Overview
Hestya is an invite-only beta operated in the United States by Zach Highley LLC. This policy applies to Hestya at gethestya.com and the personal data handled through the service.
Hestya only accesses a connected service after you choose to connect it. Access to the beta is also limited by a private allowlist.
Data we collect
Depending on what you choose to use, Hestya collects:
- Account and sign-in data. Sign-in is provided through Supabase Auth — with Google, or with an email address and password.
- Google Calendar data. Read-only calendar events, which are cached server-side so Hestya can show your schedule.
- Gmail data. Read-only unread-message summaries. This connection is currently available only to beta volunteers.
- Financial data. Bank balances — and, where a connection has transactions enabled, transaction history — you connect through SimpleFIN or Plaid, plus the manual accounts and portfolio valuations you enter yourself. Bank connections are always user-initiated.
- Apps and feeds you connect. Optional connections such as calendar feeds (ICS URLs), GitHub, Todoist, Slate (your saved-reading queue — titles and compact metadata only, never article text), YouTube channels, a weather location, and market watchlists. Access tokens and secret feed URLs are encrypted at rest, and fetched items are cached server-side so Hestya can show them to you. If you connect Slate, Hestya can also send a link you submit to your Slate account to save it — the only place Hestya writes outside your own records besides calendar events you explicitly accept.
- Content you create. Todos, captures, notes, routines and their check-ins, and other entries you add to Hestya.
- Optional computer statistics. System statistics that you configure your own device to send to Hestya.
- Beta access requests. If you request an invite, the email address you submit, your optional note, and your browser's user-agent string.
- Product usage events. First-party records of product events (for example a sign-in or a sync), linked to your account, with small technical metadata. These stay inside Hestya and are used only to operate and improve the beta.
- Feedback you send. If you send feedback through Hestya, we store your message, the page it came from, and your account's email address.
How we use data
We use your data only to provide and operate Hestya, including to:
- authenticate you and enforce the private allowlist;
- display your own calendar, mail summaries, balances, notes, todos, captures, routines, connected app and feed items, and device statistics to you;
- generate your personal daily brief and answer questions you ask inside Hestya;
- understand how the beta is used and fix problems, using the first-party usage events described above; and
- maintain the security and reliability of the beta.
We do not sell personal data or use it for advertising.
Google user data
Google Calendar and Gmail access is optional. Calendar and mail imports are read-only; if you separately grant calendar write access, Hestya can create only events you explicitly accept. Hestya uses information received from Google APIs only to provide your own calendar and mail information inside Hestya. It is never sold, shared for another party's own purposes, or used for ads.
Hestya's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
AI-generated daily brief
Hestya uses Anthropic's API to generate a daily brief from your own connected data, and to answer questions you ask through Hestya's built-in tools (for example the coach and ask features, currently owner-only). For these requests Hestya sends Anthropic the question and the relevant items from your own connected data — such as calendar events, mail summaries, balances, and tasks — as a service provider. Anthropic does not use API inputs to train its models by default.
Hestya does not use one user's data to create another user's brief or answers.
Storage and security
Hestya stores data in Supabase Postgres in the United States. OAuth refresh tokens are encrypted at rest using AES-256-GCM. Database row-level security separates each user's records.
We use these safeguards to protect your data, but no online service can guarantee absolute security.
Retention and deletion
Google, bank, and app/feed connections disconnect in Settings. Computer statistics stop when your device stops sending them; the owner-only SSOT bridge is managed outside Settings. Disconnecting deletes the connection's keys immediately. Disconnecting a bank also deletes its cached accounts, balances, and transactions at the same time, though daily balance snapshots recorded while it was connected remain part of your net-worth history until you delete your account. Removing an app or feed deletes its cached items. Calendar events and mail summaries imported before a Google disconnect are retained and labeled by freshness until you delete your account.
We process personal data to provide the service you signed up for and to run the beta safely (our legitimate interest in securing and improving it). Usage events are linked to your account and are removed automatically when the account is deleted. A beta access request and any feedback you send are stored under your email address rather than your account row, so they are removed by hand as part of your deletion request, or earlier if you ask.
Full account deletion is manual during the beta. Email zach@zhighley.com to request deletion of your Hestya account and associated data. You may also email us to request an export of your Hestya data.
Changes to this policy
Hestya is in beta, so its features may change. If this policy changes, we will update the date at the top of this page. We will provide additional notice when a change materially affects how we handle personal data.
Contact
For privacy questions, data requests, or account deletion, contact Zach Highley LLC at zach@zhighley.com.