Hearth logo Hearth
Home

Privacy Policy

Last updated: September 1, 2026

Hearth is operated by Verge Labs. This policy explains what data we collect, why we collect it, and your rights over it.

1. Data We Collect

We only collect what's necessary to run the Service:

  • Email address. Used to verify your identity via one-time passcode (OTP), to send household invitations, and occasionally to contact you about your account. If you invite someone to your household, their email is stored until the invitation is accepted, revoked, or expires.
  • Account identifiers. A randomly generated UUID identifies your user account. Separate UUIDs identify your household, the computers you enroll, the agents you create, and the devices you sign in from. These are not linked to your Apple ID, Google account, or any advertising identifier.
  • Display name (optional). If you set a name in your profile, it's stored so household members can identify each other.
  • Device identifier and secret. A UUID and cryptographic secret generated on first sign-in are stored in your device's secure storage (iCloud Keychain on iOS, Android Keystore on Android). They authenticate your app to the relay server. Only a hashed version of the secret is ever stored on the server.
  • Push notification token. A token from Apple (APNs) or Google (FCM) used solely to deliver notifications to your device. It doesn't identify you personally.
  • Household and agent configuration. Names and settings you create for your household, enrolled computers, agent configurations, and working directories are stored on the server. This includes folder paths you designate for agents to work in.
  • Permission request data. When an agent asks to take an action, the details of that request (what tool, what input) are relayed through our server to your device. Your response (Allow / Deny / Always Allow) and the timestamp are logged for operational and audit purposes.
  • Auto-approve rules. Rules that allow certain actions to proceed automatically — created by tapping "Always Allow," through direct rule management, or via plugin installation — are stored on the server and scoped to the specific agent they apply to. You can view and delete them at any time.
  • Subscription data. Hearth is currently free. If paid features are offered in the future and you purchase one, the transaction ID, product ID, and status from Apple or Google would be stored to verify your entitlement. We never receive your payment details.
  • Agent activity data. While an agent is running, its step-by-step activity (tool calls, file edits, command output) streams through our server in real time to your device. This data is only held in memory during transit — it is never written to disk or stored on our servers.
  • Chat messages. Hearth includes chat rooms where household members (and agents) can exchange messages. The content of those messages, along with the sender name, room, and timestamp, is stored on our servers for as long as your account is active. Messages you delete are soft-deleted (marked as removed) and are purged from active views, but may remain in the database for a short period before permanent removal. Agent-to-chat messages (where an agent posts into a chat room) are stored the same way as human messages.
  • OTP request IP address. Logged briefly for rate-limiting abuse on the login endpoint. Not used for tracking or analytics.
  • Hearth CLI. The CLI runs entirely on your computer. It stores credentials locally in ~/.hearth/credentials and communicates with the relay server on your behalf. It does not send any additional data to our servers beyond what the app does.
  • Google OAuth credentials (optional). If you connect a Google account to use Google Calendar, Drive, or Contacts integrations, we store an OAuth refresh token on the server. It's encrypted to your specific computer's public key (X25519 + ChaCha20-Poly1305), so only the Hearth daemon on that computer can decrypt it. Short-lived access tokens are derived on demand and used only for the specific API call in progress. We also store your Google account email as a label so you know which account is connected.
  • Voice input (optional). If you connect a voice assistant (such as a Home Assistant voice satellite) to Hearth, the text transcript of what you say is routed to the agent you designate. The wake word and speech-to-text run on your own hardware in your home — we never receive audio recordings. What reaches our servers is text, handled the same way as an agent's live activity stream: relayed in memory to the designated agent and never written to our database as a stored message. See Voice and Home Assistant below.

2. What We Don't Collect

  • We don't collect your Apple ID, Google account credentials, or advertising identifiers.
  • We don't collect usage analytics, telemetry, or behavioral tracking beyond what's described above.
  • We don't use cookies or tracking scripts in the app. The website uses Google Analytics for aggregate traffic statistics; the app does not.
  • We don't access files, source code, or any other data on your computer beyond what appears in the permission requests your agents generate.
  • Agent activity stream data (tool calls, command output, file edits) is not stored on our servers — only chat room messages are persisted.
  • Google user data (calendar events, Drive files, contacts) is passed directly to the agent on your computer. It is not stored on our servers after the API call completes.
  • We never use Google user data to train models, serve ads, or for any purpose beyond completing the specific action the agent requested.
  • We never receive or store audio recordings from voice input. Wake-word detection and speech-to-text happen locally, on hardware in your home; only text reaches us.
  • We have no human-review pipeline for voice or agent data, and Hearth does not use your voice text, chat messages, or agent activity to train machine-learning models.

3. How We Use Your Data

All data is used solely to operate the Service:

  • Authenticating you and keeping your sign-in active across devices.
  • Routing permission requests from your agents to your phone and to other approved household members.
  • Sending push notifications when agents need a decision.
  • Evaluating always-allow rules to automatically approve matching requests.
  • Sending and tracking household invitations.
  • Verifying paid subscription status, if you purchase paid features.
  • Making Google API calls on behalf of your agents when you've connected a Google account.
  • Routing voice utterances from a connected voice assistant to the agent you've designated, and relaying the agent's spoken responses back through the Hearth software on your computer.

We do not sell your data. We share it only with: (a) Apple APNs and Google FCM for push notification delivery; (b) Apple and Google for subscription verification, if you purchase paid features; (c) our email provider for OTP and invitation delivery; and (d) Google APIs when completing agent actions you've authorized.

Our use of Google API Services adheres to the Google API Services User Data Policy, including the Limited Use requirements.

4. Data Storage and Security

  • Your device credentials are stored in your platform's secure storage (iCloud Keychain or Android Keystore), encrypted by Apple or Google respectively.
  • Account data, household configuration, always-allow rules, push tokens, and subscription records are stored in a database on servers we operate.
  • OTPs are stored as SHA-256 hashes and expire quickly after issue.
  • All communication uses TLS (HTTPS/WSS).
  • Permission request logs are rotated and may be archived to cold storage indefinitely for audit purposes.
  • Google OAuth refresh tokens are encrypted at rest (X25519 + ChaCha20-Poly1305, keyed to your computer's public key) and can only be decrypted by the Hearth daemon on that computer.

5. Data Retention

Account records, household data, always-allow rules, and subscription records are kept while your account is active. Permission request logs may be retained indefinitely in pseudonymous form for audit purposes. You can delete your account at any time from within the app (see Account Deletion). Archived log entries may remain in pseudonymous form (UUID only).

6. Children's Privacy

Hearth is not intended for children under 13. We do not knowingly collect data from children under 13. If you believe we have, please contact us and we will delete it promptly.

If you connect a voice assistant to Hearth, be aware that anyone who speaks to it — including children — will have the text of their speech routed to an agent. Because voice input is not tied to an individual account, we cannot distinguish a child's speech from an adult's. A household that places a shared voice device in a common area is responsible for who has access to it. As with all voice input, we store no audio and no server-side transcript.

7. Your Rights

Depending on where you live, you may have the right to access, correct, or delete your personal data, or to object to how we process it. To exercise any of these rights, email support@vergelabs.org. We'll respond in accordance with applicable law.

8. Changes to This Policy

We may update this policy. Changes will be posted here with an updated date. For material changes we'll make reasonable efforts to notify you. Continued use of the Service after changes take effect constitutes acceptance.

9. Contact

Questions about your data or this policy? Email support@vergelabs.org.

10. Google API Services

This section describes how we handle data from Google Calendar, Google Drive, and Google Contacts (People API) if you connect a Google account.

What we access

  • Google Calendar (calendar.events): Event titles, times, attendees, descriptions, and locations in calendars you've shared access to.
  • Google Drive (drive.file): Files created by Hearth or explicitly opened through Hearth, including names, metadata, and content.
  • Google People / Contacts (contacts.readonly): Contact names, email addresses, phone numbers, and job information from your Google Contacts or Workspace directory.

How we use it

Google data is accessed only to complete the specific action your agent is attempting at that moment — for example, checking your calendar before scheduling a meeting, or finding a contact's email address. The data goes directly to the agent running on your computer and is never stored on our servers after the API call finishes.

What we never do with Google data

  • Store Google Calendar, Drive, or People data on our servers.
  • Use it to train machine learning models.
  • Use it for advertising or share it with ad networks.
  • Share it with anyone except as needed to complete the API call itself.
  • Use it for any purpose other than what you asked the agent to do.

Revoking access

You can disconnect any Google integration at any time from the app. This deletes the stored refresh token from our server immediately. You can also revoke access directly in your Google account security settings at myaccount.google.com/permissions.

Our practices comply with the Google API Services User Data Policy, including the Limited Use requirements.

11. Voice and Home Assistant

Hearth can connect to a voice assistant — typically a Home Assistant voice satellite (a "puck" or smart speaker) in your home — so you can speak to your agents and hear them respond. This section explains how that works and what it means for your privacy.

What is captured, and where

Capture is triggered by a wake word running on the voice hardware in your home, not by us. Both the wake word and the conversion of speech to text happen locally, on that hardware. We never receive an audio recording. What leaves your home is the text of what was said, which is routed to the agent you've designated.

What we retain

Voice text is routed to an agent rather than posted into a chat room, so — unlike chat messages — it is not written to our database as a stored message. It streams through our relay in memory the same way an agent's live activity does. The durable record of the conversation is the agent transcript on your own computer. Voice-activity timestamps can indicate when people are home or awake; we treat this the same as other agent activity and do not use it for profiling.

Your Home Assistant credential stays on your computer

When an agent speaks a response, that response is delivered to your Home Assistant by the Hearth software running on your own computer, over your local network — not by our servers. The credential that authorizes it is encrypted to your computer's public key (X25519 + ChaCha20-Poly1305) and can only be decrypted there. Our relay never holds your Home Assistant credential and never contacts your Home Assistant. The list of which rooms have voice devices is configuration you create; treat it as you would a sketch of your home's layout.

People who aren't account holders

A shared voice device can be spoken to by anyone in the room — a guest, a visitor, a household member without a Hearth account. When that happens, the text of what they say is routed to an agent, the same as any other utterance. Because it isn't tied to an individual account, this text is not attributed to a person and cannot be looked up or deleted on a per-person basis; as with all voice input, we store no audio and no server-side transcript of it. A household that installs a listening device in a shared space is making that choice on behalf of everyone who enters. If this matters for your household, don't connect a shared voice device, or place it where only intended users can reach it.

Training and third parties

Hearth does not use your voice text to train machine-learning models and has no human-review pipeline for it. Your voice text does become part of your agent's conversation with whatever model provider that agent uses (for example, Anthropic or OpenAI), under the account and terms you configured with that provider — so whether that provider retains or trains on it is governed by your own arrangement with them, not by Hearth.

12. Account Deletion

You can request deletion of your Hearth account and all associated personal data at any time.

How to delete your account

Open the Hearth app, go to the Account tab, scroll to the bottom, and tap Delete Account. You'll see a summary of any households that will be deleted, then be asked to confirm with a one-time code sent to your email address. Deletion is immediate and permanent.

What gets deleted

  • Your user record (email address, display name, account identifiers).
  • All household memberships and all households you own (including any that have other members).
  • All enrolled device registrations (your app sessions and computer enrollments).
  • All agent configurations, working directories, and always-allow rules associated with your account.
  • Your push notification tokens.
  • Any stored Google OAuth refresh tokens for integrations you connected.
  • Pending household invitations you sent or received.
  • Pro subscription records tied to your account.

What may be retained

Permission request log entries may remain in pseudonymous form (UUID only, no email or name) for audit and legal compliance purposes. Messages in households you owned are deleted immediately. Messages you sent in other households are marked as removed from active views and remain in the database in that form.

Privacy Policy Terms of Service Support Contact

© 2025–2026 Verge Labs. All rights reserved.