1. Who we are
DeviceHero is business software for medical device companies: customer records, sales and inventory, accounting, documents and signatures, quality and regulatory records, people records and an AI assistant. A company’s people use it inside a workspace that belongs to that company.
The operator responsible for this policy is DeviceHero. The policy covers the DeviceHero application at devicehero.app and the public website at devicehero.info, and explains what we collect, why, who else sees it, how long we keep it and what you can ask us to do. Section 4 is about data we receive from Google and Microsoft when someone connects a mailbox, and it stands on its own.
Write to us at support@devicehero.app with any question about this policy or to make a request. That address reaches us for privacy questions, security reports and legal notices alike.
2. When we decide, and when a customer decides
Most of what DeviceHero holds is not ours. It belongs to a customer — the company whose workspace it sits in — and we hold it on their behalf. Which of us decides what happens to a record changes what you should ask us for, so it is worth being plain about it.
Where we decide (we are the controller)
- sign-in accounts: your name, your email address, the password hash if you use a password, and when you last signed in;
- this website, and the security, reliability and error records that come from running the product;
- the usage analytics we keep to see which parts of DeviceHero are used, described in section 8;
- two directories that are ours rather than any customer’s: the healthcare-provider index built from federal public registries, and the investor directory.
Where a customer decides (we are a processor and a service provider)
Everything a customer puts into their workspace — contacts and leads, orders and invoices, quality and complaint records, employee records, files, and mail read from a connected mailbox — is theirs. They decide what goes in, who in their company sees it, how it is corrected and when it goes. We act on their instructions, we do not use it for our own purposes, and we do not sell it.
If you are a person whose details sit in a customer’s workspace — a contact, a document signer, a data room guest, someone who filled in one of their forms, or one of their employees — that customer answers for the record. Write to support@devicehero.app anyway if you do not know who holds it: we will pass the request to the customer who does and help them answer it, and we will handle it ourselves where the record is one of the two directories above. Section 11 sets out the steps.
3. What we collect, and about whom
DeviceHero holds information about several different kinds of people, and the honest way to describe it is by who it is about rather than by what it is called.
People who sign in to DeviceHero
- your name and work email address; a password hash if you use a password, never the password itself; when you last signed in; your role in the workspace and which workspaces you belong to;
- if you sign in with Google or Microsoft, we read only your email address, your name, and — from Google — whether that address is verified. Nothing else in the profile is stored;
- the employment record your employer keeps in DeviceHero: title, phone, manager, department, location, employment type and status, start and end dates, and pay;
- a connected mailbox: its address and display name, the permissions the provider actually granted, the access and refresh tokens (encrypted), and where the reading has got to — section 4;
- what you write to Hero, our AI assistant, and what it answers; your internal chat messages, where an edit also records the internet address and browser you made it from;
- usage analytics and error reports — section 8.
A workspace’s contacts, leads and companies
Names, email addresses, phone numbers, an NPI number, professional role and occupation, postal addresses, notes, whether an agreement is in place and when it expires, and a timeline of interactions that includes AI-written summaries of email and meetings. Records reach a workspace by being typed in, from a public form submission, from a saved prospect, from a conference lead or a photographed badge or business card read by AI, and from a connected mailbox. Campaign recipients also carry the drafted message, whether it was delivered and any unsubscribe.
Healthcare providers listed in public registries
We build and hold a directory of clinicians and healthcare organisations from federal public data: the NPPES registry, CMS Medicare physician and clinician datasets, CMS Open Payments and AHRQ data. It carries the NPI, name, credential, gender, specialty, practice address and phone, the Direct-messaging address NPPES publishes, Medicare service volumes and payments, medical school and graduation year, and organisational affiliations. Publications and clinical trials come from PubMed and ClinicalTrials.gov. Saving a prospect into a workspace adds the organisation’s authorised official and fax number, and Open Payments rows, to that workspace.
People who fill in a public form
The answers given, any file attached to them, how long the form took, and the contact record the submission created if the form was set up to make one. We do not store an internet address or browser with a form submission.
Document signers, data room guests and people answering a request by link
A signer’s name, email address, title and role; the signature they typed or drew; and the time they opened, agreed, signed or declined, each recorded with their internet address and browser. Those entries are what the signing certificate is made of, and the certificate is kept as a write-once record for ten years. A data room guest’s name, email address, organisation and role are recorded, along with each link opening, page view, download, acceptance of a confidentiality agreement and question asked, again with internet address and browser; the workspace that owns the room can read and export that log. Someone who answers a task request through a link leaves their reply, any file they attach, their internet address and their browser.
People who contact a customer’s support desk
Name, email address, phone number, the product lot or serial number, the message itself and any attachments. For a medical device company these are also complaint records, so they are kept rather than deleted, and they can contain health information — see section 15. Mail sent to a support address is kept in its raw form for 90 days; the ticket is the lasting record.
Employees of a customer
- preferred name, pronouns, date of birth, personal email and phone, home address, and emergency contacts — who are third parties themselves;
- pay history, time off including sick, parental, bereavement and military leave, reviews, goals and notes;
- dependants, held as name, relationship, date of birth and whether they are a student, and life events such as a marriage or a birth that change benefit coverage;
- HR files kept in separate drawers — personnel, medical, I-9, EEO, self-identification, payroll and benefits — with the medical and I-9 drawers gated to the person themself and an HR administrator;
- voluntary self-identification of gender, ethnicity, veteran and disability status, readable only by the person who gave it. HR sees it only as aggregates with a minimum group size, and it is left out of a workspace export entirely;
- whether a Social Security number and a bank account are on file with the payroll provider. We record those two facts and not the numbers: payroll holds them.
Taxpayer identification numbers
A workspace holds its own employer identification number and the taxpayer identification number of each contractor it pays. A contractor’s number can be a Social Security number, so we do not claim never to hold one. These are stored in normalised form, shown only masked in the app, kept out of anything the AI assistant can read back, and left out of a workspace export.
Bank and payment information
If a workspace connects a bank feed through Plaid, we hold the account name, institution, kind and last four digits, and each transaction’s date, description, counterparty, amount, direction and category. If a workspace takes card and bank payments on its invoices, the payer enters those details on Stripe’s own hosted page — card and bank numbers never reach DeviceHero. We send Stripe the invoice reference, the line descriptions, amounts, currency and the payer’s email address. A receipt captured from a mailbox can still record the last four digits printed on it.
Investors, board members, stakeholders and grant personnel
Equity stakeholders are held as name, email address, postal address and legal entity; board members and meeting attendees as name, email address and notes; grant key personnel as name, degrees, contact details, address, eRA Commons ID, ORCID, base salary and effort. The investor directory holds firm names, websites, locations, themes and stages, and a contact name, role and email address taken only from what the firm publishes on its own site.
People who visit this website
The public pages carry no analytics and set no cookie. Our application logs record the route, the outcome and how long a request took, and do not record your internet address. If a page fails in your browser, an error report is sent to us carrying the error name, the first line of its message with addresses and file paths stripped out, the stack frames and your browser’s user agent string — not your internet address. Requests to that reporting endpoint are rate-limited by internet address, and the address is used for the length of that limit and is not stored with the report.
4. Google and Microsoft mail data
This section is about data DeviceHero receives from Google and Microsoft. It is written to stand on its own, so it repeats what the rest of this policy says where that matters. Nothing elsewhere in this policy widens what we do with Google data beyond what is described here.
What DeviceHero asks for
Signing in with Google or Microsoft, and connecting a mailbox from inside DeviceHero, ask for the same permissions in one screen:
- Your identity — the openid, email and profile scopes: your email address and your name, so we can sign you in and know which mailbox is yours. From Google we also read whether the address is verified, and refuse an unverified one. No other part of the profile is stored.
- Reading your mail — Google’s gmail.readonly scope, Microsoft’s Mail.Read: to read the messages in your Inbox.
- Sending mail as you — Google’s gmail.send scope, Microsoft’s Mail.Send: to send the email you write in DeviceHero.
We never ask for permission to change, organise or delete your mail. You can decline the mail permissions and still sign in; if you decline both, no mail tokens are kept at all.
What is read, and what is stored
Reading begins on its own as soon as the read permission is granted — there is no separate switch to turn it on, and no way to pause it while the mailbox stays connected. The first read covers the messages in your Inbox from the last 90 days. After that, every new Inbox message is read for as long as the mailbox is connected. Sent mail, mail that only sits in an archive, drafts, spam and trash are not read.
For every Inbox message that is read, DeviceHero stores:
- who it came from and one recipient address;
- the subject and a short preview;
- the text of the message, cut off at 20,000 characters;
- when it arrived, and the provider’s own message and thread identifiers.
That is every Inbox message in the window, newsletters and personal mail included, not only business correspondence. Attachments are not stored, with one exception: receipts, below.
What DeviceHero does with it
The point of reading mail is to put conversations onto the right contact record. For a message with an outside correspondent, the text is sent to an AI model — Anthropic’s Claude — to judge whether the correspondent is a business relationship and to write a short summary of the exchange. Newsletters and automated mail are never sent to the model. Mail between colleagues on your company’s own domain is sent to the model, because the model runs before that check, and is then set aside: no contact, no summary, nothing added.
The summary is logged as an activity entry on the contact, with the message’s subject. A new contact record can be created when the correspondent reads as a customer, prospect, investor, partner, vendor, consultant, or someone else outside your company worth keeping on the record — a clinician giving feedback, a regulator, a conference organiser. Someone already in the workspace’s contacts is always logged, whatever the model concluded. A calendar invitation is logged as a meeting rather than an email.
Receipts
Receipt capture is on unless a workspace turns it off. For every connected mailbox, PDF, PNG, JPEG and WebP attachments on stored messages — at most five per message and up to 10 MB each — are downloaded, checked, and sent to the same AI model to read the vendor, the date and the total. A receipt that matches an expense to the cent, on the right date, from the right vendor is filed on that expense automatically; the rest wait on the Receipts page for a person. Captured receipts and their files are visible to everyone in the workspace. Any member can switch capture off, or narrow it to a single address, under Settings → Business & tax → Receipts mailbox.
Who can see it inside the workspace
The list of messages imported from your mailbox is visible only to you — not to your colleagues, not to an administrator, not to the workspace owner — and no message record is in the owner’s export of the workspace’s data: no message text, no preview, no subject line.
What the workspace does see is what was derived from your mail: the contacts, the activity entries with their subjects and summaries, and captured receipts with their files. A captured receipt also carries the sender, the recipient, the subject and the date of the message it arrived on, so for those messages those few details are visible to every member and are in the workspace export. All of it is a workspace record, and DeviceHero’s other AI features — the assistant, and campaign drafting — can read them for people in the same workspace.
If you sign in to a second workspace with the same Google or Microsoft account, your mailbox is connected there too, and it is read into both.
Sending mail as you
DeviceHero sends from your mailbox only when you send something yourself: a campaign or a test email, a support reply, a data room invitation, a board packet. A campaign leaves through the mailbox of the person who pressed Send. A campaign can name a sender, and then only that person can send it — naming a colleague hands them the campaign rather than borrowing their mailbox. No colleague can send from your mailbox.
There is one shared case. A member can connect a shared address, such as a company support mailbox, and choose it as the workspace’s support address; from then on every member’s support replies leave through that shared mailbox. Only the member who connected a mailbox can choose it that way.
Workspace invitations and mail about signing in come from DeviceHero’s own address through Amazon SES, never from anyone’s mailbox.
AI processing of your mail
The model is Anthropic’s Claude, reached through Anthropic’s API. Anthropic processes it under a Business Associate Agreement with us and a zero data retention arrangement for our API traffic, and does not use API data to train its models. Before mail text reaches the model it passes prompt-injection defences and a narrow redaction that replaces a few patient-identifier patterns. That reduces exposure; it is not de-identification, and names, addresses and phone numbers are left in place. The summary the model writes is redacted again on the way back, because it lands on a contact’s timeline.
DeviceHero does not use data obtained through Google Workspace APIs, including Gmail, to develop, improve, or train generalized or non-personalized AI or machine-learning models, and does not allow any third party to do so.
Who we share it with
Data received from Google and Microsoft goes to:
- Anthropic, for the AI processing described above;
- Amazon Web Services, which hosts DeviceHero and its database and file storage and carries DeviceHero’s own platform email;
- the people you send email to, when you send it;
- anyone the law requires, and a buyer in a merger or sale of the business, in which case we will say so before the data moves.
It is never sold. It is never used for advertising of any kind, never given to data brokers or information resellers, and never used to judge creditworthiness or for lending. It is used only to provide and improve the features in this section.
How it is protected
- Access and refresh tokens are encrypted with a key belonging to that workspace alone, itself wrapped by AWS Key Management Service and bound to the workspace, so a sealed token cannot be opened for any other workspace.
- Message records sit in the database, which AWS encrypts at rest with AWS-managed keys. The per-workspace key protects stored credentials, not message text.
- Every record carries the workspace it belongs to, every query is scoped to one workspace before it runs, and the mail table additionally carries a Postgres row-level security policy enforced against the role the application connects as.
- Traffic is carried over TLS, and the whole deployment runs in the United States.
How long it is kept, and how it is deleted
- Message text is deleted 30 days after the message arrived.
- The rest of the message record — sender, recipient, subject and dates — is deleted 365 days after the message arrived.
- What the workspace derived — contacts, activity entries and captured receipts, including the sender, subject and date a captured receipt carries — is a workspace record and is kept for the life of the workspace unless someone in it deletes the record.
Disconnecting a mailbox in Settings → Your mailbox does all of this at once:
- reading stops immediately, on every path — the regular sync, a manual import and receipt capture;
- the text and the preview of every message already read from that mailbox are deleted there and then, and anything still waiting to be imported is closed off unimported;
- DeviceHero posts the token to Google’s revocation endpoint. That is a best effort: if Google cannot be reached, the mailbox is still disconnected here but the grant stays live at Google, which is why you should also remove DeviceHero at myaccount.google.com/connections (opens in a new tab). Microsoft offers no per-app revocation, so remove DeviceHero from the app permissions in your Microsoft account;
- what survives is the sender, recipient, subject and dates of messages already read — no text, no preview — visible only to you, and deleted on the same 365-day schedule. Contacts, activity and receipts already created stay as workspace records, and a captured receipt keeps its stored file.
Revoking at Google revokes DeviceHero’s access as a whole rather than for one workspace: if you connected the same mailbox in two workspaces, reading stops in both. The same happens when an employee is deactivated or removed — every mailbox they connected is released the same way. Connecting again starts cleanly: the reading position is reset and the 90-day window is read again, without duplicating what is already there.
To have the rest deleted sooner, ask the workspace to delete the contact — which takes its activity entries with it — and write to support@devicehero.app about anything else. Section 11 sets out each step, and section 9 gives the full schedule.
Who at DeviceHero may read it
People who work on DeviceHero, including contractors, do not read mail obtained from Google or Microsoft except:
- with your explicit, documented agreement to look at specific messages;
- where it is necessary for security — investigating a bug or abuse;
- where it is needed to comply with a law or regulation; or
- where it is aggregated and anonymized and used for internal operations.
The operator console our own staff use shows no message content at all: it carries error and job records, counts and timings. A small number of people administer the systems the data sits in and could reach stored data in the course of that work, which is exactly why the limits above apply to them and to anyone working for us.
Microsoft
Everything in this section applies to a Microsoft mailbox in the same way: the same Inbox-only reading, the same 90-day first read, the same storage, the same AI processing, the same visibility, the same retention and the same deletion on disconnect. The differences are that Microsoft treats the address it returns as verified without a separate flag, and that Microsoft provides no way for an application to revoke its own access, so withdrawing the permission at Microsoft means removing DeviceHero from your Microsoft account’s app permissions.
5. How we use information
We use what we hold to:
- run the features a workspace asked for — the contact record, the invoice, the quality record, the signed document, the payroll run, the imported conversation, the captured receipt;
- sign people in, keep sessions honest and keep one workspace’s data out of another’s;
- keep the service secure and reliable: rate limits, abuse and fraud prevention, error and uptime records;
- answer support questions and fix what people report;
- see which parts of DeviceHero are used, through the first-party usage analytics described in section 8, so we know what to build and what to repair;
- send you service email — an invitation to a workspace, a notice about your account or a change to this policy;
- meet legal and regulatory obligations, and establish, exercise or defend legal claims.
We do not use anyone’s information for advertising, we do not sell it, and we do not profile people to make decisions about them that have legal or similarly significant effects. Data received from Google and Microsoft is used only for the purposes set out in section 4.
6. AI processing
DeviceHero’s AI features — the Hero assistant, mail summaries, receipt reading, drafting and the rest — all run on one provider: Anthropic, reached through its API. There is no other AI vendor, and no model is trained by us.
Anthropic processes this data under a Business Associate Agreement with us and a zero data retention arrangement for our API traffic, and does not use API data to train its models.
What can reach the model, always because a feature or a person asked for it:
- the record you ask Hero about, and the text of your conversation with it;
- documents and images you upload, including receipts, photographed badges and business cards;
- the subject and text of mail read from a connected mailbox, and receipt attachments;
- support and complaint text, drafting inputs for HR, board and grant documents.
Text that came from outside the company is cleaned before it is used as a prompt, and a few patient-identifier patterns are replaced. That lowers the risk; it is not de-identification, and it does not remove names, addresses or phone numbers. A handful of research features — finding conferences, prospects and investors — use Anthropic’s own web search, and none of them receives mailbox data.
What we keep. For each model call we record counts and the outcome — the feature, the model, how many tokens, whether it worked — and no prompt or answer text. The model’s output, though, is kept as an ordinary product record where a feature produces one: the summary on a contact’s timeline, the note on a new contact, the vendor and total read off a receipt, and your Hero conversations. Those are covered by section 9 like any other workspace record.
AI is part of how DeviceHero works and cannot be switched off feature by feature. A workspace owner or HR administrator can set a monthly limit on how much AI the workspace uses.
9. How long we keep things
Retention is decided by the kind of record, when the record is written, rather than chosen later. When a period below ends, the data is deleted — except where the period is a legal minimum, which says how long a record has to be kept rather than when it goes.
| What | How long |
|---|---|
| Your sign-in account: name, email, password hash, last sign-in | While the account exists. It is not removed when a workspace closes — write to us to have it deleted. |
| Workspace records: contacts, sales, inventory, accounting, quality, people, equity and the rest | For the life of the workspace. When a workspace is closed they are deleted, except the rows below that say otherwise. |
| Text of mail read from a connected mailbox | 30 days from the day the message arrived, or at once when the mailbox is disconnected |
| The rest of that message record: sender, recipient, subject, dates | 365 days from the day the message arrived |
| Contacts, activity entries and captured receipts made from mail | For the life of the workspace, as ordinary workspace records |
| Raw mail sent to a support address | 90 days; the support ticket is the lasting record |
| Support tickets and complaint records | Kept. They are a medical device company’s feedback and complaint record and are never deleted. |
| Internal chat messages | Kept until the workspace’s messaging administrator sets a policy; messages under a legal hold are exempt from it |
| AI usage records (counts and outcomes, no text) | Kept, including after a workspace closes |
| Usage analytics | Raw events 90 days; daily totals kept |
| Operational records: request samples, error reports, uptime and performance history | 14, 30 and 90 days respectively; application logs 14 days; background job records 3 days when they succeeded and 14 when they failed |
| Workspace export archives | 7 days, then the archive is removed |
| Invitations to join a workspace | 14 days |
| Uploads held back for checking | 7 days after they are quarantined |
| Regulated evidence: signing certificates, signed quality records, complaint files, audit bundles | 3 to 10 years depending on the record, written once under object lock. It cannot be deleted early, not even on request. |
| Audit trails: quality events and signatures, HR events, messaging audit | Never updated or deleted by the application, and kept after a workspace closes as the record of what was done |
| Database backups | 35 days |
Deleting is not instant everywhere. Data that has been deleted can remain in database backups for up to 35 days, and an earlier version of a stored file can outlive the version that replaced it, until those copies age out on their own schedule.
10. How we protect it
The controls that matter most for personal information:
- traffic is carried over TLS, and plain HTTP is redirected to HTTPS;
- the database and stored files are encrypted at rest by AWS using AWS-managed keys, in the United States, with the database and cache reachable only from the application itself;
- stored credentials — mailbox, bank-feed and payroll tokens — are additionally encrypted with a key belonging to one workspace, wrapped by AWS Key Management Service and bound to that workspace;
- every record carries the workspace it belongs to and every query is scoped before it runs; the most sensitive tables also carry Postgres row-level security policies;
- HR files, chat files, data room files and receipts are private objects streamed only through authenticated routes, never from a public directory;
- links sent to people outside the company — a signing link, a data room link, an invitation — are stored only as a hash, so a working link cannot be rebuilt from the database, and issuing a new one retires the old;
- sign-in and other sensitive endpoints are rate-limited; the session cookie is signed, HttpOnly and Secure.
To report a vulnerability, write to support@devicehero.app. No system is perfectly secure, and we do not claim otherwise.
11. Your choices, and how to use them
Manage or delete the data from your mailbox
- Disconnect the mailbox. In DeviceHero, open Settings → Your mailbox and choose Disconnect. Reading stops immediately, and the text and preview of every message already read from that mailbox are deleted there and then.
- Withdraw the permission at the provider. Disconnecting asks Google to revoke DeviceHero’s access, but that request can fail, so check at myaccount.google.com/connections (opens in a new tab) and remove DeviceHero there if it is still listed. Microsoft gives an application no way to revoke its own access, so remove DeviceHero from the app permissions in your Microsoft account.
- Delete what the workspace kept. Contacts, activity entries and captured receipts are the workspace’s records. Anyone in the workspace who can edit a contact can delete that contact, and deleting it takes its activity entries with it. There is no button for deleting a single activity entry or a captured receipt on its own, so for those, ask us.
- Stop receipt capture. Any member can switch it off, or narrow it to one address, under Settings → Business & tax → Receipts mailbox.
- Ask us. Write to support@devicehero.app and we will delete what is left, other than the records named below.
Your DeviceHero account
You can sign out at any time, and change your name, title and password in Settings. Your work email address and the rest of your employment record belong to your employer’s copy of it, so ask an administrator in your workspace to correct those. There is no self-serve way to delete an account or a workspace: write to support@devicehero.app and we will do it. Closing a workspace deletes its records, with the exceptions below. Your sign-in account is separate from any workspace and stays until you ask us to remove it.
A workspace owner can export the whole workspace’s data from Settings and download it as one archive, which is the quickest way to get a copy of what a workspace holds. That export contains no message records from anyone’s connected mailbox and no voluntary self-identification. It does contain captured receipts, which are workspace records — section 4 says what one of those carries.
If your details are in a customer’s workspace
If you are a contact, a document signer, a data room guest, someone who filled in a form, or an employee, the company whose workspace holds the record decides what happens to it. Ask them directly if you know who they are. If you do not, write to support@devicehero.app: we will pass the request to them and help them answer it.
The healthcare-provider directory is different, because it is ours. It is a copy of federal public registries — NPPES, CMS and Open Payments. Write to us and we will tell you what we hold and what we can do about our copy; because it is refreshed from those registries, a correction made at the registry is what carries through, and the registry is the place to fix the record at source.
What we cannot delete on request
- regulated evidence — a signing certificate, a signed quality record, a complaint file, an audit bundle — which is written once and locked for 3 to 10 years depending on the record;
- support tickets and complaint records, which a medical device company has to keep as its record of feedback and complaints;
- insert-only audit trails of quality, HR and messaging actions, which exist to show what was done and by whom;
- data already written to a backup, until that backup ages out, and records we must keep to comply with law.
When we cannot delete something, we will say which of these it is rather than leave the request unanswered.
How to make a request, and how we check it
Email support@devicehero.app and say what you want — a copy of what we hold, a correction, a deletion, or an explanation. DeviceHero operates online and deals with the people who use it directly, so that address is how to reach us.
We check that a request really comes from the person it concerns by matching what you tell us against what we hold, which usually means the email address the request comes from and the workspace or record it is about. We may ask for more before acting on a deletion, and anything you send for that purpose is used only to check the request. Someone may act as your authorized agent if you give them written permission; we may ask you to confirm it with us directly.
There is no charge for any of this, and we will not deny you service, change a price or give you anything worse because you asked. We answer within the period the law allows — 45 days under California law, one month under the GDPR and UK GDPR — and we will tell you if we need the extension those laws permit.
12. California and other US state privacy rights
California’s Consumer Privacy Act applies to a business that meets one of its thresholds. Rather than argue about which side of those thresholds we are on, we make these disclosures and honour these rights. They describe the last 12 months and are reviewed at least once a year.
Categories of personal information we collect
| Category | What that means in DeviceHero |
|---|---|
| Identifiers | Name, email address, postal address, phone number, account identifiers, and the internet address recorded when someone signs a document, opens a data room or answers a request by link |
| Customer records (Civ. Code §1798.80(e)) | Name, address, telephone number, employment and financial details such as pay and bank transactions |
| Protected classification characteristics | Date of birth, gender, veteran and disability status and ethnicity, where an employee gives them in an HR record or volunteers them in self-identification |
| Commercial information | Orders, invoices, payments and the products and services a workspace records |
| Biometric information | DeviceHero builds no fingerprint, face or voice template and does no biometric matching. The signature a signer types or draws, and photographs of badges and business cards, are held as images and listed under the visual category below. |
| Internet or other electronic network activity | Usage analytics events and error reports, the route templates they carry and the browser user agent recorded with them |
| Geolocation data | No precise geolocation is collected. Postal addresses are held as text, and internet addresses are recorded only where this policy says so. |
| Audio, electronic, visual or similar information | Uploaded documents and images: receipt files, photographs of badges and business cards, and the signature a signer types or draws |
| Professional or employment-related information | Job titles, employment records and pay, and clinicians’ credentials and practice details in the provider directory |
| Education information | The medical school and graduation year held in the provider directory, and the degrees of grant personnel |
| Inferences | The AI’s reading of whether a correspondent is a business relationship, and the summaries and notes written from it |
| Sensitive personal information | The contents of email read from a connected mailbox, where DeviceHero is not the intended recipient; taxpayer identification numbers, which for a contractor can be a Social Security number; the password to your DeviceHero account, held only as a hash; racial or ethnic origin where an employee volunteers it; and health information that a support or complaint record can carry |
Where it comes from
From you; from the customer whose workspace holds the record, and from their employees and colleagues; from a mailbox someone connects, and therefore from the people who wrote to them; from public federal registries and research databases; from services a workspace connects, such as Google, Microsoft, Plaid, Stripe and Gusto; and from your browser when you use the application.
Why we collect it
For the business and commercial purposes in section 5: providing the features a workspace asked for, security and abuse prevention, support, quality and usage measurement of our own service, service communications, and legal compliance.
Selling, sharing and disclosure
We have not sold or shared personal information in the preceding 12 months, and we do not sell or share it. Sharing here means disclosing it for cross-context behavioural advertising, which we do not do. We do not knowingly sell or share the personal information of consumers under 16, and DeviceHero is not for children at all — see section 14. Every category above may be disclosed for a business purpose to the service providers listed in section 7, and to the categories of recipient described there.
Sensitive personal information
We use and disclose sensitive personal information only to provide the service you or your workspace asked for, to keep it secure and to comply with the law — that is, only for the purposes the CCPA regulations permit without a right to limit. The one judgement DeviceHero draws from the contents of a mailbox is whether a correspondent is a business relationship, which is the feature the mailbox was connected for.
How long we keep each category
The periods are in section 9. Where a category has no fixed period there, we keep it for the life of the workspace that holds it and delete it when that workspace closes, except the records section 11 names as ones we cannot delete early.
Your rights
- To know and to access: the categories above, where they came from, why we collected them, who we disclosed them to, and a copy of the specific pieces we hold about you, in a portable form;
- To delete what we hold about you, subject to the exceptions in section 11;
- To correct anything inaccurate;
- To be treated the same whether or not you exercise any of these.
Because we do not sell or share personal information, there is nothing to opt out of, and an opt-out preference signal such as Global Privacy Control has nothing to switch off — see section 8. We use sensitive personal information only for the purposes the regulations permit without a right to limit; if you want it limited anyway, write to us, and where it comes from a connected mailbox, disconnecting that mailbox stops it at once. DeviceHero’s AI features prepare and explain, and a person makes the decisions, so we do not use automated decision-making technology to make decisions about you that produce legal or similarly significant effects.
Make any of these requests by emailing support@devicehero.app. Verification, authorized agents and timing are covered in section 11.
Virginia, Colorado, Connecticut, Texas, Utah and other states give residents similar rights of access, correction, deletion and portability, and a right to appeal a refusal. Use the same address, say which state you are writing from, and we will apply your state’s rules.
13. If you are in the EEA, the UK or Switzerland
For people who sign in to DeviceHero and for this website, DeviceHero is the controller. For the information a customer puts into their workspace, the customer is the controller and we are a processor acting on their instructions — section 2 explains which is which. This policy is also the notice required by Articles 13 and 14 of the GDPR and the UK GDPR.
Purposes and legal bases
- Providing DeviceHero to the workspace you belong to, and running this website — performance of a contract, or our legitimate interest in delivering the product where the contract is with your employer.
- Reading and sending mail from a mailbox you connect — your consent, given on Google’s or Microsoft’s own screen. You can withdraw it at any time by disconnecting the mailbox and removing our access at the provider, and that does not affect what was lawfully done before.
- Keeping the service secure and reliable, preventing abuse, and measuring how our own product is used — our legitimate interest in a product that works and is not abused, weighed against the limited information involved.
- Keeping records that law or regulation requires — quality, complaint, tax and employment records — a legal obligation, and establishing or defending legal claims.
- Where we act for a customer, the legal basis for their processing is theirs to determine, not ours.
Where information that is not from you comes from
Some of what we hold did not come from the person it is about: correspondents found in a mailbox someone connected, contacts a customer entered or imported, clinicians and organisations in our directory built from federal public registries (NPPES, CMS and Open Payments) and public research databases (PubMed and ClinicalTrials.gov), signers and guests a customer invited, and details a customer’s employee gave about a dependant or an emergency contact. Section 3 lists the categories in each case, and this section is the notice about them.
Recipients, transfers and retention
Recipients are listed in section 7 and retention periods in section 9. DeviceHero is operated from and runs in the United States, so using it means transferring your information there, and the United States has no general adequacy decision from the European Commission or the UK. We do not have standard contractual clauses or an appointed representative in the EU or the UK in place today, and we are not going to imply otherwise. If you need transfer safeguards before using DeviceHero, write to support@devicehero.app and we will tell you where we have got to.
Your rights
You can ask for access to your personal data, for it to be corrected or erased, for processing to be restricted, for a copy in a portable form, and you can object to processing we base on a legitimate interest. Where we rely on consent you can withdraw it at any time. Giving us your name and work email address is necessary to have a DeviceHero account — without them you cannot use the product — while mail access is optional and can be declined without affecting sign-in.
Write to support@devicehero.app first, including if you want to complain: we would rather hear it. You also have the right to complain to the data protection authority in the country where you live or work, or in the United Kingdom to the Information Commissioner’s Office.
14. Children
DeviceHero is software for companies, and the Terms of Service require anyone who uses it to be at least 18. It is not directed to children, no child is a user of it, and we collect nothing from a child directly. We do not sell or share personal information at all, so we do not sell or share the personal information of anyone under 16.
Information about a child does reach DeviceHero in one place, and it comes from an adult: an employee entering a dependant for benefits gives that dependant’s name, relationship and date of birth, and a dependant can be a child. That information comes from the employee, is held in the workspace’s people records, and is used only to administer benefits.
If you believe a child’s information reached us in any other way, write to support@devicehero.app and we will delete it.
15. Health information
A medical device company’s records can contain health information about a patient, most often because someone described what happened when a device was used. Support tickets and complaint records are where this turns up; so, occasionally, are mailbox text and uploaded documents.
DeviceHero is not a clinical record system, patients are not users of it, and it has no connection to any electronic health record. We are not a covered entity under HIPAA and we do not describe DeviceHero as compliant with it.
For the two providers who could see such information in the ordinary course, we hold agreements that address it: a Business Associate Addendum with Amazon Web Services, and a Business Associate Agreement with Anthropic together with a zero data retention arrangement for our API traffic. Before mail text is sent to the AI model, a few patient-identifier patterns are replaced, which lowers exposure without being de-identification.
If your company is itself a covered entity or a business associate, write to support@devicehero.app before putting protected health information into DeviceHero, so we can agree in writing what is needed.
16. Changes to this policy
When we change this policy we post the new version on this page with a new effective date, and we review the page at least once every 12 months whether or not anything has changed.
If a change materially affects how we handle personal information, we will email account holders and post it here before it takes effect, so there is time to read it or to object.
A new use of data received from Google or Microsoft will not begin until we have told the people affected and obtained their consent to the updated policy for that new use.
17. Contact us
DeviceHero is responsible for this policy and for the service it describes. Write to us at support@devicehero.app with a question about it, to make a privacy request, or to raise anything you think we have got wrong. That address is also where security reports and legal notices go.
Related pages: Terms of Service and service status.