Privacy Policy
Last updated 21 August 2026
Hacerfy is a task manager that follows work through — it keeps track of what needs to happen, and it can send and receive messages on your behalf so that waiting on other people does not become your job. Doing that means handling your work content, and where you choose to connect an account such as Gmail or Telegram, some content from that account too.
This policy explains what we receive, what we do with it, and what we do not do with it. It describes the product as it actually works today, not as it may work later.
Who we are
Hacerfy is operated by Pronto Sage (“Hacerfy”, “we”, “us”). You can reach us about anything in this policy at support@hacerfy.com.
When you create an account, Hacerfy opens a workspace that belongs to you. Your workspace is kept separate from other customers’ workspaces, and content you create in it is not visible to other customers.
Information Hacerfy receives
Account information
Your email address, your display name, and the password you set, which we store only as a cryptographic hash and cannot read back. If you set them, we also hold your language and time zone, because nothing can schedule or phrase anything sensibly without both.
Work content
The substance of what you use the product for: tasks, projects, goals, checklists, deadlines and commitments, notes, status updates, decisions, and the history of how each of those changed.
Messages and conversations
Messages Hacerfy sends on your behalf, replies it receives, and the conversation each belongs to — including delivery outcomes, so the product can tell “the provider accepted this” from “nobody could be reached”.
Files and links
Files you attach and links you save as evidence or reference, together with what they are attached to.
People you record
Names, contact addresses and roles of people you add so that work can be assigned to them or followed up with them. Some of these are people other than you — see Your choices and rights for what that makes you responsible for.
Meetings and scheduling
Meetings, agendas, outcomes, availability you record, and proposed or agreed times.
Standing instructions and preferences
Working hours, rules you set for how the assistant should behave, notification preferences, and similar settings.
Connection information
Where you connect an external account, we hold the authorization that account issued, the address or identifier it belongs to, and the settings for that connection. See Connected services.
Operational and security records
Records of actions taken in your workspace — who or what did them, when, and with what outcome — which is what makes the product’s own automated actions auditable by you. Our servers and our infrastructure providers also process technical information such as IP addresses and request metadata to deliver and protect the service; IP addresses are used transiently for rate limiting and are not kept as part of your workspace record.
Your Hacerfy record and connected-service data
Two different things are worth telling apart, because they behave differently when you disconnect something.
- Your Hacerfy record is what lives in the product: your tasks, messages, files, people, meetings and history. It exists in your workspace and stays there until it is deleted.
- Connected-service data is content Hacerfy reads from an external account you connected — for example a reply in your mailbox. We access it only within the permissions that connection granted, and only to provide the capability you connected it for.
Connected services
You may connect external services to Hacerfy. Today that includes Telegram, and where the deployment you use has been configured for it, Gmail. Other providers may be offered over time; a provider only appears in your settings when it is actually available to connect.
Connecting a service authorizes Hacerfy to act within the permissions you granted and no further. We use that access to provide the operational capability you connected it for — sending a message, reading a reply, finding something relevant to a task — and not for unrelated purposes. Connecting a service does not transfer ownership of that account or its contents to us.
Each provider has its own terms and privacy policy, and its own controls for reviewing or revoking what you granted. You can disconnect a service from Hacerfy at any time in Settings.
Google user data
This section applies when you connect a Google account, such as Gmail. It is specific because Google requires it to be, and because you should be able to read exactly what connecting your mailbox permits.
What we access, and why
When you connect Gmail, Hacerfy may use the access you granted to:
- send email related to your tasks and follow-ups on your behalf;
- receive replies to those messages and match them to the task and conversation they answer;
- read the content of messages relevant to that work, so a reply can be understood rather than merely counted;
- search your mail for messages relevant to a task, where you have asked Hacerfy to find supporting evidence;
- process attachments on those messages where you attach them to work;
- maintain the ongoing context of a task-related email thread.
What connecting a mailbox does not do
Connecting Gmail does not copy your mailbox into Hacerfy. We do not import your existing mail history when you connect: the connection begins from the moment you make it. Unrelated mailbox content is not intended to become part of your Hacerfy record merely because the account is connected, and the mail Hacerfy reads can be narrowed further by the search terms configured for the connection.
How the authorization is protected
The credential Google issues is held in our secret store, encrypted at rest, and is resolved only at the moment a call is made. It is never returned by our API, never shown in the interface, and is not exposed to other customers. When you disconnect, we ask Google to revoke it and we stop using it.
Limited use
Where Google user data is processed by a model provider in order to produce a feature you asked for — for example, summarising a reply — that processing is limited to providing the feature. See AI and model processing.
AI and model processing
Hacerfy uses AI models to interpret what you write and what arrives — reading a reply to work out whether it answers the question, turning a sentence into a task, drafting a follow-up, summarising a thread. To do that, the relevant content is sent to a model provider for processing and the result is returned to your workspace.
- Platform-provided models. By default, processing uses a model service selected by the deployment operator. Content is sent to that provider to produce the feature you asked for.
- Your own model. Where you configure your own model provider, content for those features is sent to the provider you chose instead, under your arrangement with them and subject to their terms.
Model output is recorded alongside the work it relates to, so that a decision the assistant made can be inspected afterwards rather than taken on trust. Your content is not used to serve advertising, and it is not sold. Voice transcription is not enabled on this service; a voice note is stored as a file and reported as untranscribed rather than silently processed.
Retention and deletion
- Your work and its history are kept while your account and workspace are active, because that history is what the product is for.
- Disconnecting a provider stops the connection and revokes the credential; it does not delete tasks, messages or files already in your workspace.
- Credentials for a connection you end are revoked with the provider where it supports revocation, and deactivated on our side.
- You can ask us to delete your account and its content by writing to support@hacerfy.com. Deletion at your request is currently handled by us rather than by a button in the product.
- Some records may be kept after deletion where we need them to meet a legal obligation, resolve a dispute, or investigate abuse or a security incident.
- Backups age out on our operational cycle, so content can persist in backups for a period after it is removed from the live service.
We do not publish fixed retention periods, because setting one we do not actually enforce would be worse than saying so plainly.
Security
We take reasonable measures to protect your information, including:
- separation between customer workspaces, so one cannot read another;
- access controls on who and what may act in a workspace, with automated actions recorded;
- encryption in transit between your browser and the service;
- credentials for connected accounts kept in a secret store, encrypted at rest, never returned by the API and never shown in the interface;
- session tokens held in cookies your browser will not expose to page scripts;
- rate limiting and operational logging to detect and contain abuse.
No service can promise that information is impossible to compromise, and we do not make that claim. Messages sent over email or Telegram are handled by those providers on their own terms and are not end-to-end encrypted; treat them as you would any ordinary email or chat message. If you believe your account has been accessed without your authorization, write to support@hacerfy.com.
Where processing happens
Hacerfy is operated with infrastructure and service providers that may be located in countries other than your own, and your information may be processed in those countries. This includes the model provider that performs AI processing. Where we transfer personal data internationally, we do so on the basis permitted by the law that applies to you.
Your choices and rights
You can, at any time:
- review and correct your account details and settings in the product;
- disconnect any connected service in Settings, and additionally revoke Hacerfy’s access from the provider’s own security settings;
- request a copy of the personal data we hold about you, or ask us to correct or delete it, by writing to support@hacerfy.com.
Depending on where you live, you may have further rights — such as objecting to or restricting certain processing, or complaining to a data protection authority. Tell us what you need and we will deal with it under the law that applies to you.
Age
Hacerfy is not intended for children. You must be at least 16 years old to use the service. If we learn that we hold information from someone under that age, we will delete it.
Changes to this policy
We may update this policy as the product changes. When we do, we will update the date at the top, and where a change materially affects how we handle your information we will make reasonable efforts to tell you before it takes effect.
Contact
Questions, requests, or anything you think this policy gets wrong: support@hacerfy.com.
Our Terms of Service govern your use of Hacerfy.