Privacy Policy
Last updated: August 2026
What we collect
We collect the minimum information needed to operate the service:
- Email address - used for authentication, essential account/service messages, and occasional product announcements (which you can unsubscribe from).
- Google profile information - if you sign in with Google, we receive your name, email address, and profile picture from Google.
- IP address - stored temporarily for anonymous publishes to enforce rate limits. Cleared when a publish is claimed or expires.
- Uploaded files - the content you upload to Sites and Drives is stored and served according to the access settings described below.
- Workspace membership data - if you join a workspace, we record your membership, role, and how and when you joined.
- Generated Site metadata - bounded excerpts from published files may be processed by a third-party AI model to generate owner-facing display names, display descriptions, search metadata, and related Site metadata. Workspace admins can turn this off for their workspace (see below).
- Support chat - if you use the in-dashboard support assistant, your messages are processed by a third-party AI model to generate answers, along with limited account context (your account email, your plan, your Sites' names and access settings, and your workspace names and roles). We retain support chat transcripts to improve the product and our documentation.
- Site request metadata - used to provide first-party analytics to site owners, including request path, referrer domain, coarse country, status class, content type, known crawler classification, and daily privacy-preserving visitor hashes.
What we do not collect
- We do not use cookies for tracking or advertising.
- We do not sell or share your information with third parties for marketing purposes.
How we use your data
- Email addresses are used for authentication, account access, essential service/onboarding messages, and occasional product announcements with an unsubscribe link. We do not share your email with third parties for marketing.
- IP addresses are used solely for rate limiting anonymous sites and are not retained after the site is claimed or expires.
- Uploaded files are stored and served at their assigned URL according to their access settings.
- When AI metadata generation is enabled, bounded published-file excerpts are sent to a third-party AI model solely to generate Site metadata for dashboard, search, profile, API, and related product surfaces. We do not use your content to train AI models. Workspace admins can disable this for all of their workspace's Sites in workspace settings; manually set titles and descriptions are unaffected and never involve an AI model.
- Support chat messages and the limited account context described above are sent to a third-party AI model solely to answer your question. We do not use your messages to train AI models. Transcripts are retained for product improvement and are visible to the here.now team. The chat only processes data when you use it.
- If a workspace has auto-join enabled for an email domain, we match your verified email domain against those rules to offer you the option to join. Joining is always your action; we never add you to a workspace automatically.
- Site request metadata is used for owner-facing analytics, abuse prevention, reliability, and debugging. Raw IP addresses are not exposed to site owners.
Workspace membership data
Workspaces are shared accounts, so some of your information is visible to the people you share them with:
- Workspace members and admins can see your email address, your role, and when you joined.
- Workspace admins can invite people by email address; we send invite emails on the workspace's behalf.
- Sites you publish into a workspace are visible to the workspace according to their access settings, and remain with the workspace if you leave. Leaving a workspace removes your membership-based access (any Site whose guest allowlist separately lists your email keeps admitting you as a guest until you are removed from it) but does not delete content you published for it.
Third-party services
We use third-party services for infrastructure, hosting, and email delivery. These services process data on our behalf and are governed by their own privacy policies.
Data retention
- Anonymous sites and their associated data are automatically deleted after 24 hours if unclaimed.
- Claimed and authenticated sites are retained until you delete them.
- If you delete your sites, all associated files are permanently removed from storage.
- Deleting a workspace permanently deletes all of its Sites and their files. Removing a member revokes their membership-based access (per-Site guest allowlist entries admit them until removed separately) but does not delete content they published for the workspace.
- Raw analytics events and daily visitor hash rows are retained for a short debugging window. Long-term analytics are stored as aggregated daily rollups.
Who can see your content
Visibility depends on the access settings you choose:
- Public Sites - served to anyone who requests the URL. Personal site URLs are randomly generated and non-guessable; workspace label URLs (like
deck.acme.here.now) are readable and should be treated as guessable. - Password-protected Sites - served to anyone who enters the password. Passwords are stored hashed; no one, including us, can read a password back.
- Members-only workspace Sites - the default for workspace publishes. Served only to signed-in, active members of the owning workspace. Access ends promptly when a member is removed.
- Restricted Sites - served only to viewers who verify an email address on your allowlist (on workspace-owned Sites, workspace members are also admitted).
- Drives - private to your account and to accounts you explicitly share them with. Drive contents are never served at a public URL.
Public sites may be indexed by search engines. If you want to prevent indexing, you can include a robots.txt file or add <meta name="robots" content="noindex"> to your HTML. Gated sites are not served to crawlers.
Changes
We may update this policy. Changes will be reflected by updating the date at the top of this page.
Contact
Questions about privacy? Email us at hello@here.now.