1. Who we are and who this policy covers
OneHop is a private relationship memory: it helps you remember, keep up with and get introduced through the people you already know. OneHop is based in Sydney, New South Wales, Australia (“OneHop”, “we”, “us”).
This policy covers three groups of people:
- Members — people with a OneHop account.
- People in members’ networks — the colleagues, friends and contacts that appear in a member’s imports and connected accounts. Most of them have never used OneHop. We have written a short, dedicated notice for them at /privacy/your-data, and every right in this policy applies to them too.
- Visitors — anyone browsing our website or a member’s public contact card.
We wrote this policy to meet the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs), the EU and UK General Data Protection Regulation (GDPR), and US state privacy laws. Where those laws differ, we apply the stricter rule to everyone.
Questions go to our privacy officer at privacy@onehop.network. We reply to every privacy message within 30 days, and usually much sooner.
2. Our commitments
These are binding parts of this policy, not marketing copy. If we ever change one, we will tell members in advance (see Changes to this policy) and the change will apply only to data collected afterwards.
- Your network is yours. We hold it to provide OneHop to you. We do not use it for anyone else’s benefit.
- We never sell, rent, license or trade personal information, and we never “share” it for cross-context behavioural advertising (in the sense of the California Consumer Privacy Act). We run no ads and no advertising trackers.
- No pooled people database. We do not merge members’ networks into a directory or search index that others can browse. Another member learns something about your network only through features you have switched on, and only the limited fields described under Who can see what.
- We do not train AI models on your data. Not ours, not our vendors’. That covers your imports, your connected accounts, your notes, and information about the people in your network.
- Email metadata by default. Unless you switch on email content for a specific account, we read only the sender, recipients, date and subject of your messages. We never read the body.
- We never contact the people in your network on your behalf without your explicit instruction, and never for our own marketing.
- No face recognition or other biometric processing of photos.
- Public-source look-ups only when you ask, only for people already in your network, and never to obtain someone’s personal email address or phone number from a scraper.
- Leaving is easy. Disconnect any source and we delete what came from it. Close your account and we delete everything, as set out under How long we keep information.
3. What we collect and where it comes from
From you, when you create and use an account
- Name, email address and password (stored only as a salted hash), or your Google sign-in identity.
- Multi-factor authentication secrets (encrypted), sign-in history, device and browser details for security.
- Your profile, goals, asks and offers, notes, tags, tasks, check-ins, card details and settings.
- Subscription and billing details. Stripe collects and stores your card, and we receive only a token, the card brand, the last four digits and your billing history.
- Messages you send to us, and feedback you give on introductions and suggestions.
From files you import
Official “download your data” archives that platforms give you for exactly this purpose. Examples are your LinkedIn data export (connections, positions, invitations, message metadata), Google Takeout, Facebook, Instagram and TikTok “Download your information” files, and your X archive. You choose which files to upload.
From accounts you connect
| Source | What we read | What we don’t |
|---|---|---|
| Google (Gmail, Contacts, Calendar, Docs) | Email sender, recipients, date and subject; contacts and “other contacts”; calendar event titles, times and attendees; Gemini meeting-note documents, only if you turn on meeting notes. | Email bodies and attachments, unless you turn on email content for that account (then we store up to an 800-character excerpt per message). We never send, delete or change anything. |
| Microsoft 365 / Outlook | The same headers, contacts and calendar details as Google. | Bodies and attachments, unless you turn on content. We never send, delete or change anything. |
| HubSpot, Attio | Contacts, companies, meetings, notes and call metadata you already hold there. | We never write back or change your CRM. |
| Slack, Discord and other community platforms | Member lists, profile fields and conversation metadata, connected by you or by a community operator you have joined. | Private messages you are not a party to. |
| Just Say Hey | Friends, spaces and events, if you link your account. | Just Say Hey is a separate service with its own privacy policy. |
| AI assistants (Claude, ChatGPT and similar) | Facts you ask your assistant to remember about you, and requests it makes on your behalf. | We see only what your assistant sends to OneHop’s connector. |
Connections are read-only unless a feature clearly says otherwise and you approve each action (for example, posting an ask you have drafted). You can disconnect any source at any time in Settings.
From your own devices
If you install our Mac or Android companion, it reads your address book and, on a Mac and only if you allow it, the metadata of your Messages conversations (who, when, how often, in which direction). The companion runs on your device under your control and uploads only to your account.
From people you meet in person
When someone scans your OneHop contact card and chooses to share their details back, we receive only the fields they tick. They see exactly what is shared before sending.
From public sources, only when you ask
For a person who is already in your network, you can ask OneHop to complete their profile from public professional sources. This means headline, current and past roles, company, education, skills, location and public photo. We show you the cost and ask for confirmation each time. Our providers are listed under Service providers. We do not use these look-ups to obtain personal email addresses or phone numbers, we never look up people you don’t already know, and we honour every opt-out on our suppression list before any look-up runs. If you connect your own Apollo account, look-ups made with your key are between you and Apollo, and the results stay in your workspace only.
What we derive
From the information above we calculate signals that make OneHop useful to you. These include relationship strength and how recently you were in touch, the nature of a relationship (colleague, client, friend), seniority, industry and community groupings, shared interests, suggested people to reconnect with, and search indexes (including numerical “embeddings”). This is profiling, and Profiling and automated decisions explains it and your right to object.
Automatically, when you use OneHop
Server logs (IP address, browser, pages requested, errors) and a record of which features you use, kept in our own database to run and improve the product. We use no third-party analytics, advertising or tracking scripts. Cookies are covered under Cookies and local storage.
4. Sensitive information
We do not ask for sensitive information (health, religion, political opinions, sexual orientation, racial or ethnic origin, trade-union membership, criminal record, biometrics). Your imports may still contain some, for example a calendar event title or a note you write. We use it only to show it back to you.
We design our AI features so they do not infer or store sensitive characteristics about anyone. Interests, groupings and labels that would reveal them are discarded. If you ever see one, tell us at privacy@onehop.network and we will remove it and fix the cause.
5. How we use information, and our legal bases
Under the APPs we use personal information for the primary purpose it was collected for, or a related purpose you would reasonably expect. Under the GDPR each use needs a legal basis. Both are set out here:
| What we do | Why | Legal basis (GDPR) |
|---|---|---|
| Run your account, sign-in, security and billing | To provide OneHop and keep it safe | Contract; legal obligation for tax and billing records |
| Store and organise what you import or connect | So OneHop can show you your own network | Contract with you; for people in your network, legitimate interests (yours, in managing your own relationships) |
| Calculate relationship signals, groupings and suggestions | The core of the product | Legitimate interests, balanced by the limits in this policy; you can object |
| Complete a profile from public sources | Because you asked, for someone you already know | Your request plus legitimate interests, balanced by our suppression list, field limits and retention limit |
| Show intro paths, match asks and offers, run Envoy | Features you switch on | Consent (your opt-in, revocable at any time) |
| AI features (Ask, summaries, drafting, explanations) | To answer your questions about your own network | Contract; consent for meeting-note summaries and email content |
| Product emails (reminders, digests, security alerts) | To tell you what you asked to hear about | Contract; legitimate interests for security |
| Marketing email from us | Only if you opt in | Consent (unsubscribe in every message) |
| Prevent abuse, enforce our Terms, meet legal duties | To keep members and their contacts safe | Legitimate interests; legal obligation |
7. Service providers and international transfers
Your OneHop data is stored in Sydney, Australia. Some providers process it elsewhere, as listed below. Each one is bound by a contract that limits them to providing their service to us, requires appropriate security, and (where the GDPR applies) includes Standard Contractual Clauses or an equivalent safeguard. Under APP 8 we remain accountable for how they handle it.
| Provider | Purpose | Location |
|---|---|---|
| Neon (on Amazon Web Services) | Primary database | Sydney, Australia |
| Cloudflare | Hosting, content delivery and security | Global edge network; processed close to you |
| OpenAI | AI features: understanding questions, summaries, drafts, explanations, embeddings, public web search when you ask | United States |
| TypeSafe AI | Fast text classification (for example, is this message an ask or an offer) | United States |
| Stripe | Payments and invoices | Australia and United States |
| Resend and Amazon SES | Sending account and product emails | United States |
| Apify | Public-profile look-ups you request | European Union (Czech Republic) |
| Apple and Google | Wallet passes, only if you add your card to a wallet | United States |
We give members at least 30 days’ notice before adding a provider that processes personal information. Email privacy@onehop.network to receive that notice. If you object and we cannot address it, you can close your account and receive a pro-rata refund of prepaid fees.
Companies whose services you connect (Google, Microsoft, HubSpot, Attio, Slack, Discord, Just Say Hey, your AI assistant) are not our processors. They are sources you control, and their own privacy policies apply to them.
8. Artificial intelligence
- AI powers Ask, search, summaries, draft messages, explanations of why someone is a good fit, and Envoy. Text written by AI is labelled as such.
- When a feature needs a model, we send only the information needed for that request. Our AI providers process it under business terms that forbid training on it and limit how long they keep it (OpenAI keeps API data for up to 30 days for abuse monitoring, then deletes it).
- We do not train, fine-tune or improve any AI model, ours or anyone else’s, with your data or the data of people in your network.
- Meeting-note summaries and email-content features are off until you turn them on.
- AI output can be wrong. Treat it as a suggestion, and use the sources OneHop shows you to check it before you rely on it.
- Notes, email excerpts and message previews are treated as data, never as instructions to the model, so text inside them cannot make OneHop act on its own.
9. Profiling and automated decisions
OneHop uses automated processing to rank and suggest people, estimate relationship strength, match asks with offers, match a contact to a public profile, and screen introduction requests (Envoy). The inputs are interaction metadata (how often and how recently you were in touch, and in which direction), shared employers, schools, communities and events, roles and seniority, and what you have told OneHop about your goals.
None of these produces a decision with legal or similarly significant effects on anyone. They are suggestions to you. A person always decides whether to make or accept an introduction. Envoy never declines a request on its own, and profile matches wait for your confirmation.
You can correct any score or label, hide a suggestion, or switch off the feature. Anyone, member or not, can ask us to explain an automated outcome that involves them, object to it, or have a person review it by writing to privacy@onehop.network.
10. How long we keep information
| Information | How long |
|---|---|
| Your account, network and notes | While your account is open |
| Data from a source you disconnect | Deleted within 30 days of disconnecting, along with what we derived from it |
| Email and message excerpts (content opt-in) | 24 months, then the text is removed and only metadata remains |
| Public-source profile details | 24 months after your last interaction with that person, then refreshed at your request or deleted |
| A closed account | Deleted within 30 days of closure, including search indexes and vendor copies |
| Encrypted database backups | Overwritten on a rolling cycle within 30 days |
| Server logs | 90 days |
| Security records (sign-ins, account and admin actions — no message content) | 12 months, to investigate misuse and protect accounts |
| Billing and tax records | 7 years (required by Australian tax law) |
| Opt-out (suppression) records | Kept as long as needed to honour the opt-out, stored as one-way hashes |
11. Security
- Encryption in transit (TLS) everywhere; encryption at rest for the database and backups; OAuth tokens and authentication secrets separately encrypted.
- Multi-factor authentication for members; every database query is scoped to its owner; features that cross between members are enforced in the database and covered by automated privacy tests.
- Staff access is limited to what is needed, logged, and used only to support you (with your permission), to keep the service secure, or to comply with the law.
- If a data breach is likely to cause serious harm, we will notify affected people and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme. Where the GDPR applies, we notify the relevant authority within 72 hours.
- Found a vulnerability? Please report it to security@onehop.network. We will not pursue good-faith research that respects our members’ privacy.
No system is perfectly secure, but we will always tell you honestly what happened and what we did about it.
12. Your rights and choices
Whether or not you are a member, you can ask us to:
- Access the personal information we hold about you, and get a copy in a portable format.
- Correct anything inaccurate, out of date or incomplete.
- Delete it. Members can also disconnect individual sources.
- Object to profiling or to public-source look-ups, or restrict how we use your information.
- Withdraw consent for any opt-in feature, at any time, without affecting what came before.
- Opt out of look-ups for good. We add you to our suppression list so no member can trigger a public-source look-up about you again.
- Remain anonymous or use a pseudonym when you contact us, where that is practical.
Email privacy@onehop.network from the address involved, or follow the steps on /privacy/your-data if you are not a member. We may ask you to confirm that you control an email address, phone number or profile before acting. We respond within 30 days, at no cost. If we refuse a request, we will tell you why and how to complain. We will never treat you worse for exercising a right.
For people in a member’s network: we delete everything we hold about you as controller. That means information we obtained from public sources, anything we inferred about you, and any match of you to other members, and we stop further look-ups. A member’s own records of you, such as their address book or their inbox, belong to them, just like their phone’s contacts do. You can ask them directly, and we will pass your request on if you want us to.
Complaints
Please contact us first so we can put it right. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner, to your local data protection authority in the EU or UK, or to your state Attorney General in the United States.
United States residents
In the last 12 months we have collected the categories described under What we collect: identifiers, professional and employment information, commercial (billing) information, internet activity on our service, and inferences. We disclose them only to the service providers listed under Service providers, for the business purposes listed under How we use information. We do not sell or share personal information, and we do not use sensitive personal information to infer characteristics. You may use an authorised agent. If we deny your request you can appeal by replying to our decision. We will answer the appeal within 45 days.
13. Google user data
OneHop’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- We use Gmail, Contacts, Calendar and Docs data only to provide and improve the features you see in OneHop: your network, relationship signals, reminders, meeting context and search.
- We do not use it for advertising, to build profiles for anyone else, or to determine creditworthiness, lending or insurance eligibility.
- We do not use it to develop, improve or train generalised AI or machine-learning models.
- We transfer it only to the service providers needed to run those features (see Service providers), to comply with law, or as part of a merger with your notice.
- Nobody at OneHop reads it unless you ask us to for a specific item, it is needed for security or to comply with law, or it has been aggregated and anonymised.
- Disconnecting Google in Settings deletes the data we obtained from it within 30 days. You can also revoke access at myaccount.google.com/permissions.
15. Children
OneHop is for adults. You must be 18 or older to create an account, and we do not knowingly collect information from children. If you believe a child’s information is in OneHop, tell us and we will delete it.
16. Other platforms and links
OneHop imports only data that platforms provide to you for export, or that they offer through official connections you authorise. We are not affiliated with, endorsed by, or sponsored by LinkedIn, Google, Microsoft, Meta, X, TikTok or any other platform we mention. Links to other sites are governed by their own policies.
17. Changes to this policy
We will post every change here and update the date at the top. For material changes we will email members and show a notice in the app at least 30 days in advance. We will not apply a less protective change to information we already hold without your consent. Previous versions are available on request.
18. Contact us
Privacy officer: privacy@onehop.network
General support: support@onehop.network
Security reports: security@onehop.network
OneHop, Sydney, New South Wales, Australia