Your data
Privacy policy
Effective September 12, 2026
heydayclaw is a personal email assistant operated by Mihir Belose. This policy describes the application’s read-only Gmail and Outlook integration and this public information website.
Data accessed and why
After the account owner grants permission, heydayclaw can access email message identifiers, senders, recipients, subjects, timestamps, snippets, bodies, and read/unread status. It uses this information to search, display, and summarize messages when the owner asks. Gmail access is limited to https://www.googleapis.com/auth/gmail.readonly. Outlook access uses delegated Microsoft Graph Mail.Read.
The integration does not send email, create drafts, delete or archive messages, change labels, or update read/unread status. It does not access calendars or contacts, and it does not download attachments. No scheduled inbox polling is enabled in the current version.
Authorization and credentials
Google and Microsoft handle account sign-in and consent. heydayclaw does not ask for or store mailbox passwords. OAuth access tokens and refresh tokens allow the private service to retrieve authorized messages and renew access while the grant remains valid.
Processing and sharing
Email content retrieved for an assistant request may be sent to OpenAI through the operator’s authenticated Codex service to generate a response or summary. OpenAI’s handling of that content is governed by the operator’s applicable OpenAI terms and data settings. The current chat interface is the private OpenClaw dashboard.
heydayclaw does not sell email data, use it for advertising, or use it to develop or train its own machine-learning models. It does not publish mailbox content on this website. Google and Microsoft receive requests needed to provide their respective email and authorization services.
heydayclaw’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
Storage and retention
OAuth credentials are stored in permission-restricted files in the operator’s private virtual machine. A dedicated mail service handles the credentials; the assistant receives mail results through a restricted local connection.
The mail service does not maintain a separate synchronized mailbox archive. Retrieved content, summaries, and tool results can remain in the assistant’s conversation history until the operator deletes that history. OAuth credentials remain until they are removed or replaced. Revoking a provider grant stops future authorized access but does not automatically erase existing assistant conversations. Copies processed by external providers remain subject to those providers’ retention rules.
Control, revocation, and deletion
The owner can revoke Google access at Google Account connections and review Microsoft grants at Microsoft My Apps, subject to the college’s policies. The operator can remove stored credentials and assistant history from the private installation. For access, deletion, or privacy requests, contact belose.mihir@gmail.com.
This website
Vercel hosts these public informational pages. The site includes no analytics scripts, advertising trackers, forms, or mailbox connection endpoints. Vercel may process ordinary request information, such as IP addresses and browser metadata, to deliver and secure the pages under its own privacy policy. Mailbox credentials and email content are not uploaded as part of this site.
Changes and contact
This policy will be updated before the application adds materially different data uses or sharing. Questions can be directed to Mihir Belose at belose.mihir@gmail.com.