HeyZuly
Privacy Terms Home

Legal · Draft

Privacy Policy

Last updated: July 14, 2026 · Applies to heyzuly.com and the Hey Zuly app

Draft. This Privacy Policy is a working draft for soft-launch prep. It is not legal advice and has not been sealed by counsel. Have a qualified attorney review it before any Stripe billing or paid public launch.

1. Who we are

Hey Zuly (“Zuly,” “we,” “us”) operates an AI wellness guide at heyzuly.com. Zuly is a programmed persona that offers support for meditation, self-healing reflection, gentle body habits, and everyday life guidance. She is not a therapist, clinician, or medical device, and conversations with Zuly are not therapy, counseling, diagnosis, or medical treatment.

2. What this policy covers

This draft describes personal data we may collect when you join the waitlist, create an account, chat with Zuly, or use Wave / day-plan features. It will evolve as product and vendors go live. It is written for honesty during soft-launch prep — not as a finished, counsel-approved policy.

3. Not a HIPAA product

Hey Zuly is a consumer wellness product. We do not claim to be a HIPAA covered entity or business associate, and we do not offer HIPAA-compliant medical records services. Do not use Zuly to store information you only want handled under a clinical privacy regime. If you need clinical care, contact a licensed provider or local emergency services.

4. Information we collect

Depending on how you use the product, we may collect:

  • Waitlist email — when you join the waitlist (and optional honeypot / rate-limit metadata for abuse prevention).
  • Account data — if you use signed-in access, account identifiers and profile details provided through our auth provider (when Clerk is configured), such as email and user id.
  • Chat messages — what you send to Zuly and what Zuly replies, stored so conversations can continue across sessions.
  • Memory facts (user_facts) — short preference and context notes we retain to personalize guidance (for example, pillar focus, rhythm, onboarding answers).
  • Waves and day plans — Wave selections and structured day plans (waves / day_plans), including calendar export requests when you download an ICS file.
  • Technical data — routine logs such as timestamps, approximate request metadata, and error diagnostics needed to run and secure the service.

5. How we use information

  • Provide and improve the wellness guide, memory, and Wave experience
  • Authenticate you when accounts are enabled
  • Communicate about waitlist, invites, and (later) product updates you request
  • Operate safety features (for example, crisis resource routing when prompts suggest acute risk)
  • Prevent abuse, spam, and attempts to jailbreak the system for harm
  • Comply with law and enforce our Terms

We do not sell your wellness conversations to advertisers, and we do not run ad-tracking pixels on your journal or chat content.

6. Where data is hosted

The site and APIs are built to run on Cloudflare (Pages / Workers) with application data in Cloudflare D1. Processing happens in Cloudflare’s infrastructure according to our configuration and their platform practices.

7. Third parties we may use

When configured for an environment, we may use the following (this list is not a guarantee that every vendor is live today):

  • Clerk — authentication and account session management
  • Anthropic — model inference to generate Zuly’s replies
  • Resend — transactional or waitlist-related email, if/when enabled

Those providers process data only as needed to perform their services for us. Payment processing (for example Stripe) is planned for a later monetization phase and is not enabled by this draft; when billing launches, this policy will be updated after counsel review.

8. Crisis and safety

Zuly is not an emergency service. If you are in crisis or may harm yourself or someone else, contact local emergency services, call or text 988 (US), or visit findahelpline.com. We may surface crisis resources in product when risk signals appear; that is not a substitute for human help.

9. Retention and deletion

We keep waitlist, account, message, fact, and Wave data while those features are active and as needed to operate the service, prevent abuse, and meet legal obligations. Soft-launch controls for export and deletion will be refined; until then, contact us at the email below to request account or data deletion where feasible.

10. Age

Hey Zuly is intended for adults 18 years or older. We do not knowingly collect personal information from children under 18. If you believe a minor has provided data, contact us and we will take reasonable steps to delete it.

11. Your choices

  • Do not submit information you are uncomfortable storing with a wellness AI
  • Request deletion or correction by emailing us (see Contact)
  • Stop using the product and sign out when accounts are in use

Specific “do not sell / share” or regional rights language (for example GDPR / CCPA) will be completed with counsel before paid launch in applicable jurisdictions.

12. Security

We use platform security controls on Cloudflare (HTTPS, access controls, least-privilege secrets handling). No method of transmission or storage is perfectly secure. Treat sensitive clinical or legal details carefully and prefer human professionals for those needs.

13. Changes

We may update this draft as the product, vendors, and legal review progress. Material changes before paid launch will be reflected on this page with an updated date. Continued use after changes means you should re-read the current draft.

14. Contact

Questions about privacy: support@heyzuly.com · heyzuly.com

HeyZuly
Zuly is a wellness tool, not a medical device. It does not diagnose, treat, or prevent any condition. Zuly is an AI. Your conversations are not therapy and are not confidential in the same way. If you're in crisis, call or text 988 (US) or visit findahelpline.com.
Privacy · Terms · support@heyzuly.com
© 2026 · heyzuly.com