspace that installed it. Slack data is not used to develop, improve, or train generalized AI or machine learning models. Uninstalling Henry stops all collection immediately and revokes our Slack tokens; previously stored data remains in your Workspace until you delete it or request deletion.
  • Microsoft Teams. Henry accesses Teams data only within the permissions your Microsoft 365 administrator consents to and uses it only to provide the Service. Removing the app stops collection immediately.
  • Google. Henry's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide and improve user-facing features of the Service, is not transferred to third parties except to provide those features, comply with law, or as part of a merger or acquisition, is not used for advertising, and is not used to develop, improve, or train generalized AI or machine learning models. Humans do not read it except with your consent, for security, or to comply with law.
  • Apple and Google app stores. Our apps' privacy details in the App Store and Google Play describe the same practices as this Policy. The app stores may collect their own data under their policies.
  • Websites visited by the Agent Browser. Sites Henry visits on your behalf see traffic from our browser provider's infrastructure rather than from your device, and their own privacy policies govern what they collect.
  • Third-party links. Output and Connected Tool results may include links to third-party sites we do not control and whose privacy practices we are not responsible for.

13. Changes to this Policy

We may update this Policy as the Service and the law change. We will post the new version here with a new “Last updated” date, and, for material changes, notify Workspace owners by email or in-product notice before the changes take effect. Earlier versions are available on request.

14. Contact us

Henry AI Technologies LLC
Attn: Privacy
2810 N Church St STE 90844
Wilmington, DE 19802, United States
privacy@usehenry.ai (privacy requests)
support@usehenry.ai (general support)