LegalHisendy

Privacy Policy

Last updated 21 September 2026

The short version
We never sell personal information, and we never will.
Your mailbox credentials are encrypted at rest and never reach a browser, including yours.
Everything in your workspace can be exported or deleted by you, from Settings, without asking us.
Recipient data you upload is yours. We process it to run your campaigns and for nothing else.

Who we are

Hisendy is operated by Hisendy, an independent software business. For anything in this policy you can reach us at privacy@hisendy.com.

For the contacts you upload and email, you are the data controller and Hisendy is your processor. For your own account, billing and support data, Hisendy is the controller.

What we collect, and why

DataWhy we have itHow long we keep it
Your accountName, work email, organization, hashed password. Needed to give you an account and to bill you.While the account exists, then 30 days
Mailbox connectionsOAuth tokens or IMAP and SMTP credentials for the mailboxes you connect. Needed to send as you.Until you disconnect the mailbox, then deleted immediately
Contacts you importWhatever columns are in your file. Needed to run the campaign you built.Until you delete them, or 30 days after the account closes
Message contentSequences you write or approve, and replies that come back. Needed for the shared inbox and the stop rules.Until you delete the campaign, or 30 days after the account closes
Sending recordsWhich message went to which contact, when, and what happened. Needed for the ramp, the stop rules and your reports.13 months, then aggregated
Product usagePages used, actions run, credits spent. Needed for the credit ledger and to find bugs.13 months

Your mailbox

When you connect a Google or Microsoft mailbox we ask for the narrowest scopes that let us send as you and read the replies to what we sent. We do not read the rest of your mail, and the token is stored encrypted at rest.

Mailbox tokens, and any IMAP or SMTP credentials, are encrypted with a key held outside the database. They are decrypted only inside the worker, at the moment it talks to your mail provider, and they are never returned to a browser, including yours. Once you disconnect a mailbox the record is deleted, not archived.

Signing in with Google or Microsoft proves who you are. It does not give Hisendy your mailbox. Those are two separate grants and you make the second one later, deliberately.

Sendy AI and the model

When you run one of the nine AI actions, the input for that action is sent to Anthropic to produce the result. Input is trimmed to the ceiling for that action before it is sent, so an action never sends more of a thread than it needs.

Model output is stored in your workspace as a draft. It is never sent to a recipient without a person approving it. We do not use your data, your contacts or your messages to train any model, and our agreement with Anthropic does not permit them to either.

Who else touches your data

Only the four processors listed on our Sub-processors page. We publish that list, we keep it current, and we give notice before adding to it.

We do not sell personal information and we do not share it for cross context behavioural advertising. There is a Do Not Sell or Share page anyway, because you should not have to take our word for it.

Your rights

Access. Export everything in your workspace from Settings, as CSV, without asking us.
Correction. Edit any contact or account field in the product.
Deletion. Delete a contact in the product, archive a campaign, or close the whole account from Settings. Closing the account deletes the workspace data 30 days later.
Portability. The export is plain CSV and JSON, not a proprietary format.
Objection and restriction. Email privacy@hisendy.com and we will action it within 30 days.

If you are a recipient of an email sent through Hisendy rather than a customer, the unsubscribe link in that message removes you from that sender permanently. You can also email privacy@hisendy.com and we will pass the request to the customer and suppress you on our side.

Where your data sits

The application and database run on Cloudflare, with the primary region in Europe. Model calls go to Anthropic in the United States, payment to Paddle, and our own transactional mail through Resend. Transfers outside the UK and the EEA rely on the International Data Transfer Agreement and Standard Contractual Clauses, which are in our Data Processing Agreement.

Security

Encryption in transit and at rest, session expiry after 30 minutes idle by default and 7 days absolute, and every database query filtered by workspace on the server rather than in the browser. The Security page has the detail and the route for reporting a vulnerability.

Changes

If we change anything that affects what we do with your data, we email every account owner at least 14 days before it takes effect, and the date at the top of this page changes.