Privacy
Privacy policy
Last updated October 8, 2026
- We collect what’s needed to show a customer how their job is going, and to run a business’s account.
- We don’t sell personal information, and there are no advertising or tracking scripts.
- Card details go to Stripe, never to us.
- The business decides what goes on a customer’s page. Internal notes never reach it.
Who this covers
Here’s Your Update is used by two kinds of people, and this page covers both:
- Businesses and their teams, who have an account and use the app to post updates.
- Customers of those businesses, who open a private link to see how their job is going. Customers don’t have an account with us.
When a business adds a customer’s details or posts about their job, the business decides what goes in. We store and show that information on the business’s behalf. If you are a customer and want something corrected or removed, the business that sent you the link is the right place to start — and you can always write to us too.
What we collect
Account details. Your name, email address and password, and your business’s name, time zone and settings. Passwords are stored only as salted scrypt hashes; we can’t read them.
What a business puts in. Jobs, stages and notes; customers’ names, email addresses and phone numbers; updates, photos, videos, voice notes and documents; messages; approval requests; payment requests; and internal notes, which are never shown on a customer’s page.
What a customer does on their page. Messages they send, files they upload, feedback they leave, and their answers to approval requests — including the name they type or the signature they draw. We also record when a link was opened, so the business can see that an update was seen.
Technical details. The IP address and browser type are recorded when someone signs in, when a PIN-protected link is unlocked, when an approval is answered (as part of its record) and alongside entries in a business’s activity log. We keep short-lived counters to limit repeated sign-in, PIN and sign-up attempts.
Notifications. If you turn on browser notifications, we store the subscription your browser gives us so we can send them. Our Android app uses your browser’s notifications, so nothing extra is stored. In our iPhone app, we store the device token Apple gives the app, for the same purpose. We delete the subscription or token when you turn notifications off on that device, or when the push service tells us it no longer works.
Payments. Card details are entered on Stripe’s pages, not ours. We keep the amount, the status and Stripe’s reference for a payment. We never see or store card numbers.
How we use it
- To run the service: show the right page to the right person, keep the job’s history, and produce reports and exports.
- To send the emails, text messages and notifications a business sets up — a new update, an approval request, a weekly summary.
- To keep accounts and links secure, and to investigate reports of abuse.
- To bill for paid plans.
We don’t sell personal information, and we don’t use what’s in your account for advertising.
AI assist. When someone uses the writing assistant, the note they wrote is sent to an AI provider together with the business’s name, the job’s title and the customer’s first name, and the rewritten text comes back for a person to review. When someone asks it to suggest an update instead, the job’s current stage, what it is waiting on and its next step are sent. If no AI provider is connected, a built-in writer is used and nothing leaves our servers. Weekly summaries are always put together by that built-in writer — nothing from them is sent to an AI provider.
Cookies and browser storage
We use only what the product needs to work:
- A sign-in cookie that keeps you logged in. It lasts up to 30 days (two hours for a demo) and is removed when you log out.
- A link cookie, set only when a customer link is protected by a PIN, so the PIN isn’t asked for on every visit from the same device.
- Your light or dark preference, kept in your browser’s local storage.
- A few small notes for the app itself, kept in your browser’s storage too: an update you’ve started writing but haven’t posted yet, a hint you’ve dismissed, and whether notifications are on for this device.
There are no advertising cookies and no third-party analytics or tracking scripts on this site, in the app or on customer pages. The app installs a small service worker so it can be added to a home screen, show an offline notice and receive notifications.
Our mobile apps
Our Android and iPhone apps show this same website, signed in to the same account or opened on the same customer link. Everything on this page applies to them just as it does in a browser, and the same information is collected — nothing more, apart from the iPhone notification token described above.
- Android. The app is the website running full-screen in the browser already on your phone (usually Chrome). It has no analytics or advertising code of its own, and the only permission it asks for is to show notifications, which are the same browser notifications as on the website.
- iPhone and iPad. The app is a thin shell around the website. Browser notifications don’t work inside it, so when you turn notifications on, the app registers with Apple’s push service and passes us the device token Apple issues. It asks for the camera, photo library, microphone and speech recognition only when you use them — to add a photo or video, record a voice note or dictate an update.
Neither app contains advertising, analytics or tracking code, and neither reads your contacts, calendar or location.
Who else handles data
We use other companies to do specific jobs. Each one receives only what it needs, and only when that feature is switched on and used:
- Stripe — card payments from customers and billing for paid plans.
- Resend — sending email.
- Twilio — sending text messages.
- Anthropic or OpenAI — the writing assistant, as described above.
- Your browser’s push service (run by its maker, such as Apple, Google or Mozilla) — delivering notifications you’ve turned on. This covers the Android app too.
- Apple’s push service — delivering notifications you’ve turned on in the iPhone app.
- Your browser’s or phone’s speech recognition (run by its maker, such as Apple or Google) — turning what you say into text if you dictate an update. We receive only the text.
- Our hosting and file storage providers — running the servers and keeping the database and uploaded files.
We may also disclose information when the law requires it.
Customer links
A customer’s page is reached through a link containing a long random token. Anyone who has the link can open the page, so treat it like a private message. A business can add a 6-digit PIN, set an expiry date, replace the link or switch it off, and the old link stops working straight away.
Customer pages ask search engines not to index them, and photos and documents are served through signed links that expire after a few hours.
How long we keep it
We keep an account’s information for as long as the account is open. When something is deleted in the app it disappears from the workspace and from customer pages, but it can remain in our database and backups until it is permanently erased.
Approval records and the activity log are designed not to be edited after the fact — that is what makes them useful as a record.
You can delete your account yourself under Settings → Account → Delete account (what that removes). To have specific information permanently erased, or if you can’t sign in, write to support@heresyourupdate.com.
How we protect it
- Each business’s data is kept apart: every database query is scoped to one business below the application code.
- Internal notes and internal-only photos are filtered out on the server and are never sent to a customer’s browser.
- Only a hash of each customer link’s token and of each session token is stored.
- Sign-in, PIN entry and sign-up are rate-limited, and you can see and end your active sessions.
No system is perfectly secure. If you think you’ve found a problem, please tell us at support@heresyourupdate.com.
Your choices
- See and correct. Account owners can edit their own details, their customers and their jobs in the app.
- Take it with you. The Business plan can export jobs, customers, payments and the activity log as CSV files; on any plan you can ask us for a copy.
- Delete. Delete your account in Settings → Account, or ask us to erase specific information.
- Stop messages. Customers can ask the business to stop sending updates, or write to us and we’ll pass it on.
Depending on where you live, the law may give you further rights over your personal information. Write to support@heresyourupdate.com and we’ll help, whichever applies.
Children
Here’s Your Update is a tool for businesses and their customers. It isn’t meant for children, and we don’t knowingly collect information from them.
Changes and contact
If this page changes, we’ll update the date at the top. If a change is significant, we’ll tell account owners by email before it takes effect.
Questions about any of this: support@heresyourupdate.com.