1. Scope
This Privacy Policy describes how Kollective LLC, operating under the Hey Laika name (“Hey Laika,” “we,” “us,” or “our”), handles personal information when you visit www.heylaika.app, join the waitlist, use the Hey Laika web application or iOS beta distributed through TestFlight, forward messages for processing, use Ask Laika, receive notifications, or contact us (collectively, the “Service”).
The Service is intended for adults in the United States who coordinate family logistics. It is user- and email-based. We do not ask about or require relationship status, household structure, custody, or living arrangements.
2. Information we collect
Account and profile information
When an adult creates or uses an account, we collect information such as the person’s name, email address, account and family identifiers, authentication and session records, family display name, home city and state, and time zone. Hey Laika uses passwordless email links or codes for ordinary account access.
Family members and child-related information
Adults may provide the names and email addresses of invited adult users and information about children, such as names, schools or camps, grade or group information, colors used in the interface, and dates associated with enrollment or routing. Children do not create Hey Laika accounts. We do not ask adults to identify their relationship to one another or describe living arrangements.
Forwarded emails and attachments
When an authorized user forwards a message to a family’s Hey Laika address, we receive the message body, subject, sender and recipient information, dates, message identifiers, headers, attachment names and metadata, and other content included in or associated with the message. Supported PDF and image attachments may be fetched and processed transiently during extraction; Hey Laika does not store the attachment files in its application database or file storage. Forwarded content may contain information about children, family members, senders, schools, camps, teams, organizations, and other people.
Extracted and created family-plan information
We create and store structured information from forwarded messages and user actions, including events, dates, times, tasks, deadlines, costs, locations, status updates, summaries, source references, child or adult associations, and limited routing rules. We also retain a bounded, paraphrased family-memory record and its search embedding so the Service can retrieve useful context without preserving a second copy of the raw message. Users may also create or edit plan information directly.
Ask Laika information
We collect questions and requests submitted to Ask Laika and store the resulting answers, support status, citations, model and prompt provenance, conversation titles, and any reviewable calendar drafts or proposals. Ask Laika conversations are private to the adult account that created them, as described in Section 5.
Notifications and device information
If you enable notifications, we collect an Expo push token, device platform, registration and enablement status, and temporary delivery-ticket identifiers needed to route, troubleshoot, and stop notifications. Your device, Expo, and Apple also process permission and delivery information under their own settings and policies.
Website, security, and diagnostic information
Our hosting, authentication, and security providers process technical information needed to operate and protect the Service. This can include an IP address, request date and time, page or endpoint requested, browser or device type, operating system, app version, HTTP headers, authentication and security events, and error or performance details. When you activate the waitlist form, Cloudflare Turnstile may process browser and network signals to distinguish people from automated traffic. We do not send the waitlist email field to Turnstile.
Closed-beta product analytics
When you use the signed-in web application or iOS beta, we may record a small set of product interactions in PostHog. Each event may include your pseudonymous account and family identifiers, the client platform, and a bounded label describing the interaction or outcome. The approved event categories are app availability, onboarding-step views, setup-checklist views, opening invitation or email-forwarding guidance, calendar-save attempts and outcomes, and notification-permission outcomes.
Waitlist and support information
When you join the waitlist, we collect the email address you submit, your Hey Laika segment and topic preferences, and the date and time of your first signup. The waitlist does not verify that you own the submitted address. If you contact us, we receive your contact details and the content and attachments you provide.
3. Where information comes from
We receive information:
- from you, when you create an account, configure a family, forward a message, create or edit a plan item, ask a question, enable notifications, join the waitlist, or contact us;
- from other authorized adult users, when they invite you, add family information, or act in a shared family view;
- from forwarded messages and their senders, including schools, camps, teams, activity providers, and other people or organizations whose messages an adult chooses to forward;
- from your browser, device, and operating system, through requests, permission settings, authentication, and optional notification registration; and
- from our service providers, such as delivery results, security signals, authentication events, and infrastructure diagnostics.
4. How we use information
We use the information described above to:
- create accounts, authenticate users, and manage invitations and access;
- receive messages and extract events, tasks, costs, locations, and other logistics;
- build, synchronize, display, edit, and search the shared family plan;
- route information conservatively to the appropriate child or adult;
- provide grounded Ask Laika answers and reviewable event or status proposals;
- deliver optional reminders, account messages, invitations, and service notices;
- operate the website and waitlist and send requested early-access updates;
- provide support and respond to privacy requests;
- protect the Service, prevent abuse, troubleshoot errors, and improve reliability;
- evaluate and improve product quality using minimized or controlled test data; and
- comply with law, enforce our terms, and protect users, the public, and our rights.
5. Family sharing and private conversations
Adults who have access to the same family can see the shared family plan. This includes family and child profiles, member identity and access information, processed-message summaries and source metadata, extracted or manually created events and tasks, costs, locations, child or adult associations, status changes, and other shared family settings. An authorized administrator may invite or remove adult accounts and manage other access settings. Removing someone ends future access but does not necessarily erase shared records or actions already attributed to that person.
Family memory is shared because it supports the common family plan. Ask Laika conversations, including a user’s questions, answers, and conversation drafts, are private to the adult account that created them. Other family members may still see shared plan changes that the user separately confirms, and a private answer may cite shared source information that authorized family members can already access.
Only invite people you intend to authorize. If your access changes, contact us if you need help understanding or removing information associated with your account.
6. Artificial intelligence processing
We use OpenAI’s API to help extract structured logistics, create bounded family memory and search embeddings, interpret certain requests, and generate grounded answers. Depending on the task, we send OpenAI only the portions of forwarded content, structured family information, private conversation context, and instructions needed to perform that task. Retrieved context, query embeddings, hidden reasoning, and raw email content are not stored in Hey Laika conversation threads.
Hey Laika configures OpenAI response requests with store: false, so OpenAI application-state storage is disabled for those requests. OpenAI states that API data is not used to train its models by default unless the customer opts in. OpenAI may still keep abuse-monitoring logs containing customer content for up to 30 days, unless a longer period is legally required or different approved data controls apply. See OpenAI’s API data controls. Hey Laika does not claim that this default arrangement provides zero data retention.
7. Forwarded email processing
A forwarded email is temporarily copied into Hey Laika’s application database for extraction. After extraction succeeds, the raw body is deleted in the same database transaction that stores the structured extraction, operational summary, family memory, and plan items. A separate hourly cleanup deletes any raw-ingestion record after it has been present for more than 24 hours, including failed or interrupted processing attempts.
The structured logistics, short summary, bounded paraphrased memory, search embedding, and limited source metadata remain as described in Section 10. They are designed to preserve useful family context without acting as a verbatim archive of the original message or attachment.
Resend receives the original message before delivering it to Hey Laika. As of this Policy’s effective date, Resend’s documented receiving interface does not provide Hey Laika with a supported way to delete or set an expiration for that provider-side received-email copy. We therefore cannot promise immediate deletion from Resend. Resend controls that copy under its own retention practices while we evaluate a provider or control that better matches our deletion model. Deleting data from Hey Laika also does not delete the message from the sender’s or user’s email account.
8. Service providers and other disclosures
We use the following providers to operate the current Service:
- Supabase provides authentication, database, storage, and server-side functions. See Supabase’s Privacy Policy.
- Resend receives forwarded messages, sends authentication, invitation, lifecycle, and other service emails, and stores the marketing waitlist. See Resend’s Privacy Policy.
- OpenAI provides the artificial intelligence and embedding processing described in Section 6. See OpenAI’s Privacy Policy and API data controls.
- Vercel hosts the public website and web application, provides related request and security infrastructure, and provides the production website analytics described in Section 9. See Vercel’s Privacy Notice.
- Cloudflare provides Turnstile bot detection for the website waitlist. See Cloudflare’s Turnstile Privacy Addendum.
- Expo and Apple support iOS beta distribution, app builds, optional push delivery, and device services. See Expo’s Privacy Policy and Apple’s Privacy Policy.
- Google Maps Platform provides optional U.S. city suggestions during family setup and resolves a selected city to a normalized city, state, and time zone. Provider place identifiers and autocomplete session tokens are transient and are not stored by Hey Laika. See Google’s Privacy Policy.
- Sentry provides error monitoring for the web application, iOS app, and server-side functions. See Sentry’s Privacy Policy.
- PostHog provides the closed-beta product analytics described in Section 9. See PostHog’s Privacy Policy.
We configure provider accounts and technical controls to limit information to what is needed for the services they perform. Providers process information under their applicable agreements and policies and may process technical or service data under their own terms where they act independently, such as Apple’s operation of TestFlight and device services.
We may also disclose information to professional advisers, regulators, law enforcement, or other parties when reasonably necessary to comply with law, respond to valid legal process, investigate abuse, protect rights or safety, or complete a merger, financing, acquisition, reorganization, or sale of assets.
We do not sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising.
9. Cookies and analytics
We use Vercel Web Analytics on the production public website to understand aggregate site traffic and improve our content. It may report a page view and page route, referring site, approximate city and country, browser, operating system, and device category. Our implementation removes URL query strings and fragment identifiers before sending a page view and does not send custom analytics events.
Vercel describes Web Analytics as cookie-free and anonymous and states that its temporary visitor-session hash is discarded after 24 hours. We do not send waitlist email addresses, form contents, Turnstile tokens, account or family identifiers, child-related information, forwarded-email details, or Ask Laika questions to analytics. We do not use this analytics data for advertising, cross-site tracking, or behavioral profiling.
We may use Sentry to detect and diagnose software errors. When enabled, Hey Laika configures Sentry to receive minimized technical diagnostics such as app, build, runtime, platform, device, and operating-system versions; a fixed error category; and sanitized code locations. We do not intentionally send Sentry forwarded-email content, family-plan or calendar content, Ask Laika conversations, names, email addresses, account or family identifiers, request bodies or headers, page URLs, screenshots, session replays, or activity breadcrumbs. Sentry is configured not to store client IP addresses, and Hey Laika filters derived city, region, and country values from stored events.
We may use PostHog during the closed beta to understand whether the limited product flows listed in Section 2 are working and where people encounter difficulty. Events may include a pseudonymous Supabase account identifier, a pseudonymous family identifier when one exists, the client platform, and one of the bounded interaction labels listed above. We do not send PostHog names, email addresses, child or family profile details, forwarded-email content, message summaries, calendar titles, notes, dates, times or locations, Ask Laika text or citations, page URLs, device details, or free-form error messages.
PostHog autocapture, page-view collection, session replay, heatmaps, exception capture, surveys, feature flags, person profiles, cookies, and persistent local analytics storage are disabled. When PostHog is enabled, the project is configured to discard client IP data and not derive or store location from the request. We do not use Sentry or PostHog for advertising, cross-site tracking, or behavioral profiling.
The Service may otherwise use strictly necessary local storage, cookies, or comparable technologies for authentication, preferences, security, and core functionality. Turnstile may use strictly necessary browser technologies to prevent automated abuse. Because the current Service does not sell or share information for cross-context behavioral advertising, a Do Not Track or Global Privacy Control signal does not change its operation.
10. Retention and deletion
- Waitlist. We keep the Hey Laika waitlist record for up to 24 months from the first signup, unless the person joins the beta or asks us to remove it sooner. We may retain a minimal suppression record needed to honor an opt-out.
- Raw forwarded content in Hey Laika. We delete the raw application copy after successful extraction, with the 24-hour cleanup backstop described in Section 7.
- Structured family information. Family profiles, extracted and created plan items, summaries, bounded memory, embeddings, and source metadata generally remain while the family is active, until an authorized user deletes them through an available control, or until the family is deleted.
- Private Ask Laika information. A user’s conversations, messages, citations, and drafts remain until the user deletes the conversation or account, or the associated family is deleted.
- Push information. Push tokens and related registration records remain until notifications are disabled, the token is replaced or reported invalid, the account is deleted, or the information is no longer needed to provide notifications.
- Sentry error diagnostics. The current Sentry Developer plan retains error events for 30 days. Hey Laika may delete an issue and the diagnostic events grouped under it sooner. The configured events do not include a Laika account or family identifier and are not designed for account-level lookup.
- Closed-beta PostHog analytics. The current PostHog account setting permits product-analytics retention for up to seven years, but Hey Laika uses a separate closed-beta project and will delete that entire project when the closed beta ends. The beta configuration deliberately creates no PostHog person profiles. PostHog therefore does not provide a supported way to delete one person’s already-recorded personless events separately; they are removed with the whole beta project. Any post-beta analytics project will require a fresh retention, deletion, and Privacy Policy review before use.
- Support, security, and transactional records. We keep these only as long as reasonably necessary for the request, security, troubleshooting, dispute, or legal purpose, subject to provider and system settings.
A user can delete an Ask Laika conversation or request account deletion through the Service. Account deletion revokes that user’s access and removes user-owned private conversations. Shared family data remains available to other authorized members. If no other active account remains, or an authorized administrator requests family deletion, the family and its family-owned derivatives are scheduled for deletion after a reversible seven-day period. Removing a child profile deletes its routing information and child-specific Ask Laika conversations; shared family messages and plan items may remain without that child association.
Limited copies may remain temporarily in protected backups or provider systems until overwritten under their ordinary schedules. We may retain information when reasonably necessary to comply with law, protect security, prevent fraud, preserve an opt-out, or establish or defend legal claims. The Resend provider-side limitation for received email is described in Section 7.
11. Your choices and rights
You can:
- review and correct available account, family, child, and plan information;
- delete private Ask Laika conversations and use available item controls;
- enable or disable notifications in the Service and device settings;
- request account deletion through the account settings provided in the Service;
- unsubscribe from Hey Laika marketing messages using the link in an email; and
- ask to access, correct, or delete information by emailing contact@kollective.co.
We may need to verify your identity or authority before completing a request. Deletion and access requests are subject to the shared-access consequences and exceptions described in this Policy. Depending on where you live, you may have additional rights, may be able to use an authorized agent, and may have a right to appeal our response. We will not discriminate against you for exercising an applicable privacy right.
12. Children’s privacy
Hey Laika accounts are for adults age 18 or older. The Service is directed to parents and caregivers, not children, and children do not create accounts or submit information directly. An adult who provides child-related information must have the authority to do so and is responsible for deciding what information is appropriate to share.
We do not knowingly collect personal information directly from a child under 13. If you believe a child has created an account or submitted information directly, contact us so we can review and delete it as appropriate. Because adults may provide information about children as part of family logistics, child-related information otherwise follows the access, use, retention, and deletion rules in this Policy.
13. Security
We use administrative, technical, and organizational safeguards intended to protect information, including encrypted transmission, server-side secret handling, access controls and row-level authorization, passwordless authentication, provider account controls, request validation, bot detection, request limiting, and minimized logging. These safeguards reduce risk but no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
14. Where information is processed
The Service is currently intended for people in the United States. We and our providers may process information in the United States and other locations where they operate. If information is transferred across jurisdictions, we use contractual and other safeguards required by applicable law. We will review the legal and transfer requirements before offering the Service in additional countries.
15. Changes to this policy
We may update this Policy as the Service, providers, or legal requirements change. We will post the revised version with a new effective date. If a change materially affects how we use previously collected information, we will provide additional notice and request consent where required by law. We may provide that notice through the Service or by email.
16. Contact
Contact Kollective LLC with questions, privacy requests, complaints, or appeals at contact@kollective.co. Please describe your request and the account or email address involved so we can verify and respond to it.