Legal

Privacy Policy

Last updated: May 23, 2026

1. Introduction

HeHRa, LLC ("HeHRa," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website at hehra.com and our services, including the AI HR Advisor, consultant marketplace, and related features (collectively, the "Service").

2. Information We Collect

Information You Provide:
  • Email address (for account creation and magic link authentication)
  • Conversation content with the AI HR Advisor
  • Intake notes and booking details for consultant sessions
  • Payment information (processed by Stripe; we do not store card numbers)
  • Consultant application information (name, bio, certifications, states)
HeHRa Advocate Application Information:
  • Contact basics (name, email, phone, LinkedIn URL, state, country)
  • Professional history (role, years of experience, industries, expertise)
  • Current employer and other corporate consulting clients (used to populate your matching-pool exclusion list and to manage conflicts of interest)
  • Rate expectations, weekly availability, and insurance status
  • Open-text answers ("Why HeHRa," "Best at," additional info, referral source)
  • Uploaded credential files (PDF, JPG, PNG, or HEIC) such as certificates, licenses, and transcripts
  • Consent records (scope acknowledgment, independent-contractor acknowledgment, truthfulness and Terms/Privacy consent)
  • Session metadata (UTM parameters, referrer, IP address, user agent) used to understand how applicants found the page and to deter abuse
Information Collected Automatically:
  • Usage data and analytics (via Vercel Analytics and product analytics)
  • Device type, browser type, and IP address
  • Pages visited and features used

3. How We Use Your Information

We use your information to:
  • Provide, maintain, and improve the Service
  • Process transactions and send related information (receipts, confirmations)
  • Send transactional emails (booking confirmations, account notifications)
  • Facilitate consultant-client connections and bookings
  • Monitor and analyze usage patterns and trends
  • Comply with legal obligations

4. Data Storage & Security

Your AI conversation data is stored in our Supabase database, which is encrypted at rest, with Row Level Security (RLS) enabled. RLS isolates your records so that the conversations, bookings, and personal data tied to your account are not accessible to other users of the Service. Data is also encrypted in transit using TLS. Uploaded credential files are kept in a private storage bucket that is not publicly accessible. However, no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security. Payment processing is handled entirely by Stripe, which is PCI DSS Level 1 certified; we do not store full card numbers.

5. Data Sharing

We do not sell your personal information. We share data only in these circumstances:
  • With Consultants: When you book a consultation, your intake notes and contact information are shared with the booked consultant to prepare for your session.
  • With HeHRa Reviewers (Advocate applications): Advocate applications — including open-text answers, credential files, and disclosures — are shared with the HeHRa team members responsible for reviewing applications and with any third parties we engage specifically for credential or reference verification.
  • Service Providers: We use Stripe and Stripe Connect (payments and advocate payouts), Supabase (database and private file storage), Anthropic (AI), Resend (email), and Vercel (hosting and analytics) to operate the Service.
  • Legal Requirements: When required by law, subpoena, or to protect our rights.

6. AI Conversations

Your conversations with the AI HR Advisor are stored in your account and are accessible only to you. We use Anthropic's Claude API to process your messages. Anthropic's data retention and privacy policies apply to the processing of your messages. We do not use your conversations to train AI models.

7. Your Rights

All users may:
  • Access your personal data by logging into your account
  • Delete your account and associated data by contacting us at privacy@hehra.com
  • Opt out of non-essential communications
Residents of certain US states have additional rights, described in Section 8.

8. US State Privacy Rights

If you are a resident of a US state with a comprehensive consumer privacy law — currently including California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia — you may have some or all of the following rights regarding your personal information. These rights are not absolute and may be limited by applicable law.

  • Right to know whether we are processing your personal information, and to access it
  • Right to correct inaccuracies in your personal information
  • Right to delete your personal information
  • Right to obtain a copy of the personal information you previously provided, in a portable format
  • Right to opt out of the sale of personal information, targeted advertising, or profiling that produces legal or similarly significant effects
  • Right to limit the use and disclosure of sensitive personal information
  • Right to non-discrimination for exercising any of these rights
Sale and targeted advertising.

We do not sell your personal information, we do not share it for cross-context behavioral or targeted advertising, and we do not use it for profiling that produces legal or similarly significant effects about you.

Sensitive information.

The AI HR Advisor lets you enter free-text information, which may include sensitive details about your employment situation. We process this information only to provide the Service and only with your consent or as otherwise permitted by law. We do not use sensitive personal information to infer characteristics about you.

How to exercise your rights.

Email privacy@hehra.com with the request you would like to make. You may also use an authorized agent to submit a request on your behalf; we may require the agent to provide proof of your written authorization and may still ask you to verify your own identity directly.

Verification.

To protect your information, we will take reasonable steps to verify your identity before acting on a request. We use the information you provide in a request only to verify identity and to respond to the request.

Appeals.

If we decline to act on your request and your state's law provides an appeal right, you may appeal by emailing privacy@hehra.com with "Privacy Appeal" in the subject line. We will respond in writing with our decision and the reasons for it. If your appeal is denied, you may contact your state attorney general.

9. Data Retention

We retain your data for as long as your account is active. Deleted conversations are soft-deleted and permanently removed after 30 days. You may request full account deletion at any time. Advocate application data and credential files follow the retention schedule described in Section 10.

10. Advocate Applications and Credential Files

This section supplements Sections 2, 5, and 9 for HeHRa Advocate applicants and accepted Advocates.

Storage.

Advocate application data is stored in our Supabase database with Row Level Security enabled. Uploaded credential files are stored in a private Supabase Storage bucket (advocate-credentials) that is not publicly accessible. Review-time access to credential files happens via short-lived signed download URLs issued to authorized HeHRa reviewers (default expiration: seven days).

Retention.
  • Accepted Advocates. Application data and verified credential files are retained while your Advocate account is active and for one (1) year after offboarding, after which they are deleted unless we are legally required to retain them longer.
  • Declined applicants. Application data is retained for ninety (90) days after the decline decision; uploaded credential files are deleted automatically at the end of that window. Summary analytics data (without identifying information) may be retained longer to evaluate recruiting patterns.
  • Pending review. While your application is in review, data is retained until a decision is made.
  • Applicant-initiated deletion. You may request deletion of your application and any associated credential files at any time by emailing advocates@hehra.com. We will honor the request within thirty (30) days, except where we are legally required to retain specific records.
Conflict-of-interest data.

The employer and other-clients information you disclose is used to populate your matching-pool exclusion list. We do not publish this information on your public Advocate profile, and we do not share it with clients; it is used internally to route matches.

Payouts.

Advocate payouts are processed through Stripe Connect. Stripe collects and stores the identification data required by its Know-Your-Customer (KYC) obligations directly; HeHRa receives only the account status and transfer metadata it needs to operate the payout pipeline. Stripe's privacy policy governs Stripe's handling of that data.

11. Children's Privacy

The Service is not intended for individuals under 18 years of age. We do not knowingly collect information from minors.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on the Service. The "Last updated" date at the top reflects the most recent revision.

13. Contact Us

For privacy-related questions or data requests, contact us at:

privacy@hehra.com

HeHRa, LLC
Georgia, United States