What HeyPM handles, what it sends where, and what you can ask me to delete. Written to be read once and understood, rather than to be technically survivable.
Last updated 26 August 2026This page describes what happens to your information when you use HeyPM: the website, the demo, and the agent once it is running on a program of yours. It is written in plain English on purpose. If your legal or security team needs it in their own format, email hello@heypm.ai and I will work through their questionnaire with them.
Everything below is what actually happens today, not what is planned. Where a thing is a limitation rather than a feature, it says so.
HeyPM is a product of Yavade, Inc., a corporation registered in Ontario, Canada and based in LaSalle, Ontario. Where this page says I or me, it means Yavade, Inc. Where it says you, it means whoever the workbook belongs to.
Yavade is run by Aman Vohra. There is no team, no support desk and no third party administering your account. When you email hello@heypm.ai, I read it.
That is a genuine trade. It means questions get answered by the person who wrote the code. It also means there is one person, and you should size your risk accordingly.
The workbook is created in your Google Drive, under your Google account, in the first minute of the first conversation. It is yours the way any spreadsheet you made is yours.
For the agent to read the plan and write back to it, you grant HeyPM access to that one file. That access is what makes the morning run possible, and it is the only thing you are granting. It does not extend to the rest of your Drive.
The workbook is not mirrored into a database, a data warehouse or a backup of mine. The sheet is the system of record, which is the whole point of building it this way.
Every weekday morning the agent reads your workbook, works out what has moved and what has not, and writes back. Doing that means it handles:
Documents you send during discovery, such as a charter or an existing plan, are read to build the program and are not needed afterwards. See how long things are kept.
Four services are involved in running HeyPM. This is the complete list, and what each one sees.
| Service | What it is for | What it sees |
|---|---|---|
| The workbook itself, your Drive, and the mail that carries each brief. | Everything in the workbook, because the workbook is a Google Sheet in your own Google account. | |
| Anthropic | The model that reads the rows and writes the answers and briefs. | The rows relevant to the question being answered, sent at the moment of answering and not retained afterwards. |
| n8n | The automation that wakes up each morning and runs the sequence. | The workbook contents in transit while a run is in progress, and the run’s own log. |
| Cloudflare | Hosting for this website and the demo. | Standard web request data. Nothing from any customer workbook. |
Ask me for the current hosting regions and the model provider’s terms before you sign anything. A security review should not have to take my word for it, and I will send the actual documents.
Your program content is not used to train any model. The commercial terms of the model provider are what make that true, and I will send you those terms if you want to read them rather than take the sentence at face value.
Nor do I use your workbook to improve HeyPM’s own templates. What I learn from running programs is the kind of thing anybody learns from doing the work, and it never travels as your content.
| Where | What it takes | Why |
|---|---|---|
| The intake form | Your name, your email, what you wrote about your program, and up to six files. | So I can read the real thing before the call instead of guessing on it. |
| Booking a call | Whatever Google Calendar asks you for. | The booking runs on Google Calendar, so their privacy terms apply to that step. |
| Anything you email | Your address and what you wrote. | To answer you. |
There is no advertising pixel, no cross-site tracker, no session recorder and no newsletter you get put on for filling something in. If you send the intake form, you get a reply from a person about that program, and nothing else unless you ask for it.
The demo runs on a fictional program that ships with HeyPM. It is not your data and it never becomes your data.
Do not paste anything confidential into the demo. It is a sandbox on a fictional program, and it was not built to be the place your real numbers live.
You give me the names and addresses of the people on your program so the agent can send them their brief. Two things follow from that.
You need the right to give them. These are work addresses being used for work, which is ordinary, but you are the one who knows your own obligations to your staff and your contractors. I am relying on you here.
They are used for one thing. Their brief, about their items, on your program. They are never marketed to, never added to a list, and never used to reach them about anything else. When they come off the program, they come out of the workbook and the briefs stop.
Each brief contains links that are signed and specific to one person and one item. There is no login, because the link itself is the credential. That is what lets somebody answer in one tap from a phone in a warehouse, which is the whole reason people actually reply.
It cuts both ways. Because the link is the credential, forwarding a brief lets somebody else answer as that person. Treat a brief like any other work email. This is a deliberate trade of strictness for reply rate, and you should know it is the trade being made.
| What | How long | Who ends it |
|---|---|---|
| Your workbook | Forever, because it is in your Drive and it is yours. I never delete it. | You. Revoke access or delete the file. |
| Files you sent during discovery | Through the engagement, then deleted within 30 days of it ending. | Automatic, or sooner if you ask. |
| Intake form submissions | Twelve months, so I can remember a conversation we started. | Ask and it goes immediately. |
| Demo workbook copies | Deleted 30 days after the demo. | Automatic. |
| Demo email addresses | Kept to stop the same person running it endlessly. | Ask and it goes. |
| Email you sent me | Kept like any working correspondence. | Ask and it goes. |
One email to hello@heypm.ai gets you any of these. No form, no ticket number.
I will answer within 30 days and usually within the same week. If you are somewhere whose law gives you these rights formally, you have them here regardless of where I am sitting, because arguing about jurisdiction is a poor way to treat somebody asking a reasonable question.
What is true today:
What is not true today, and I would rather you hear it here than find out in a questionnaire: HeyPM has no SOC 2 report, no ISO 27001 certification and no penetration test on file. It is a young product run by one person. If your organisation requires those before a tool can touch program data, HeyPM does not clear that bar yet, and I will say so on the call rather than waste your procurement team’s time.
When this page changes, the date at the top changes with it. If a change actually affects what happens to your data, you get an email about it before it takes effect, not a quiet edit and a new timestamp.