Legal
GDPR CompliantPrivacy Policy
We value your trust. Transparency is our core currency.
Last updated May 28, 2026
Introduction
How we protect your privacy
Welcome to Heightss ("we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our web application at heightss.com(the "Service").
We are committed to protecting your personal information and your right to privacy. If you have any questions or concerns about this policy, or our practices with regards to your personal information, please contact us at heightss@heightss.com.
By using our Service, you agree to the collection and use of information in accordance with this Privacy Policy. Please also review our Terms of Service.
Data Collection
What information we collect
To provide our AI-powered investment and scheduling services, we collect and request access to specific data. We only request the minimum access required for functionality.
Information You Provide
Account Information
Name, email, and profile picture from registration or Google Sign-In.
Google Calendar
Read/Write access for investment-related events. We only access Heightss-created events.
Phone Number
(Optional) Used strictly for Multi-Factor Authentication to secure your account.
User Content
Journal entries, watchlists, notes, and preferences you create within the Service.
Automatically Collected Information
- Device Information: Browser type, operating system, device identifiers
- Usage Data: Pages visited, features used, time spent on pages
- Log Data: IP address, access times, referring URLs
- Analytics: Aggregated usage patterns via Google Analytics
Google API Disclosure
Google Limited Use Policy compliance
Mandatory Compliance Statement
Why We Access Google Data:
Heightss integrates with Google Calendar to help you schedule and manage investment-related events, earnings calls, and portfolio review reminders through our AI assistant.
What Data We Access:
- calendar.events scope: Create, read, update, and delete calendar events. We only interact with events created by Heightss.
- Basic profile info: Email and name for authentication purposes only.
How We Use Google Data:
- Create calendar events for scheduled investment activities
- Display your upcoming events within the Heightss interface
- Send reminders for earnings calls and portfolio reviews
Data Storage: Google OAuth tokens are encrypted using AES-256 encryption and stored securely in our database. We do not store the content of your existing calendar events.
Revoking Access: You can disconnect Google Calendar at any time from your Heightss profile settings or from your Google Account permissions page. When disconnected, we immediately delete your stored OAuth tokens.
AI Features (Anthropic)
How AI features process your data
Heightss uses AI features powered by Anthropic, PBC (Claude). When you use these features, we send certain information to Anthropic so the model can generate responses.
What we send to Anthropic:
- Chat messages: Text you send in Heightss AI conversations, including follow-up messages and context needed to answer your questions.
- Financial queries: Investment-related questions and prompts, such as stock lookups, portfolio questions, journal analysis requests, and other finance-focused inputs you submit through AI features.
We send this data only to provide AI-powered functionality within Heightss. Anthropic processes it according to its own privacy practices. For details on how Anthropic handles data, see the Anthropic Privacy Policy.
Data Usage
How we use your data
No AI Training on Private Data
We do not use your Google Workspace data to train generalized AI models shared outside your specific user account context. Your data models are isolated.
No Human Access Without Consent
We do not allow humans to read your data unless:
- We have obtained your affirmative agreement
- It is necessary for security purposes (e.g., investigating abuse)
- To comply with applicable laws or valid legal process
- For internal operations where data has been aggregated and anonymized
No Advertising
We do not use or transfer your data for serving advertisements, including retargeting, personalized, or interest-based advertising.
No Selling of Data
We never sell, rent, or trade your personal information to third parties for their marketing purposes.
Usage Analytics
How we measure product usage, and what we never record
We collect first-party usage analytics to understand how Heightss is used and to make it better. This data is processed on our own infrastructure and is never sold, shared, or disclosed to third parties.
What we record:
- Pages viewed — as generic route patterns (for example
/journal/:id), never the specific entry, community, or AI session identifier. - Time spent on each page, measured only while the tab is in the foreground.
- Interactions — click positions, scroll depth, and which on-screen control was used.
- Feature usage — which features are opened and completed, so we can find where people get stuck.
- Performance — page load speed, responsiveness, and errors, measured on your device.
- Device context — screen size category (mobile, tablet, desktop) and the referring website's domain.
What we never record:
- Anything you type — no keystrokes, no form values, no search terms
- The content of your journal entries, community messages, or AI conversations
- Text shown on screen, or screen recordings of your session
- Web addresses you visit outside Heightss
Analytics are stored against your account so we can measure things like whether a feature is used more than once. Access is restricted to a small number of named Heightss personnel, every access is logged, and the data is used only in aggregate— to answer questions like "how many people finish creating a journal entry", never to profile an individual.
Detailed interaction records are automatically deleted after 90 days. Only aggregate counts, which contain no personal data, are kept beyond that. See Data Retention and Your Rights.
This is separate from the third-party Google Analytics described under Cookies.
Data Retention
How long we keep your data
We retain your data for as long as necessary to provide our services and fulfill the purposes described in this policy:
- Account Data: Retained while your account is active. Deleted within 30 days of account deletion request.
- Google OAuth Tokens: Retained while Google Calendar integration is connected. Immediately deleted when you disconnect.
- Journal Entries & User Content: Retained while your account is active. You can delete individual entries at any time.
- Usage Analytics — detailed records: Individual interaction records (pages viewed, time spent, clicks) are automatically deleted after 90 days.
- Usage Analytics — aggregate counts: Daily totals containing no personal data (e.g. "412 people opened the journal on 12 August") are retained for up to 24 months for trend analysis.
- Log Data: Retained for up to 90 days for security and debugging purposes.
After deletion, data may persist in encrypted backups for up to 30 additional days before being permanently purged.
Your Rights
Access, correct, or delete your data
You have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal data ("right to be forgotten")
- Data Portability: Request your data in a structured, machine-readable format
- Withdraw Consent: Withdraw consent for data processing at any time
- Restrict Processing: Request that we limit how we use your data
- Object: Object to processing of your data for certain purposes
How to Exercise Your Rights:
- Email us at heightss@heightss.com
- Use the settings in your Heightss profile
- For Google data: Visit Google Account permissions
We will respond to your request within 30 days. We may ask you to verify your identity before processing.
Third-Party Services
Services we integrate with
We integrate with the following third-party services:
- Google (OAuth, Calendar): Authentication and calendar integration - Privacy Policy
- WorkOS: Authentication infrastructure - Privacy Policy
- Google Analytics: Usage analytics - Privacy Policy
- Anthropic, PBC (Claude AI): AI-powered chat and financial analysis — see AI Features (Anthropic) above; Anthropic Privacy Policy
- Sentry: Error monitoring - Privacy Policy
Each third-party service has its own privacy policy. We encourage you to review their policies.
Security
How we protect your data
We implement industry-standard security measures to protect your data:
- Encryption: All data transmitted over HTTPS/TLS 1.3. Sensitive data encrypted at rest using AES-256.
- Authentication: Secure OAuth 2.0 implementation with PKCE. Optional two-factor authentication.
- Access Control: Role-based access control for internal systems. Regular access audits.
- Infrastructure: Hosted on secure cloud infrastructure with SOC 2 compliance.
- Monitoring: 24/7 security monitoring and incident response procedures.
While we strive to protect your information, no method of transmission over the Internet is 100% secure. Use strong, unique passwords and only access the Service within a secure environment.
Community Message Encryption
How community chat is encrypted — and what that does not cover
Every message sent in a Heightss community is encrypted before it is written to our database. This is on by default for all communities and all members. There is no setting to turn it on or off, and nothing for a community owner to misconfigure.
How it works
- In transit: HTTPS/TLS 1.3 between your device and our servers.
- At rest: each message body is encrypted with AES-256-GCM, an authenticated cipher, using a unique random initialisation vector per message. Tampering with stored data is detected and rejected rather than silently returned.
- Key custody: the encryption key is held by Heightss in our infrastructure secret store, separate from the database itself. A copy of the database — a stolen dump, a leaked backup, a compromised replica — cannot be read without that key.
- Row binding: each encrypted message is cryptographically bound to the community and author it belongs to, so a stored message cannot be moved into a different community or reattributed to a different person without breaking decryption.
This is not end-to-end encryption
We want to be precise, because "encrypted" is often used loosely. Heightss holds the encryption key, which means our servers are technically able to decrypt community messages. We are not able to honestly claim, as an end-to-end encrypted messenger can, that it is impossible for us to read your messages.
This is a deliberate trade-off. In a true end-to-end system the keys live only on your devices, so signing in on a new phone or laptop requires transferring a key or entering a long recovery code — and losing that code means permanently losing your chat history. We chose to hold the key so that you can sign in to any device and have your communities work immediately, with no key management and no risk of locking yourself out.
What this protects against, and what it does not
Protected
- Theft or leak of a database backup or snapshot
- Direct database access that bypasses the application
- Someone reading message rows with a database client
- Undetected modification of stored messages
Not protected
- A compromise of our application servers, which hold the key
- A lawful order compelling us to produce message contents
- Other members of a community you have joined
- Anyone with access to your own signed-in device
Attachments — images and files shared in chat — are stored in our object storage and are protected by access control rather than by this message encryption key. AI features only process a community's message content when a member explicitly invokes them; see the AI & Anthropic section.
If your threat model requires that no provider can ever read your messages, you should use a dedicated end-to-end encrypted messenger for that conversation rather than a Heightss community.
Children's Privacy
Not intended for users under 18
Heightss is not intended for users under 18 years of age. We do not knowingly collect personal information from children under 18.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us at heightss@heightss.com. We will take steps to delete such information promptly.
International Transfers
Cross-border data handling
Heightss is based in India. Your information may be transferred to and processed in countries other than your country of residence, including India and the United States (where our cloud infrastructure providers operate).
These countries may have data protection laws different from your country. By using our Service, you consent to the transfer of your information to these countries.
We ensure appropriate safeguards are in place for international transfers:
- Standard contractual clauses approved by relevant authorities
- Data processing agreements with our service providers
- Use of service providers with appropriate certifications (SOC 2, ISO 27001)
Policy Changes
How we notify you of updates
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page
- Notify you via email (for registered users)
- Display a prominent notice on the Service
We encourage you to review this Privacy Policy periodically. Your continued use of the Service after changes constitutes acceptance of the updated policy.
Contact Us
Get in touch with questions
If you have questions or concerns about this Privacy Policy or our data practices, please contact us:
Email: heightss@heightss.com
Website: https://heightss.com