Privacy Policy
Last updated September 29, 2026
Who we are
Hayes (hellohayes.ai) is a UX, design and product assistant built and operated by Aaron Dence ("we," "us"). This policy explains what we collect when you use Hayes, why, and what you can do about it. Hayes is currently invite-only.
What we collect
- Account details. Your email address, and, if you sign in with Google, your name and profile photo.
- What you put into Hayes. Your messages, the screenshots and images you upload, and what Hayes produces for you (reviews, mockups and PRDs).
- Early-access requests. The name, email, role and use case you enter on the sign-up form, the question you ask the public preview, and the link that referred you, if any.
- Referrals. If you join through a friend's invite link, we record that they invited you, so they can earn a review. They see how many friends joined, never who.
- Security records. A one-way salted hash of your IP address, used to limit sign-in attempts and preview requests. We don't store raw IP addresses. Our hosting provider keeps standard server logs.
Google sign-in
If you sign in with Google, we ask only for your basic profile and email address (the openid, email and profile scopes). We use that data only to sign you in and to show your name and photo in the app. We don't use it for advertising, we don't sell it, we don't use it to train AI models, and we share it with nobody except the service providers below, as needed to run Hayes.
Hayes's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can remove Hayes's access at any time from your Google account permissions.
How we use it
- To run Hayes: answer your questions, review your screens and generate mockups and PRDs.
- To sign you in and send the emails you ask for, such as sign-in links.
- To reply to early-access requests and support questions.
- To keep Hayes secure and prevent abuse.
We don't sell your data or use it for advertising.
AI processing
Hayes sends your messages and images to Anthropic's Claude API to generate responses. Under Anthropic's commercial terms, content sent through the API isn't used to train their models. We don't use your content to train models either.
Service providers
These companies process data on our behalf, only to provide Hayes:
- Vercel: hosting
- Neon: database
- Anthropic: AI responses
- Resend: email delivery
- Google: sign-in, if you choose it
We may also disclose information if the law requires it.
Cookies
Hayes uses one essential cookie to keep you signed in. We don't use advertising or cross-site tracking cookies.
How long we keep it
We keep your account and chats until you delete them or ask us to. Sign-in links expire after 15 minutes. Security records are kept only as long as needed to enforce rate limits.
Your choices
You can ask for a copy of your data, or ask us to correct or delete it, by emailing hello@hellohayes.ai. We'll respond within 30 days.
Security
Data is encrypted in transit and stored with providers that encrypt it at rest. Access is limited to what is needed to run Hayes. No online service is perfectly secure, so avoid uploading screenshots that contain passwords, payment details or other sensitive personal information.
Children
Hayes isn't intended for anyone under 16, and we don't knowingly collect their data.
Changes
If we change this policy, we'll update the date above and, for significant changes, let signed-in users know.
Contact
Questions about privacy: hello@hellohayes.ai.