Skip to content

Last updated 30 July 2026

Privacy

Superhive holds two of the most personal things you own, your diary and your mail. This page says exactly what we take, what we keep and what we never touch. If anything here is unclear, write to hello@superhive.app and we will fix the wording.

Your email address and display name, so you have an account. Your tasks, projects and labels, because that is the product. Calendar events from the calendars you connect: title, time, location, attendee addresses and free or busy state. From Gmail: message headers, thread ids, labels and a short snippet of the most recent message in a thread.

We also record ordinary operational data. Request timestamps, a request id, the API route and the response status. There is no advertising identifier, no third party analytics script on this website, and no cross-site tracker anywhere in the product.

We do not download attachments. We do not read message bodies beyond the snippet used to classify a thread, and that snippet is not written to disk. We do not sell data, share it with advertisers, or use your content to train a model, and there is no setting that turns any of that on.

No person at Superhive reads your mail. Support staff can see your account email, your plan and the operational logs above. Reading your content requires your explicit written permission for a specific incident, and it is logged.

Everything travels over TLS. Integration tokens are sealed with AES-256-GCM under a key that is not stored beside them, so a stolen database row is not a stolen mailbox. Backups are encrypted and expire after 30 days.

Data is processed in the European Union and the United States by our hosting and database providers. We do not move your content anywhere else.

Disconnect a calendar or an inbox at any time from Settings. Disconnecting revokes the token with Google immediately and deletes the derived rows in the same request. You can also revoke access from your Google account without opening Superhive.

Export everything as JSON from Settings. Delete your account from the same screen: tokens are revoked at once and every remaining row is removed within 30 days. If you are in the EU or the UK you have the usual rights of access, rectification, erasure, restriction, portability and objection, and you exercise them with those two buttons or by writing to us.

This website sets no cookies and runs no analytics. The app stores a session token on your device so you do not sign in every morning. That is the whole list.

If we change something material we will email everyone with an account at least 30 days before it takes effect, and say plainly what changed. The date at the top of this page is the last time a single word of it moved.