1. Local data protection

Supported notes, transcripts, meeting data, and files stored by hello hero on your Mac are encrypted at rest using AES-256-GCM. hello hero creates a local device key and protects it using Electron safeStorage, which uses the operating system's secure storage facilities on macOS.

File encryption is performed in chunks so large recordings and attachments do not need to be held entirely in memory. Authentication tags are checked when content is decrypted, helping detect modified or corrupted ciphertext.

2. Recovery

The app can generate a recovery kit that wraps the local encryption key using a recovery key derived with scrypt. Store the kit and recovery key somewhere secure and separate from the Mac. Anyone who obtains both the recovery material and encrypted data may be able to recover it.

If all trusted devices and the recovery key are lost, we may be unable to restore encrypted content. A recovery export is decrypted and is no longer protected by hello hero encryption; you are responsible for protecting and deleting exported copies.

3. Encrypted sync and team workspaces

For supported cloud-synced content, the app generates content keys and workspace keys on the client. Content and metadata such as titles are encrypted before upload, and keys are wrapped for authorized workspace members. The backend stores ciphertext, encrypted key envelopes, versions, and the operational records needed to synchronize content and enforce membership.

Account identity, membership, roles, invitations, billing, credit usage, and other service metadata are not part of the encrypted content payload because the service needs them to authenticate users and operate the workspace.

4. Hosted transcription and AI

Hosted processing is intentionally separate from encrypted storage. For live or file transcription, the relevant audio is sent through our hosted endpoint to Soniox. For AI chat and summaries, the app sends the prompt and selected context through our hosted endpoint to OpenRouter and the chosen model provider. These providers must receive readable input to perform the request.

The hosted transcription flow requests deletion of uploaded audio and transcription artifacts after processing. Processing providers may retain security logs or backups under their own policies and agreements. Do not submit content to a hosted feature if it must never leave your device.

5. Authentication and authorization

Account sign-in uses Google or Microsoft through Convex Auth. Local authentication session data is encrypted on the Mac. Hosted workspace operations check authenticated identity and workspace role, and shared content keys are issued only through the authorized workspace flow.

You are responsible for securing your Mac, operating-system account, Google or Microsoft account, recovery kit, and any device or workspace access you grant to another person.

6. Network and infrastructure

Network requests use HTTPS or secure WebSocket connections. Cloudflare delivers the website and hosted worker endpoints, Convex provides account and backend services, and collaboration transport is hosted on Cloudflare. Our providers maintain their own infrastructure controls and compliance programs; their certifications do not certify hello hero itself.

7. Calendar and payment credentials

If you connect a calendar, the service stores Google or Microsoft OAuth tokens needed to retrieve events until you disconnect the integration or the token is revoked. Polar handles payment entry and card data; hello hero stores the customer, order, subscription, and credit records needed to apply the purchase.

8. Safe use

9. Reporting a security issue

If you believe you found a vulnerability or unauthorized access, email privacy@hellohero.ai with enough detail for us to reproduce or investigate the issue. Please do not access other users' data, disrupt the service, or publish sensitive details before we have had a reasonable opportunity to respond.

10. Incident response

We investigate credible security reports, work to contain and remediate confirmed incidents, and notify affected users or authorities when required by applicable law. The timing and detail of a notice depend on the nature of the incident and legal requirements.

11. No absolute guarantee

No application, encryption design, provider, or operational process can eliminate every risk. This page describes the current design; it is not a warranty that the service is invulnerable. We will update it when material security architecture or processing boundaries change.

12. Contact

Security and privacy reports can be sent to privacy@hellohero.ai.