The execution layer is still being built. This page separates what is true of the design from what
is implemented, because the difference is the only part of a privacy page worth reading.
What your assistant never sees
No credential ever enters your assistant’s context, or the model’s. Not a password, not a one-time code, not a token for a third party. When Hence needs one, it sends your assistant a link; you open it and enter the value on a single-use page on our domain, and it goes from your browser into the one form it was requested for. Your assistant sees what you would tell a person helping you: which errand is running, what question is pending, what the result was. That last part is not nothing — a result can carry an APR, a balance or a match formula, and those pass through the conversation like any other answer, subject to whatever your assistant’s provider retains. What it never holds is a credential, a one-time code or a third-party token, and screenshots of signed-in pages are referenced rather than handed over.What Hence stores
When an errand runs, it records the task and its steps, the receipt for each act, the values it read and where they came from, the audit trail for each single-use credential fill, and the screenshots and any statements it downloaded. Figures an errand establishes about you — an APR, a match formula — are written into your financial profile, which is the same profile the rest of Hence reads. No retention period is stated here, because none has been set. Rather than invent one, this page says so. When a retention rule exists it will be stated on this page, with the date it took effect.Asking for erasure
To ask what is held about you, or to ask for it to be erased, write to privacy@usehence.com. Erasure completes within 30 days for application data, plus up to 28 days for relational backup erasure and up to 30 days for R2 lifecycle erasure. Nothing about it is instant, and we will not claim otherwise: for that window, copies survive in backups we cannot reach individually, and they age out rather than being picked out. How long we keep your data while you are a customer and how long an erasure takes are different questions, and the paragraph above answers the first.Screenshots are not redacted during the pilot
How to revoke a connection
Remove the Hence connector in your host’s settings. It stops being able to call us at that moment, and no further errand can be started through it.Who can run errands right now
Access is gated to accounts on our own company domain during the pilot, and it is evaluated on our side for the signed-in user at the moment a tool is called. Anyone may add the connector and complete the consent flow; if access is not enabled, every tool refuses cleanly and says so. Everything on this page — the unredacted screenshots most of all — is confined by that gate to accounts inside the company while the pilot runs.The limits that do not move
- Hence does not move money between your accounts.
- Hence does not sign anything, elect anything, or prove your identity on your behalf.
- Hence does not enter a credential itself; every credential is entered by you, once, on our page.
- An errand that meets a hard stop — an active debt lawsuit, identity theft, insolvency, an irreversible tax election — stops and points you at a professional.