OneHop
PrivacyTermsNot a member?

Privacy Policy

Your network is yours.

Last updated 30 September 2026

OneHop only works if you trust it with the people who matter to you. This policy explains, in plain English, what we collect, why, who can see it, how long we keep it, and how to make us delete it.

The short version

  • We never sell your data, run ads, or pool members’ networks into a people database.
  • We never train AI models on your data or on anyone in your network.
  • Email is metadata-only by default: who, when and subject, not the body.
  • Only you see your network. Sharing with other members is opt-in and limited to a few fields.
  • Public-profile look-ups happen only when you ask, and only for people you already know.
  • Your data is stored in Sydney. Disconnect a source or close your account and we delete it.
  • Not a member but in someone’s network? You have rights too. Start here.
  • Questions: privacy@onehop.network. We answer within 30 days.

Contents

  1. Who we are and who this policy covers
  2. Our commitments
  3. What we collect and where it comes from
  4. Sensitive information
  5. How we use information, and our legal bases
  6. Who can see what
  7. Service providers and international transfers
  8. Artificial intelligence
  9. Profiling and automated decisions
  10. How long we keep information
  11. Security
  12. Your rights and choices
  13. Google user data
  14. Cookies and local storage
  15. Children
  16. Other platforms and links
  17. Changes to this policy
  18. Contact us

1. Who we are and who this policy covers

OneHop is a private relationship memory: it helps you remember, keep up with and get introduced through the people you already know. OneHop is based in Sydney, New South Wales, Australia (“OneHop”, “we”, “us”).

This policy covers three groups of people:

  • Members — people with a OneHop account.
  • People in members’ networks — the colleagues, friends and contacts that appear in a member’s imports and connected accounts. Most of them have never used OneHop. We have written a short, dedicated notice for them at /privacy/your-data, and every right in this policy applies to them too.
  • Visitors — anyone browsing our website or a member’s public contact card.

We wrote this policy to meet the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs), the EU and UK General Data Protection Regulation (GDPR), and US state privacy laws. Where those laws differ, we apply the stricter rule to everyone.

Questions go to our privacy officer at privacy@onehop.network. We reply to every privacy message within 30 days, and usually much sooner.

2. Our commitments

These are binding parts of this policy, not marketing copy. If we ever change one, we will tell members in advance (see Changes to this policy) and the change will apply only to data collected afterwards.

  1. Your network is yours. We hold it to provide OneHop to you. We do not use it for anyone else’s benefit.
  2. We never sell, rent, license or trade personal information, and we never “share” it for cross-context behavioural advertising (in the sense of the California Consumer Privacy Act). We run no ads and no advertising trackers.
  3. No pooled people database. We do not merge members’ networks into a directory or search index that others can browse. Another member learns something about your network only through features you have switched on, and only the limited fields described under Who can see what.
  4. We do not train AI models on your data. Not ours, not our vendors’. That covers your imports, your connected accounts, your notes, and information about the people in your network.
  5. Email metadata by default. Unless you switch on email content for a specific account, we read only the sender, recipients, date and subject of your messages. We never read the body.
  6. We never contact the people in your network on your behalf without your explicit instruction, and never for our own marketing.
  7. No face recognition or other biometric processing of photos.
  8. Public-source look-ups only when you ask, only for people already in your network, and never to obtain someone’s personal email address or phone number from a scraper.
  9. Leaving is easy. Disconnect any source and we delete what came from it. Close your account and we delete everything, as set out under How long we keep information.

3. What we collect and where it comes from

From you, when you create and use an account

  • Name, email address and password (stored only as a salted hash), or your Google sign-in identity.
  • Multi-factor authentication secrets (encrypted), sign-in history, device and browser details for security.
  • Your profile, goals, asks and offers, notes, tags, tasks, check-ins, card details and settings.
  • Subscription and billing details. Stripe collects and stores your card, and we receive only a token, the card brand, the last four digits and your billing history.
  • Messages you send to us, and feedback you give on introductions and suggestions.

From files you import

Official “download your data” archives that platforms give you for exactly this purpose. Examples are your LinkedIn data export (connections, positions, invitations, message metadata), Google Takeout, Facebook, Instagram and TikTok “Download your information” files, and your X archive. You choose which files to upload.

From accounts you connect

SourceWhat we readWhat we don’t
Google (Gmail, Contacts, Calendar, Docs)Email sender, recipients, date and subject; contacts and “other contacts”; calendar event titles, times and attendees; Gemini meeting-note documents, only if you turn on meeting notes.Email bodies and attachments, unless you turn on email content for that account (then we store up to an 800-character excerpt per message). We never send, delete or change anything.
Microsoft 365 / OutlookThe same headers, contacts and calendar details as Google.Bodies and attachments, unless you turn on content. We never send, delete or change anything.
HubSpot, AttioContacts, companies, meetings, notes and call metadata you already hold there.We never write back or change your CRM.
Slack, Discord and other community platformsMember lists, profile fields and conversation metadata, connected by you or by a community operator you have joined.Private messages you are not a party to.
Just Say HeyFriends, spaces and events, if you link your account.Just Say Hey is a separate service with its own privacy policy.
AI assistants (Claude, ChatGPT and similar)Facts you ask your assistant to remember about you, and requests it makes on your behalf.We see only what your assistant sends to OneHop’s connector.

Connections are read-only unless a feature clearly says otherwise and you approve each action (for example, posting an ask you have drafted). You can disconnect any source at any time in Settings.

From your own devices

If you install our Mac or Android companion, it reads your address book and, on a Mac and only if you allow it, the metadata of your Messages conversations (who, when, how often, in which direction). The companion runs on your device under your control and uploads only to your account.

From people you meet in person

When someone scans your OneHop contact card and chooses to share their details back, we receive only the fields they tick. They see exactly what is shared before sending.

From public sources, only when you ask

For a person who is already in your network, you can ask OneHop to complete their profile from public professional sources. This means headline, current and past roles, company, education, skills, location and public photo. We show you the cost and ask for confirmation each time. Our providers are listed under Service providers. We do not use these look-ups to obtain personal email addresses or phone numbers, we never look up people you don’t already know, and we honour every opt-out on our suppression list before any look-up runs. If you connect your own Apollo account, look-ups made with your key are between you and Apollo, and the results stay in your workspace only.

What we derive

From the information above we calculate signals that make OneHop useful to you. These include relationship strength and how recently you were in touch, the nature of a relationship (colleague, client, friend), seniority, industry and community groupings, shared interests, suggested people to reconnect with, and search indexes (including numerical “embeddings”). This is profiling, and Profiling and automated decisions explains it and your right to object.

Automatically, when you use OneHop

Server logs (IP address, browser, pages requested, errors) and a record of which features you use, kept in our own database to run and improve the product. We use no third-party analytics, advertising or tracking scripts. Cookies are covered under Cookies and local storage.

4. Sensitive information

We do not ask for sensitive information (health, religion, political opinions, sexual orientation, racial or ethnic origin, trade-union membership, criminal record, biometrics). Your imports may still contain some, for example a calendar event title or a note you write. We use it only to show it back to you.

We design our AI features so they do not infer or store sensitive characteristics about anyone. Interests, groupings and labels that would reveal them are discarded. If you ever see one, tell us at privacy@onehop.network and we will remove it and fix the cause.

5. How we use information, and our legal bases

Under the APPs we use personal information for the primary purpose it was collected for, or a related purpose you would reasonably expect. Under the GDPR each use needs a legal basis. Both are set out here:

What we doWhyLegal basis (GDPR)
Run your account, sign-in, security and billingTo provide OneHop and keep it safeContract; legal obligation for tax and billing records
Store and organise what you import or connectSo OneHop can show you your own networkContract with you; for people in your network, legitimate interests (yours, in managing your own relationships)
Calculate relationship signals, groupings and suggestionsThe core of the productLegitimate interests, balanced by the limits in this policy; you can object
Complete a profile from public sourcesBecause you asked, for someone you already knowYour request plus legitimate interests, balanced by our suppression list, field limits and retention limit
Show intro paths, match asks and offers, run EnvoyFeatures you switch onConsent (your opt-in, revocable at any time)
AI features (Ask, summaries, drafting, explanations)To answer your questions about your own networkContract; consent for meeting-note summaries and email content
Product emails (reminders, digests, security alerts)To tell you what you asked to hear aboutContract; legitimate interests for security
Marketing email from usOnly if you opt inConsent (unsubscribe in every message)
Prevent abuse, enforce our Terms, meet legal dutiesTo keep members and their contacts safeLegitimate interests; legal obligation

6. Who can see what

By default, only you can see your network. Your people, notes, message metadata, strength scores and history are private to your account. Our staff do not look at them except as described below.

Features that involve other members (all opt-in)

  • Intro paths. If you and another member have both switched on introductions, OneHop can tell them that you know someone they want to meet. They see only that person’s name, role, company, public profile link and a coarse strength band (for example “close”). They never see your notes, messages, other contacts, or exact scores. Nobody is introduced without your approval.
  • Asks, offers, Envoy and goodwill. What you post is visible to the audience you choose. Envoy screens incoming requests for you. It can suggest a response but never declines or accepts on its own. Goodwill scores are relative to the person viewing them, are never public and are never exported.
  • Communities (Spaces). When you join a community on OneHop you choose who there can see you: nobody but the community team (Private), the community team only, or members too. Whoever can see you sees your name, photo, public profile and what you say you can help with. Your email and phone number are shown only if you tick “share my email” or “share my phone” for that community; otherwise people reach you through OneHop. The community operator is responsible for how they use its member data.
  • Contact card. Your public card shows only what you choose to put on it.
  • “Is this also you?” If another member’s address book has a handle that may belong to you, we may ask you to confirm it. We never show that suggestion to anyone else.

Switch any of these off in Settings → Privacy and your information stops appearing in them straight away.

Outside OneHop

  • Service providers who process data for us under contract (see Service providers).
  • Services you direct us to, such as an AI assistant you connect, a calendar you export to, or a digital wallet pass you add.
  • Law enforcement and courts, only when legally required. We will tell you first unless the law forbids it, and we challenge requests that are overly broad.
  • A buyer or successor if OneHop is sold or merged. They must honour this policy, and we will notify you before your information becomes subject to a different one.

7. Service providers and international transfers

Your OneHop data is stored in Sydney, Australia. Some providers process it elsewhere, as listed below. Each one is bound by a contract that limits them to providing their service to us, requires appropriate security, and (where the GDPR applies) includes Standard Contractual Clauses or an equivalent safeguard. Under APP 8 we remain accountable for how they handle it.

ProviderPurposeLocation
Neon (on Amazon Web Services)Primary databaseSydney, Australia
CloudflareHosting, content delivery and securityGlobal edge network; processed close to you
OpenAIAI features: understanding questions, summaries, drafts, explanations, embeddings, public web search when you askUnited States
TypeSafe AIFast text classification (for example, is this message an ask or an offer)United States
StripePayments and invoicesAustralia and United States
Resend and Amazon SESSending account and product emailsUnited States
ApifyPublic-profile look-ups you requestEuropean Union (Czech Republic)
Apple and GoogleWallet passes, only if you add your card to a walletUnited States

We give members at least 30 days’ notice before adding a provider that processes personal information. Email privacy@onehop.network to receive that notice. If you object and we cannot address it, you can close your account and receive a pro-rata refund of prepaid fees.

Companies whose services you connect (Google, Microsoft, HubSpot, Attio, Slack, Discord, Just Say Hey, your AI assistant) are not our processors. They are sources you control, and their own privacy policies apply to them.

8. Artificial intelligence

  • AI powers Ask, search, summaries, draft messages, explanations of why someone is a good fit, and Envoy. Text written by AI is labelled as such.
  • When a feature needs a model, we send only the information needed for that request. Our AI providers process it under business terms that forbid training on it and limit how long they keep it (OpenAI keeps API data for up to 30 days for abuse monitoring, then deletes it).
  • We do not train, fine-tune or improve any AI model, ours or anyone else’s, with your data or the data of people in your network.
  • Meeting-note summaries and email-content features are off until you turn them on.
  • AI output can be wrong. Treat it as a suggestion, and use the sources OneHop shows you to check it before you rely on it.
  • Notes, email excerpts and message previews are treated as data, never as instructions to the model, so text inside them cannot make OneHop act on its own.

9. Profiling and automated decisions

OneHop uses automated processing to rank and suggest people, estimate relationship strength, match asks with offers, match a contact to a public profile, and screen introduction requests (Envoy). The inputs are interaction metadata (how often and how recently you were in touch, and in which direction), shared employers, schools, communities and events, roles and seniority, and what you have told OneHop about your goals.

None of these produces a decision with legal or similarly significant effects on anyone. They are suggestions to you. A person always decides whether to make or accept an introduction. Envoy never declines a request on its own, and profile matches wait for your confirmation.

You can correct any score or label, hide a suggestion, or switch off the feature. Anyone, member or not, can ask us to explain an automated outcome that involves them, object to it, or have a person review it by writing to privacy@onehop.network.

10. How long we keep information

InformationHow long
Your account, network and notesWhile your account is open
Data from a source you disconnectDeleted within 30 days of disconnecting, along with what we derived from it
Email and message excerpts (content opt-in)24 months, then the text is removed and only metadata remains
Public-source profile details24 months after your last interaction with that person, then refreshed at your request or deleted
A closed accountDeleted within 30 days of closure, including search indexes and vendor copies
Encrypted database backupsOverwritten on a rolling cycle within 30 days
Server logs90 days
Security records (sign-ins, account and admin actions — no message content)12 months, to investigate misuse and protect accounts
Billing and tax records7 years (required by Australian tax law)
Opt-out (suppression) recordsKept as long as needed to honour the opt-out, stored as one-way hashes

11. Security

  • Encryption in transit (TLS) everywhere; encryption at rest for the database and backups; OAuth tokens and authentication secrets separately encrypted.
  • Multi-factor authentication for members; every database query is scoped to its owner; features that cross between members are enforced in the database and covered by automated privacy tests.
  • Staff access is limited to what is needed, logged, and used only to support you (with your permission), to keep the service secure, or to comply with the law.
  • If a data breach is likely to cause serious harm, we will notify affected people and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme. Where the GDPR applies, we notify the relevant authority within 72 hours.
  • Found a vulnerability? Please report it to security@onehop.network. We will not pursue good-faith research that respects our members’ privacy.

No system is perfectly secure, but we will always tell you honestly what happened and what we did about it.

12. Your rights and choices

Whether or not you are a member, you can ask us to:

  • Access the personal information we hold about you, and get a copy in a portable format.
  • Correct anything inaccurate, out of date or incomplete.
  • Delete it. Members can also disconnect individual sources.
  • Object to profiling or to public-source look-ups, or restrict how we use your information.
  • Withdraw consent for any opt-in feature, at any time, without affecting what came before.
  • Opt out of look-ups for good. We add you to our suppression list so no member can trigger a public-source look-up about you again.
  • Remain anonymous or use a pseudonym when you contact us, where that is practical.

Email privacy@onehop.network from the address involved, or follow the steps on /privacy/your-data if you are not a member. We may ask you to confirm that you control an email address, phone number or profile before acting. We respond within 30 days, at no cost. If we refuse a request, we will tell you why and how to complain. We will never treat you worse for exercising a right.

For people in a member’s network: we delete everything we hold about you as controller. That means information we obtained from public sources, anything we inferred about you, and any match of you to other members, and we stop further look-ups. A member’s own records of you, such as their address book or their inbox, belong to them, just like their phone’s contacts do. You can ask them directly, and we will pass your request on if you want us to.

Complaints

Please contact us first so we can put it right. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner, to your local data protection authority in the EU or UK, or to your state Attorney General in the United States.

United States residents

In the last 12 months we have collected the categories described under What we collect: identifiers, professional and employment information, commercial (billing) information, internet activity on our service, and inferences. We disclose them only to the service providers listed under Service providers, for the business purposes listed under How we use information. We do not sell or share personal information, and we do not use sensitive personal information to infer characteristics. You may use an authorised agent. If we deny your request you can appeal by replying to our decision. We will answer the appeal within 45 days.

13. Google user data

OneHop’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

  • We use Gmail, Contacts, Calendar and Docs data only to provide and improve the features you see in OneHop: your network, relationship signals, reminders, meeting context and search.
  • We do not use it for advertising, to build profiles for anyone else, or to determine creditworthiness, lending or insurance eligibility.
  • We do not use it to develop, improve or train generalised AI or machine-learning models.
  • We transfer it only to the service providers needed to run those features (see Service providers), to comply with law, or as part of a merger with your notice.
  • Nobody at OneHop reads it unless you ask us to for a specific item, it is needed for security or to comply with law, or it has been aggregated and anonymised.
  • Disconnecting Google in Settings deletes the data we obtained from it within 30 days. You can also revoke access at myaccount.google.com/permissions.

14. Cookies and local storage

We use only what the service needs to work:

  • a sign-in session cookie and security tokens that protect against forged requests;
  • preference cookies for choices you make (for example, trying a preview feature);
  • your browser’s local storage, for conveniences such as saved map views and offline use of the app.

No advertising, cross-site tracking or third-party analytics cookies. Because they are all strictly necessary, we don’t show a cookie banner. If that ever changes, we will ask first.

15. Children

OneHop is for adults. You must be 18 or older to create an account, and we do not knowingly collect information from children. If you believe a child’s information is in OneHop, tell us and we will delete it.

16. Other platforms and links

OneHop imports only data that platforms provide to you for export, or that they offer through official connections you authorise. We are not affiliated with, endorsed by, or sponsored by LinkedIn, Google, Microsoft, Meta, X, TikTok or any other platform we mention. Links to other sites are governed by their own policies.

17. Changes to this policy

We will post every change here and update the date at the top. For material changes we will email members and show a notice in the app at least 30 days in advance. We will not apply a less protective change to information we already hold without your consent. Previous versions are available on request.

18. Contact us

Privacy officer: privacy@onehop.network
General support: support@onehop.network
Security reports: security@onehop.network
OneHop, Sydney, New South Wales, Australia

Related

  • Terms of Service
  • Acceptable Use Policy
  • If you’re in someone’s network
OneHop

Everyone you need is one hop away.

Sign inGet started

Product

How it worksBring your communityGuides

Who it's for

Fractional executivesConsultants & advisorsFoundersCommunity organisers

Popular guides

How to ask for a warm introductionForwardable intro email templatesDouble opt-in introductionsHow fractional executives find clients through their network

Trust

PrivacyTermsNot a member?hello@onehop.network

© 2026 OneHop. OneHop is not affiliated with, endorsed by or a partner of LinkedIn, Meta, Google or Microsoft.