This policy explains what HyperTools collects, how we use it, and the choices you have — including Google sign-in and optional Calendar sync. It is written for humans. It is not legal advice.

Who we are

HyperTools (“we”, “us”) is a product studio. The service at https://app.hypertools.dev is a suite of focused apps: Compass (personal planning), Canvas (collaborative boards), Shift Manager (rosters, hours and pay), and Kana (Japanese kana practice).

Questions about this policy: support@hypertools.dev.

Information we collect

We collect only what we need to run the studio. Depending on how you use HyperTools, that may include:

Account. Name, email address, password (stored as a hash — we never see the plain text), role (manager or employee), optional profile photo, and the manager/employee link if you join a team.

Google sign-in. If you choose “Continue with Google”, Google shares the name, email address, and profile picture associated with that Google account so we can create or recognise your HyperTools account. We do not receive your Google password.

Google Calendar (optional). If you connect a calendar in Settings, we store OAuth access and refresh tokens, the connected Google email, and IDs of events we create. The Calendar permission we request is calendar.events, so we can create, update, and delete events on calendars you can access. We use that only to push HyperTools items one way onto your calendar (shifts, and Compass prep blocks if you turn calendar sync on). We do not read, import, scan, or list your existing calendar events.

App content you create. Compass tasks, notes, calendar blocks, habits, focus sessions, weekly goals and reflections, content-pipeline drafts; Shift Manager shifts, hours, pay, recaps, and clock-ins; Canvas boards, nodes, and images; Kana study progress. Timezone is read from your browser so reminders fire at a local time you chose.

Notifications you opt into. Web Push subscription keys for the installed app; optional Discord webhook URLs or Telegram chat IDs you paste into Compass settings.

Technical. Auth session cookies, a short-lived OAuth state cookie during Calendar connect, and a theme preference in localStorage. We do not currently use advertising cookies or third-party analytics pixels.

How we use it

We use personal information to:

  • Create and authenticate your account (email/password or Google).
  • Provide the apps — planning, rosters, boards, and study.
  • Send transactional email (sign-up codes, password resets) via Postmark from support@hypertools.dev.
  • Sync shifts and optional Compass prep blocks to Google Calendar when you have connected it.
  • Send the reminders you enabled (morning brief, nightly preview, weekly reset) over Web Push, Discord, or Telegram.
  • Keep the service secure, debug issues, and meet legal duties.

We do not sell personal information. We do not use it for advertising. We do not train AI models on Google user data, and we do not transfer information received from Google APIs to AI systems.

Google user data

HyperTools’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In plain terms:

  • Google sign-in data is used only to identify you and populate your profile.
  • Calendar tokens and event IDs are used only to write (and later update or delete) events that originated in HyperTools.
  • We do not share Google user data with third parties except Google itself (to perform the API calls you authorised) and our infrastructure processors listed below, who are bound to handle it only to run the service.
  • Disconnecting Calendar in Settings deletes the stored tokens immediately. Events already created on your Google Calendar stay there unless you delete the matching item in HyperTools first, or remove them in Google Calendar.

Who can see your data

Your manager / your team (Shift Manager). If you are an employee linked to a manager, that manager can see your shifts, hours, pay, clock-in status, and whether Calendar is connected. They cannot see your password or Google tokens.

Compass is private by default. A manager sees Compass data only if you turn on a sharing toggle for that module in Settings. Shared views are summaries (counts, titles, busy blocks) — never habit names or full lists you have not opted to share. Timetable sharing exposes busy times only, never event titles.

Canvas share links. If you turn on link sharing for a board, anyone with the URL (and the password, if you set one) can view or edit it, including people without a HyperTools account. Treat that link like a secret.

Processors who host or deliver the service: Convex (database and backend), Vercel (web hosting), Google (sign-in and Calendar API), Postmark (email), and, if you enable them, the Web Push services of your browser vendor, Discord, or Telegram. They process data on our instructions to provide those functions.

Retention and deletion

We keep account and app data for as long as your account is active. You can edit or delete most content in the apps themselves (tasks, shifts, boards, and so on).

To close your account and delete personal information we hold, email support@hypertools.dev from the address on the account. We will delete or de-identify your data within a reasonable time, except where we must keep a record (for example a transaction you asked us to keep, or a legal obligation).

Security and transfers

Data is stored with our processors (primarily Convex and Vercel) using encrypted connections. Google tokens are stored in our database and used only on the server. No method of transmission or storage is perfectly secure.

Processors may be located outside Australia (including the United States). By using HyperTools you understand that your information may be processed in those places, subject to this policy and the safeguards those providers offer.

Your rights

Depending on where you live, you may have the right to access, correct, or delete personal information, to withdraw consent (for example by disconnecting Google Calendar or turning off notifications), and to complain to a regulator. In Australia that is the Office of the Australian Information Commissioner (oaic.gov.au).

Start with us: support@hypertools.dev.

Children

HyperTools is built for work and personal productivity. It is not directed at children under 16. We do not knowingly collect personal information from them. If you believe we have, contact support@hypertools.dev and we will delete it.

Changes

We may update this policy as the studio changes. The “Last updated” date at the top will change. Continued use after a revision means you accept the new policy. Material changes that affect Google user data will stay consistent with Google’s Limited Use rules.