Last updated 21 September 2026
Hisendy is operated by Hisendy, an independent software business. For anything in this policy you can reach us at privacy@hisendy.com.
For the contacts you upload and email, you are the data controller and Hisendy is your processor. For your own account, billing and support data, Hisendy is the controller.
When you connect a Google or Microsoft mailbox we ask for the narrowest scopes that let us send as you and read the replies to what we sent. We do not read the rest of your mail, and the token is stored encrypted at rest.
Mailbox tokens, and any IMAP or SMTP credentials, are encrypted with a key held outside the database. They are decrypted only inside the worker, at the moment it talks to your mail provider, and they are never returned to a browser, including yours. Once you disconnect a mailbox the record is deleted, not archived.
When you run one of the nine AI actions, the input for that action is sent to Anthropic to produce the result. Input is trimmed to the ceiling for that action before it is sent, so an action never sends more of a thread than it needs.
Model output is stored in your workspace as a draft. It is never sent to a recipient without a person approving it. We do not use your data, your contacts or your messages to train any model, and our agreement with Anthropic does not permit them to either.
Only the four processors listed on our Sub-processors page. We publish that list, we keep it current, and we give notice before adding to it.
We do not sell personal information and we do not share it for cross context behavioural advertising. There is a Do Not Sell or Share page anyway, because you should not have to take our word for it.
If you are a recipient of an email sent through Hisendy rather than a customer, the unsubscribe link in that message removes you from that sender permanently. You can also email privacy@hisendy.com and we will pass the request to the customer and suppress you on our side.
The application and database run on Cloudflare, with the primary region in Europe. Model calls go to Anthropic in the United States, payment to Paddle, and our own transactional mail through Resend. Transfers outside the UK and the EEA rely on the International Data Transfer Agreement and Standard Contractual Clauses, which are in our Data Processing Agreement.
Encryption in transit and at rest, session expiry after 30 minutes idle by default and 7 days absolute, and every database query filtered by workspace on the server rather than in the browser. The Security page has the detail and the route for reporting a vulnerability.
If we change anything that affects what we do with your data, we email every account owner at least 14 days before it takes effect, and the date at the top of this page changes.