heygrc
heyGRC legal

heyGRC Privacy Policy

Effective date: 2026-10-01

This page is the privacy policy for heyGRC: the heyGRC website (heygrc.com), the heyGRC console (app.heygrc.com), the heyGRC GitHub App and heyGRC's optional Google Drive connection.

heyGRC is a product of Better ISMS EURL, the company that also runs ISMS Copilot. heyGRC is covered by the ISMS Copilot Privacy Policy, which applies to heyGRC in full. This page sets out what is specific to heyGRC, including the complete disclosure for data heyGRC receives from Google. If this page and the full policy ever differ, the text that is more protective of you applies, and we will correct the other. Nothing in the full policy permits any use of Google user data that this page excludes.

Who is responsible

  • Controller: ISMS Copilot, operated by Better ISMS EURL, France (European Union)
  • Privacy contact: privacy@ismscopilot.com
  • Supervisory authority: Commission Nationale de l'Informatique et des Libertés (CNIL)

For the content your organization gives heyGRC to review (pull requests, linked documents, company context), we act as your organization's processor under the Data Processing Agreement.

What heyGRC processes

  • Account data: the email address and sign-in identifiers of the people who use the heyGRC console, and the organizations they belong to.
  • Pull-request review data: when your organization installs the heyGRC GitHub App, heyGRC receives the pull requests it reviews from GitHub and posts its review back. How heyGRC handles your code is summarized on Trust and security and described in the full privacy policy.
  • Billing data: handled by Stripe. We do not store card details.
  • Google Drive files: only if an owner or admin of your organization connects Google Drive. See Google user data below.

Google user data

heyGRC's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements (see the Google Workspace API User Data and Developer Policy).

  • Who can connect and use it: only an owner or admin of your heyGRC organization can connect Google Drive, and only the person who connected can add files from Drive, from the Google account they connected.
  • Permissions we ask Google for: drive.file, which lets heyGRC open only the individual files that you pick in Google's file picker or open with heyGRC, and nothing else in your Drive; and, if the person who connected turns on Open with, drive.install, which only makes heyGRC appear in Google Drive's Open with menu for that account. drive.install does not let heyGRC see, list or open any file.
  • What we access: the files you choose (their content, name, type, size, and the modification time, checksum and version Google reports); the email address and account identifier of the Google account that connected; and, when you open a file with heyGRC, the file identifier and Google account identifier that Google sends with it. We cannot list, search, or open any other file in your Drive. heyGRC reads Google Docs and plain-text, Markdown and HTML files; Google Sheets, Google Slides, PDF and Word files are not supported yet. If someone other than the person who connected opens a file with heyGRC, heyGRC does not read or keep that file; it tells them to ask that person.
  • How we use it: only to provide the feature you turned on: to confirm that the file can be read and what type it is, to extract its text and compile it into your heyGRC linked-document review pack (clauses with verified quotes that heyGRC cites in your pull-request reviews), to check linked files once a day and re-read only the ones that changed (a file that keeps changing is checked less often, down to once a week), and to show who connected and manage the connection. heyGRC only reads your files. It never edits, moves, deletes, or changes the sharing of any file.
  • Who we share it with: the extracted text of the files you chose is sent to the AI model providers listed for heyGRC review in the ISMS Copilot Privacy Policy (the zero-data-retention OpenRouter provider set, or Mistral AI in the EU if your organization enabled EU inference), for inference only, to compile and apply your clauses. These providers do not retain it after processing and do not use it to train models. Short verified quotes from these files appear in the pull-request reviews (hosted by GitHub, Inc.) heyGRC posts to your private GitHub repositories where heyGRC is installed; on public repositories heyGRC refers to them only by subject. Our EU hosting and database providers (Fly.io and Supabase) process and store it on our behalf. We do not share Google user data with anyone else, except as required by law, or, with your prior explicit consent, as part of a merger, acquisition or sale of assets.
  • What we do not do: we do not sell Google user data. We do not use or transfer it for advertising, including retargeting, personalized or interest-based advertising, and we do not transfer it to advertising platforms, data brokers or information resellers. We do not use it to determine creditworthiness or for lending purposes. We do not use it, and do not let anyone else use it, to create, train, or improve any artificial intelligence or machine-learning model, whether a generalized model or a model personalized to you. Our staff do not read it, except with your permission for specific files, where needed for security (for example investigating a bug or abuse), to comply with applicable law, or for internal operations in aggregated and anonymized form.
  • How we store and protect it: the OAuth refresh token is encrypted with AES-256-GCM in an EU-hosted database table that only our backend can read, and is never logged or sent to an AI model. Short-lived access tokens are never written to a database or log: they are held in server memory until they expire (about an hour), and when you use Google's file picker, one is handed to your browser for that session. Extracted text and compiled clauses are stored in the EU. Extracted text is readable only by our backend; compiled clauses and their quotes are also shown to members of your heyGRC organization in the console and can be quoted in heyGRC's pull-request reviews (hosted by GitHub, Inc.) on your private GitHub repositories, as described above.
  • How long we keep it and how to delete it: we keep a linked document's extracted text and compiled clauses only while the document stays linked in your heyGRC console. When you remove the document, we delete its content. Quotes heyGRC has already posted in pull-request reviews stay in your GitHub repository, where you can edit or delete them. We delete the refresh token when you disconnect Google Drive in the heyGRC console, when the person who connected leaves your organization or loses the owner or admin role, and when your organization uninstalls heyGRC. Disconnecting stops all further reads; documents already linked keep their last extracted text until you remove them. Linked-document content is deleted about 30 days after your organization uninstalls heyGRC, by a daily purge job. Audit records of the connection (for example who disconnected and when; never a token or file content) follow the period in "heyGRC Audit Records" in the ISMS Copilot Privacy Policy (up to 12 months). You can also remove heyGRC's access at any time at https://myaccount.google.com/permissions. If you remove access there, we delete the stored token the next time heyGRC contacts Google. Questions or deletion requests: privacy@ismscopilot.com.

Your rights

You can ask to access, correct, export or delete your personal data, or object to its processing, at privacy@ismscopilot.com. The full list of rights, retention periods, sub-processors and international transfers is in the ISMS Copilot Privacy Policy. You can also complain to the CNIL or to your local data protection authority.