Legal
Privacy policy
Last updated: July 20, 2026
1. Who we are
SmittyHQ, LLC ("Smitty," "we," "us") provides a privacy-first assistant for family and household logistics. You can interact with Smitty over SMS/text, WhatsApp, email, and our authenticated web app. Our AI-powered conversational features (including Q&A) are available over SMS, WhatsApp, and email; the web app is used for setup, viewing your plans, and managing your account and settings.
The data controller responsible for your information is SmittyHQ, LLC, 1869 Catalina Ave, Berkeley CA 94707.
This policy explains what data we collect, why, how long we keep it, who processes it, and how you can access or delete it.
2. Data we collect
Account data: your email address, zip code, optional phone number, household name, and authentication identifiers. We support passwordless sign-in (magic link / one-time code) and email-and-password sign-in; depending on the method you choose, we process the corresponding credentials and login identifiers.
Content you share with us: emails (and their attachments) you forward to your private Smitty address; messages and supported voice notes you send over SMS, WhatsApp, or the web app; and questions you ask our assistant over SMS, WhatsApp, or email. This content often includes information about other people in your household — see Section 4.
Sensitive information: because Smitty helps run a family's life, the content you share may include sensitive details such as health or medical appointments, information about children, and school or care arrangements. Voice notes may also capture sensitive audio (for example, a child's voice or a health-related message); we send this audio to OpenAI only to transcribe it, then handle the transcript with the same care as your other content. We treat all such information as confidential and use it only to provide the features you've asked for. We do not use it for advertising and we never sell it.
Derived data: events, action items, reminders, lists, and other structured information we generate from the content you share.
Operational metadata: timestamps, delivery receipts, error logs, and usage telemetry needed to operate and debug the service. Our logs use strict allowlists and never include message bodies, chat content, attachments, voice audio, or family-profile fields.
Web app data: authentication/session: we use Supabase session tokens to keep you signed in.
Web app data: local browser storage: we store certain preferences and operational values in your browser's localStorage/sessionStorage, including your household identifier, onboarding progress flags, timezone reporting, view/display preferences, invite code, and calendar debug flags. These stay on your device and are used to run the app.
Product analytics: we use Google Analytics only if you opt in, and it is off by default. You can change your choice at any time in the Privacy choices link in our website footer or in authenticated app settings. If you opt in, Google Analytics runs across our website and signed-in app and sets cookies that share certain device and usage identifiers with Google, to help us understand how Smitty is used so we can improve it. We do not intentionally send the contents of your household — your messages, forwarded emails, attachments, voice notes, or family profiles — to Google Analytics.
Zip Code: We collect your home ZIP code to determine the location and time zone relevant to messaging compliance. If you enable location-based features such as weather forecasts, we also use your ZIP code to provide those features. We do not use your ZIP code to send location-based advertising or sell it to third parties.
3. Google API Services and Google user data
Google data we access
If you choose to connect a Google Account, Smitty uses Google OAuth to request read-only access to certain Google Account and Google Calendar information. Depending on the permissions you grant, Smitty may access:
- Your Google Account identifier and email address;
- Information about the calendars available through your Google Account, such as calendar identifiers, names, descriptions, time zones, colors, access roles, and selection status;
- Information contained in calendars that you select for synchronization, including event identifiers, titles, descriptions, dates and times, locations, recurrence information, status, organizers, attendees, availability, conferencing information, attachments or links referenced by an event, and other information included in the Google Calendar event record; and
- Technical information necessary to maintain synchronization, including the permissions granted, synchronization tokens, OAuth refresh tokens, connection status, and synchronization timestamps and error information.
Smitty requests read-only Google Calendar permissions. Smitty does not use these permissions to create, modify, or delete events in your Google Calendar.
References in this section to "Google user data" include both information received directly from Google APIs and information Smitty derives from that information.
How we use Google user data
Smitty uses Google user data only to provide or improve user-facing features that you request. Specifically, we may use it to:
- Display the Google Account and calendars available for connection;
- Synchronize events from calendars you select;
- Display selected Google Calendar events alongside other household plans;
- Convert synchronized events into corresponding household calendar items;
- Keep imported calendar items current when an event is added, changed, canceled, or removed in Google Calendar;
- Identify scheduling conflicts and relevant household activities;
- Generate reminders, digests, planning information, and responses from Smitty's assistant;
- Associate calendar events with the appropriate members of your household;
- Maintain and troubleshoot your Google Calendar connection; and
- Protect the security, integrity, and reliability of the service.
Smitty does not use Google user data for advertising, personalized or interest-based advertising, retargeting, credit or lending decisions, data brokerage, or sale to information resellers. Smitty does not sell Google user data.
Smitty does not use Google user data to train general-purpose or shared artificial-intelligence models. Our service providers are not permitted to use Google user data to train their models.
Aggregated, anonymized, and derived Google data
Smitty may create household calendar items and other structured information derived from Google Calendar events in order to provide the features described above. Derived information may include normalized event dates and times, reminders, household-member assignments, scheduling information, and calendar summaries. We treat this derived information as Google user data for purposes of this section.
Smitty does not create, sell, transfer, or use aggregated or anonymized datasets derived from Google user data for advertising, profiling, data brokerage, model training, or other independent commercial purposes.
We may use limited aggregated operational measurements, such as the number of successful or failed synchronization operations, to maintain the reliability and security of the service. These measurements are designed not to contain calendar-event contents, Google Account identifiers, OAuth credentials, or information that identifies a particular user or household.
How Google user data is shared
Smitty does not sell Google user data. We disclose Google user data only as necessary to provide the user-facing features described in this policy, protect the service, or comply with applicable law.
Google user data may be processed by the following categories of service providers acting on our behalf:
- Database, authentication, and storage providers that host account information, OAuth connection records, synchronized calendar information, and derived household items;
- Cloud and application-hosting providers that operate Smitty's backend and web application;
- Artificial-intelligence service providers when Google Calendar information is relevant to a reminder, digest, planning feature, or assistant response requested by the user; and
- Security, monitoring, and technical-support providers where access is necessary to protect, troubleshoot, or operate the service.
Our service providers are contractually restricted to processing the information on our behalf and may not use it for their own advertising, profiling, data brokerage, or model training.
We may also disclose Google user data:
- When required to comply with applicable law, regulation, legal process, or a valid governmental request;
- When reasonably necessary to detect, investigate, prevent, or address fraud, abuse, security incidents, or technical problems; or
- As part of a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, subject to applicable law and, where required by Google's policies, the user's prior explicit consent.
Smitty does not transfer Google user data to advertising platforms, data brokers, information resellers, credit-reporting organizations, or lending providers.
Human access to Google user data
Smitty personnel, contractors, and service providers are not permitted to read Google Calendar event contents except:
- When you affirmatively request or consent to access for support or troubleshooting;
- When access is reasonably necessary to investigate a security incident, suspected abuse, or a technical problem;
- When access is required to comply with applicable law; or
- When the information has been aggregated and anonymized and is used for lawful internal operations.
Any permitted access is limited to authorized personnel with a legitimate need for access and is subject to confidentiality and security obligations.
How Google user data is protected
Smitty uses administrative, technical, and organizational safeguards designed to protect Google user data against unauthorized access, disclosure, alteration, loss, or destruction. These safeguards include:
- Encryption of information in transit using industry-standard transport encryption;
- Encryption of stored Google OAuth refresh tokens;
- Encryption at rest provided through our database, storage, and hosting infrastructure;
- Household-level access controls intended to prevent one household from accessing another household's information;
- Restricted access to production systems and personal information;
- Secure OAuth practices, including state validation, PKCE, nonce validation, and validation of Google identity tokens;
- Revocation and removal of stored OAuth credentials when a Google Account connection is disconnected;
- Logging controls designed not to record OAuth credentials or Google Calendar event contents; and
- Monitoring, testing, and incident-response procedures intended to detect and address unauthorized access.
No method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security.
Retention of Google user data
We retain Google OAuth credentials only while they are needed to maintain a Google Calendar connection. When the last active Google Calendar connection associated with a Google Account is disconnected, Smitty attempts to revoke the authorization with Google and deletes the stored OAuth refresh token. After disconnection, Smitty can no longer retrieve new or updated information from that Google Account unless you reconnect it.
Disconnecting Google Calendar does not automatically delete information that Smitty previously imported or derived from your calendar. Previously synchronized event records, calendar metadata, and derived household items may remain associated with your household so that existing plans, reminders, historical context, and household records are not unexpectedly removed.
Previously imported Google Calendar items and stored copies of Google Calendar data are retained until you remove the applicable imported data, request its deletion, or delete your household. Certain derived items may be retained until the corresponding item or household is deleted.
Short-lived OAuth authorization-state records used to secure the connection process expire after approximately 15 minutes and are subsequently purged from our systems.
Limited security, audit, and operational records that do not contain calendar-event contents or OAuth credentials may be retained for up to 90 days, unless a longer period is required by law or reasonably necessary to investigate a security incident.
Disconnecting Google and deleting Google user data
You may stop Smitty's future access to Google Calendar at any time by:
- Disconnecting the applicable calendar or Google Account through Smitty's settings;
- Revoking Smitty's access through your Google Account permissions; or
- Contacting us at privacy@smittyhq.com.
Revoking access through Google stops future API access but does not, by itself, send Smitty a request to delete data previously obtained from Google.
You may remove imported calendar items using the controls available in Smitty. You may also request deletion by contacting privacy@smittyhq.com.
To delete all Google user data associated with your household, along with your other household information, you may use the household-deletion control in the web application or follow the account-deletion instructions described in the "Retention and deletion" section of this Privacy Policy. Confirmed household deletion permanently removes the household's Google OAuth connection records, stored calendar metadata and event records, imported and derived calendar items, and associated account information from Smitty's active systems, subject to any limited retention required by applicable law or necessary for security, fraud prevention, or dispute resolution.
Google API Services User Data Policy
Smitty's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. Information about children and other people in your household
Smitty is built to help you manage your family's life, so you will often share information about other people — children, partners, caregivers, and household contacts — and that information may include health, school, or other sensitive details.
Children: Smitty is intended for adults managing a household. We do not knowingly allow anyone under 13 (or the minimum age in your country) to create an account, and we do not knowingly collect data directly from children. We never use information about children for advertising or behavioral targeting.
By sharing this information, you confirm you have the authority to do so on those individuals' behalf.
Smitty does not independently verify whether a person has authority to submit, modify, or delete information relating to other members of a household. The account holder is responsible for ensuring they have appropriate authority to share and manage information about others.
- We use it only to provide the service to you (for example, reminders, digests, calendars, and packing lists).
- We do not build advertising or marketing profiles of anyone, we do not show ads, and we never sell or share this data.
- If someone whose information appears in your household wants it corrected or deleted, you can do this directly in the app, or they (or you) can contact privacy@smittyhq.com.
5. How we use your information
We process the content you share to extract events, action items, and context, and to deliver the morning digest, just-in-time pings, and Q&A responses you've signed up for.
We use account and operational data to authenticate you, deliver and secure the service, debug problems, and meet legal obligations.
We do not sell or "share" your data, including as those terms are defined under California law.
We do share your information with carefully selected service providers acting on our behalf to operate Smitty, as described in this Policy. We do not sell your personal information or allow these providers to use it for their own advertising or model training.
We do not allow our AI vendors to train on your messages (see Section 6).
Legal bases (for EU/UK users). Where GDPR or UK GDPR applies, we process your data to perform our contract with you (delivering the service), to comply with legal obligations, and on the basis of our legitimate interests in securing, debugging, and operating Smitty. Where we process sensitive information (such as health-related details), we rely on your explicit consent.
Withdrawing consent for sensitive information. You can withdraw your consent at any time. Because deleting an individual item in the app removes it from your plans and lists but does not necessarily purge the original email or attachment it came from, the way to fully remove your sensitive information is to delete your household (Section 10) or to let your content reach the end of its retention period, after which it is purged automatically.
6. How we use AI
To turn your messages and forwarded content into useful plans, we send the relevant content to vetted AI providers that process it to generate digests, reminders, and answers.
We do not train models on your content, and our AI providers are not permitted to use your content to train their models.
Text processing (Anthropic). Our conversational and organizing features are powered by Anthropic. Anthropic processes your content under our signed data-processing terms, which prohibit retaining your content beyond what's needed to return a result and prohibit training on it.
Voice transcription (OpenAI). If you send a supported voice note (and have opted in), we send the audio to OpenAI's transcription API to create a text transcript. OpenAI's published API data controls list the transcription endpoint (/v1/audio/transcriptions) as not used for training, with no abuse-monitoring retention and no application-state retention. Once transcribed, the transcript is handled like any other message text and is used only to provide the assistant features you requested. We do not create voiceprints and do not use audio to identify speakers.
We send only what's needed to perform the task and minimize personal details where we can.
AI output can be wrong, incomplete, or out of date, and transcriptions may contain errors. Please don't rely on Smitty as a substitute for professional medical, legal, or financial advice, and double-check anything important.
7. Subprocessors
We rely on a small number of vetted vendors to operate Smitty, including:
- Supabase — database and authentication
- Railway — backend hosting
- Vercel — web hosting
- Twilio — SMS and WhatsApp message delivery
- Stripe — payment processing, invoices, and subscription billing
- Postmark — transactional email delivery
- Anthropic — AI processing for the assistant
- OpenAI — voice transcription for supported voice notes
- Google Analytics — product analytics (only if you opt in)
- All vendors operate under signed data-processing agreements. WhatsApp messages are delivered via Twilio and Meta's WhatsApp platform, whose handling of message delivery is subject to their own terms. A current subprocessor list is available on request at privacy@smittyhq.com.
8. International data transfers
Some of our subprocessors may process data outside your home country, including outside the EEA or UK. Where we transfer personal data internationally, we use appropriate safeguards such as Standard Contractual Clauses (SCCs) or the UK International Data Transfer Addendum. You can request more detail at privacy@smittyhq.com.
9. Messaging and consent (SMS and WhatsApp)
When you sign up to receive messages from Smitty, you consent to receive service and transactional messages — such as digests, reminders, confirmations, command responses, and support replies — at the number you provide, over SMS and/or WhatsApp. Message and data rates may apply. We do not send marketing messages.
- Reply STOP at any time to opt out of all Smitty messaging, including both SMS and WhatsApp. Reply HELP for help.
- You can also manage or revoke messaging in the web app.
10. Retention and deletion
Deleting your household. To permanently delete everything, text DELETE to Smitty (or use the delete control in the web app). This starts a 24-hour confirmation window: to complete the deletion you must reply DELETE CONFIRM. Deletion requires this confirmation step. After you confirm, your household data — including messages, calendar feed, attachments, derived items, and account — is removed from our active systems. A 24-hour post-confirmation undo window is being introduced; until then, please treat confirmation as irreversible.
- Forwarded emails and attachments (raw content) are retained for 30 days or less, then automatically purged. Retention is not user-configurable.
- Voice note audio is sent to OpenAI only to produce a transcript and is deleted immediately after transcription (including from Twilio media storage on our account). After that, only the transcript is retained, under the same rules as your other content.
- Derived items (events, lists, reminders) are kept until you delete them or close your household. Deleting an individual item marks it as deleted and removes it from your plans and lists; the original inbound email or attachment it was created from is removed when it reaches the end of its retention period (above) or when you delete your entire household.
- Operational logs are retained for 90 days and then purged.
11. Your rights
Depending on where you live, you may have the right to access, correct, export, delete, or restrict your personal data, to object to certain processing, and to withdraw consent. Email privacy@smittyhq.com to exercise any of these rights, and we'll respond within the timeframes required by law.
Because Smitty contains information about other household members, requests from a non-account holder will be handled directly and may require us to verify identity and authority.
- California residents (CCPA/CPRA): you have the right to know, delete, correct, and to limit the use of sensitive personal information. We do not sell or share your personal information, and we do not use sensitive information for purposes beyond providing the service.
- EU/UK residents (GDPR/UK GDPR): the rights above apply, and you may lodge a complaint with your local supervisory authority (in the UK, the ICO; in the EU, your national data protection authority).
12. Security incidents
We aim to notify affected users within 72 hours after confirming a security incident that materially affects their personal information, unless a longer period is required or permitted by applicable law or law enforcement.
13. Changes to this policy
If we make material changes, we'll notify you by email and in the web app at least 30 days before they take effect.
14. Contact
Privacy questions: privacy@smittyhq.com. Security questions: security@smittyhq.com. General: hello@smittyhq.com.