Privacy Policy
Last updated 4 October 2026
This policy explains what personal data Honk processes when you use the Honk service at honk-me.app, the Honk web app and the Honk apps for iPhone and Apple Watch: why we process it, for how long, who else receives it, and what your rights are.
- We use your data only to run Honk for you. No ads, no tracking, no analytics SDKs, and we never sell data.
- Messages your systems send are kept only for your plan’s retention period: at most 3, 14 or 30 days.
- AI features on iPhone run on the device. Nothing is sent to a server for AI.
- You can delete your account in the app at any time.
Who is responsible
The controller responsible for the Honk service at honk-me.app is:
Dan Florian, Strada Nicolae Steinhardt 6, 400194 Cluj‑Napoca, Romania. Email: [email protected].
When this policy says “Honk”, “we” or “us”, it means this controller.
What this policy covers
This policy applies to the Honk service hosted at honk-me.app, and to the Honk web app, iPhone app and Apple Watch app when they are connected to it.
The Honk apps can also connect to a Honk server that someone else runs. The operator of that server decides how data on it is used; for such a server, this policy covers only what the apps do on your device.
Content your systems send. You or your organization decide what your apps, scripts and servers send to Honk. We process those messages and images on your behalf, only to provide the service: to store, group, search and deliver them. Please don’t put more personal data into messages than you need.
What data we process
- Account
- Your email address and, if you add one, your name. Your language, time zone, notification and Trash settings, and whether two-step verification is on (its secret is stored encrypted).
- Sign-in
- When you ask for a sign-in code, we store your email address, the time, your IP address and a keyed hash of the code, never the code itself. A code works once, for 10 minutes. Invitations contain the invited email address and who sent them.
- Sessions and security logs
- For each signed-in browser or device: its type, name and user agent, its IP address, and when it signed in and was last used. Security and administrative actions, such as new ingestion keys, member changes or account deletion, are recorded in an audit log with the account, the action, the time and the IP address.
- Devices for notifications
- To send pushes we store each device’s push token (Apple Push Notification service on iPhone) or Web Push subscription (in browsers), with the device name, platform, app version, language and time zone. An Apple Watch that signed in through your iPhone can be listed too, without a push token.
- Messages and images
- The messages your systems send (title, text, severity, source and the other fields they include), how Honk grouped them, and your own read, handled, mute and Trash state. When a message has an image URL, the Honk server downloads the image from that address and stores it with the message.
- Workspaces and projects
- Workspace and project names, members and their roles, invitations, ingestion keys (stored only as a hash), rules, notification settings such as quiet hours and mutes, daily usage counts, the exports you create, and the notes you send with “Report incorrect grouping”.
- Support
- What you tell us when you write to us, and our replies.
We don’t collect your location, contacts, calendar contents, photos, browsing history, health or payment data.
Data that stays on your devices
- iPhone and Apple Watch: the apps keep a copy of your inbox on the device so it works offline, together with AI summaries and categories and Spotlight entries for search. Signing out on the iPhone removes all of them from the iPhone.
- Calendar: when you add an event found in a message, Honk asks only for permission to add events. It never reads your calendar.
- Contacts: “Add to Contacts” opens the system’s new-contact card. Honk doesn’t read your contacts.
- Camera: used only to scan the pairing QR code shown in the Honk web app.
- Web app: your browser keeps your session cookies, an offline copy of your inbox and preferences such as theme and language. Signing out clears your session and the offline copy.
On-device AI on iPhone
On iPhones that support Apple Intelligence, Honk uses Apple’s on-device Foundation Models to write short summaries, titles and categories for your messages and notifications. This runs entirely on your iPhone: no message content is sent to Honk, to Apple or to anyone else for AI, and Honk doesn’t use cloud AI models.
AI only rewords what your iPhone shows. It never deletes, hides, delays or downgrades a message or a notification, and the original text is always available. You can turn it off in Honk under Settings ▸ AI.
Why we use your data, and our legal basis
- To provide Honk
- Creating and running your account, signing you in, receiving, grouping, storing and searching messages, sending notifications to your devices, workspaces and members, exports, and support. Legal basis: the performance of our contract with you (Art. 6(1)(b) GDPR).
- To keep Honk secure and reliable
- Rate limits, abuse prevention, security and audit logs, backups and recovery after failures, and investigating problems. Legal basis: our legitimate interest, and yours, in a secure and reliable service (Art. 6(1)(f) GDPR).
- To meet legal obligations
- When the law requires us to keep or disclose information (Art. 6(1)(c) GDPR).
We send only service emails: sign-in codes and invitations. No newsletters, no marketing.
How long we keep data
- Messages and their images
- Deleted automatically after the project’s retention period: at most 3 days on Free, 14 days on Pro and 30 days on Team. Admins can choose a shorter period.
- Trash
- Moving a message to Trash hides it only for you. Your Trash empties itself after the period you choose (7 to 90 days, 30 by default), and the project’s retention period still applies, so nothing stays longer than that.
- Notification history
- Records of sent notifications and their delivery status: 31 days.
- Exports
- Available for 24 hours after they are created.
- Sign-in codes and invitations
- A code is valid for 10 minutes; the record of the attempt is removed in routine clean-up, usually within a day. Invitations that were never accepted are deleted 30 days after they expire.
- Sessions
- While you stay signed in (a session ends after 90 days without use), then 30 more days.
- Devices
- Until you sign out on that device, remove it, or delete your account.
- Audit log
- 12 months.
- “Report incorrect grouping” notes
- 90 days.
- Logs
- Our web server’s access logs contain IP addresses; old log files are deleted after 30 days. The application’s own logs never contain message content, keys or cookies.
- Backups
- The database is backed up every 6 hours, and backups are kept for up to about 4 weeks. A few extra copies made just before software updates are replaced as newer updates happen. Deleted data disappears from backups when they expire; we don’t edit backups to remove single items.
- Deleted accounts
- When you delete your account, we immediately remove your email address and name, sign you out everywhere, remove your devices and memberships, and delete the workspaces in which you are the only member, with all their data. Messages in workspaces you share with others stay there under those workspaces’ retention. Audit log entries are kept for their 12 months, and backups expire within about 4 weeks.
- Support emails
- As long as we need them to handle your request.
Service providers and other recipients
We use these providers to run Honk. They process data only for the purposes described here:
- Hetzner Online GmbH
- Hosts the Honk server and its backups in a data center in Germany (EU).
- Cloudflare, Inc.
- Network proxy, content delivery and protection against attacks. All traffic to honk-me.app passes through Cloudflare, which processes it, including IP addresses, in order to deliver it.
- Mailman (themailman.xyz)
- Sends our emails: sign-in codes and invitations. Open and click tracking are switched off.
- Apple Push Notification service
- Delivers notifications to iPhones. Apple receives the device token and the notification content that your preview setting allows; the “Generic” preview sends no message content.
- Browser push services (Apple, Google, Microsoft, Mozilla)
- Deliver Web Push notifications to your browser. The content is encrypted for your browser, so the push service can’t read it; it sees the subscription address and technical data.
Inside Honk. Members of a workspace see the messages of the projects they can access, according to their role; owners and admins also see the workspace’s audit log. Honk’s operators can see account and workspace details, such as email addresses, workspaces, plans and usage counts, in order to run the service; the operator console doesn’t show message content. For support, an operator can sign in as a user for at most one hour, and this is recorded in the audit log of each of that user’s workspaces.
Apple. If you download the app from the App Store, Apple handles the download under its own privacy policy.
Authorities. We disclose data to authorities only when the law requires it.
International transfers
The Honk server and its backups are in Germany, in the EU. Some of the providers listed above, such as Cloudflare, Apple, Google, Microsoft and Mozilla, are based in the United States or operate worldwide, so data may be processed outside the European Economic Area.
When that happens, the transfer is protected by safeguards that the GDPR recognizes: an adequacy decision of the European Commission (including the EU–U.S. Data Privacy Framework for certified companies) or the Commission’s standard contractual clauses. You can ask us for details at [email protected].
No advertising, no tracking
- No advertising and no ad networks.
- No tracking across apps or websites, and no tracking pixels or tracked links in our emails.
- No analytics or crash-reporting SDKs in the apps or the web app.
- We never sell or rent personal data, and we don’t use your messages to train AI models.
Your rights
Under the GDPR you have the right to:
- Access your data and receive a copy of it.
- Correct it: change your name, language and time zone in the web app’s Settings, or write to us for anything else, such as your email address.
- Delete it: on iPhone, Account ▸ Delete account; on the web, Settings ▸ Account ▸ Delete my account. If you are the only owner of a workspace with other members, transfer ownership or delete that workspace first.
- Take it with you: owners and admins can export a project’s messages as NDJSON in the web app (the project’s Export tab). For a copy of your account data, write to us.
- Restrict processing, or object to processing based on our legitimate interests.
- Withdraw permissions you gave on your device, such as notifications, camera and calendar access, at any time in the device settings.
- Complain to a data protection supervisory authority, in particular in the EU country where you live or work, or where you think the infringement happened.
To use these rights, write to [email protected]. We answer within one month and may ask you to confirm that the account is yours, usually by replying from its email address.
Children
Honk is a tool for people and teams who run websites, shops, automations and apps, and is not intended for anyone under 16. If you think a child under 16 has given us personal data, contact us and we will delete it.
Security
We protect your data with measures that fit a service like Honk, including:
- HTTPS with HSTS for every connection to honk-me.app.
- Sign-in with one-time codes instead of passwords. Codes, session tokens and ingestion keys are stored only as hashes.
- Optional two-step verification, and a fresh confirmation before sensitive actions such as creating keys or deleting your account.
- Push credentials and two-step verification secrets encrypted at rest.
- Strict separation between workspaces, rate limits, audit logs, and logs without message content, keys or cookies.
- Regular backups.
Messages are not end-to-end encrypted: the Honk server reads them in order to group and route them. For projects with sensitive content, choose the “Generic” push preview, so notifications show no content.
Changes to this policy
We update this policy when Honk or the law changes, and the date at the top shows the current version. If a change affects how we use your data, we will tell you in the app or by email before it takes effect.
Contact
Questions about privacy, or a request about your data: [email protected].
Dan Florian, Strada Nicolae Steinhardt 6, 400194 Cluj‑Napoca, Romania.
For help with the app, see Support.