Legal

Privacy Policy

Last updated: August 5, 2026

This policy explains what data hegl collects, why we collect it, how we protect it, and how we use it. We collect only what we need to operate the service.

1. Who we are

Katch AI Inc. ("we", "our") operates hegl, the agentic automation platform available at hegl.ai. Businesses use hegl to describe a process they run manually, connect the systems that process touches, and have AI agents build and run it as an automated workflow — with a human decision step wherever their process requires one. We are the data controller for personal data collected through our website and for account and usage data. For customer content processed through the platform, we act as a data processor on behalf of the customer organization whose workflows process it.

Contact: privacy@hegl.ai

2. Data we collect

Account data. When you sign up, we collect your name, email address, and company name. This is required to create and manage your account.

Organizations and teams. hegl accounts belong to an organization. Administrators can invite other users into their organization, remove them, and assign roles that control what each member can see and do. When an administrator invites someone, we process the invitee's name and email address on the organization's instructions to set up their account.

Customer content. To operate the service, we process the content your workflows act on: the process descriptions, procedures, and example documents you share while building an agent, and the documents, messages, and records your configured workflows read from the systems you connect. This content is used solely to build and run the workflows you configure and to maintain the evaluation records that let you verify how your own agents are performing. We do not use your content to train generalized AI models.

Connected services data. When you connect a third-party account (for example Google Workspace, Dropbox, or Box — see our integrations overview for the full list), we receive an access credential authorizing exactly the permissions shown on that provider's consent screen, and we access data in the connected account only to execute the workflow steps you have configured. See "Data from connected accounts" below for how we handle this data.

Usage data. We log product events (e.g. which features you use, agent run counts) to improve the product and detect issues. This data is associated with your account and is not shared with third parties; sub-processors that help us operate the product process it only on our instructions (see Sub-processors).

Communication data. If you contact us, we retain that correspondence to respond to your inquiry and improve support quality.

3. How we use your data

We use the data we collect to:

  • Operate, maintain, and improve the hegl platform
  • Build and run the workflows you configure, on the data you connect
  • Maintain your evaluation records — the per-account history of what your agents saw and decided, which you use to verify and improve your own automations
  • Send you transactional emails (receipts, alerts, agent notifications)
  • Respond to support requests and bug reports
  • Comply with legal obligations

We do not sell your data. We do not use your content to train generalized AI models. Evaluation records are scoped to your account, are used only to test and improve your own workflows, and are never aggregated across customers.

4. How we protect your data

We protect all customer data, and sensitive data in particular, with the following measures:

  • Encryption in transit — all traffic between your browser, our services, and our sub-processors is encrypted with TLS 1.2 or higher.
  • Encryption at rest — our databases and backups are encrypted at rest. Credentials for connected third-party services, including OAuth access and refresh tokens, are additionally encrypted at the application layer before being stored, so they are never persisted in plaintext.
  • Access control — access to production systems and customer data is restricted to authorized personnel who need it to operate the service, and is protected by multi-factor authentication.
  • Workload isolation — each customer's workflows execute in an isolated project. One customer's automations cannot read another customer's data or credentials.
  • Auditability — administrative and agent activity is logged, and audit logs are retained for 12 months (see Data retention).
  • Deletion — disconnecting a third-party account deletes its stored credentials, and closing your organization's account deletes its data within 90 days (see Data retention).
  • Incident response — if we become aware of a breach affecting your personal data, we will notify you without undue delay and, where GDPR applies, within the timelines it requires.

5. Data from connected accounts

The commitments in this section apply to all data hegl accesses from any third-party account you connect. We access only the data covered by the permissions you grant on the provider's consent screen, and we use it solely to execute the workflow steps you have configured and to provide the product's user-facing features to you.

Within your organization, data from connected accounts — and the workflow runs, evaluation records, and decision steps built on it — is available to other authorized members according to the roles and permissions your organization configures (for example, a teammate reviewing a human decision step). This intra-organization sharing is part of the product's user-facing features. The restrictions below concern everyone else, including our own personnel.

With data from your connected accounts, we do not:

  • use it for advertising, or sell it to anyone;
  • transfer it to third parties, except as necessary to provide the features you configured, with your consent, for security purposes, or to comply with applicable law;
  • permit humans to read it, except with your explicit permission (for example a support request), where necessary for security or abuse investigation, to comply with applicable law, or where the data is aggregated and anonymized for internal operations;
  • use it to develop, improve, or train generalized artificial intelligence or machine-learning models.

When your workflows run, content from connected accounts may be processed by the AI model providers we use to run the agents you configure (see Sub-processors). They process it solely to execute your configured workflow steps and are contractually prohibited from using it to train or improve their models.

You can disconnect any account at any time, from hegl or from the provider's own security settings; when you do, we delete the stored credential. Content your workflows have already read from the account and stored — for example in your workflow run history or evaluation records — remains part of your account data and is covered by the Data retention section: you can request its deletion at any time, and it is deleted in any case when your account closes.

6. Google user data

If you connect a Google account, all of the commitments above apply to the Google user data hegl accesses — such as Gmail messages, Google Drive files, Google Sheets, Google Docs, and BigQuery data.

hegl's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

You can revoke hegl's access to your Google account at any time at myaccount.google.com/permissions; we delete the stored credential when you disconnect the account in hegl. Google user data your workflows have already stored — in your workflow run history or evaluation records — is deleted on request at privacy@hegl.ai, and in any case within 90 days of your organization's account closure.

7. Legal basis (GDPR)

For users in the EU/EEA, we process personal data on the following legal bases:

  • Contract performance — processing necessary to deliver the service you signed up for
  • Legitimate interests — product analytics and security monitoring, balanced against your privacy rights
  • Legal obligation — compliance with applicable law
  • Consent — where we explicitly ask for it (e.g. marketing emails)

8. Data retention

Account data is retained while your organization's subscription is active and deleted within 90 days of the organization's account closure. If you leave an organization, records of your activity within it (for example audit logs and decisions you made) remain part of that organization's data.

Customer content — including content read from connected accounts and stored in your workflow run history and evaluation records — is retained while your organization's account is active, or for the shorter window configured in your retention settings. Enterprise customers can configure custom retention windows down to 24 hours. All customer content is deleted within 90 days of account closure, and your organization can request deletion of specific content at any time at privacy@hegl.ai.

Credentials for connected third-party services are deleted when you disconnect the account.

Audit logs are retained for 12 months.

9. Sub-processors

We use a small number of sub-processors to operate the service, including cloud infrastructure providers, an email delivery service, and AI model providers used to run the agents you configure. All sub-processors are bound by data processing agreements and may only process your data on our documented instructions.

A current list of sub-processors is available on request at privacy@hegl.ai.

10. Your rights

Under GDPR, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request deletion ("right to be forgotten")
  • Object to or restrict processing
  • Port your data to another service
  • Withdraw consent where processing is based on consent

If your access to hegl is administered by an organization, requests that concern customer content we process on that organization's behalf should be directed to your organization; we assist our customers in fulfilling them. Requests about the account data we control can always be sent to us directly.

We extend these rights to all users, wherever you are located. If you are a California resident, you have corresponding rights under the CCPA, including the rights to know, delete, and correct; we do not sell or share personal information as defined by that law.

To exercise any of these rights, contact us at privacy@hegl.ai. We will respond within 30 days.

11. Cookies

We use strictly necessary cookies to keep you logged in and to maintain session state. We use analytics cookies to understand how the product is used — you can opt out via your browser settings or our cookie banner.

We do not use advertising or tracking cookies.

12. Changes to this policy

We may update this policy from time to time. Material changes will be communicated via email or an in-product notice at least 14 days before they take effect. The latest version is always available at hegl.ai/privacy.

13. Contact

Questions about this policy or your data? Email us at privacy@hegl.ai.