Privacy.
Effective August 19, 2026 · Applies to the Den product, the den.house website, and the waitlist
Den is built for the most private space a family has: the group chat. That only works if you can trust us with less, not more. This page explains, in plain language, what Den handles, what it does with it, and how to get it all deleted.
What Den is, and what it handles
Den is a household assistant you reach by text. It joins your family's iMessage thread, keeps track of what's coming, and does errands the household asks for. To do that, it handles:
- Messages your household sends it. The texts in threads Den is part of: what you ask for, what you approve, and what Den replies.
- Things you forward it. Each household gets its own private forwarding
address at
mail.den.house. Anything sent there — a school newsletter, an appointment confirmation, a sign-up form — is treated as something you asked Den to read. - Calendar data, if you connect a calendar. Events and times, used to build schedules and briefs and to check for conflicts before Den proposes anything.
- What you ask Den to remember. Lists, reminders, preferences, and the facts about your household that make its answers useful: sizes, allergies, who does pickup on Thursdays.
What Den does with it
- Runs the service for your household, and nothing else. Your household's content is used to provide Den to that household. It is not pooled with other families and is not used to build anything outside your den.
- Models draft; your household decides. AI models read the content to draft proposals: a reminder, a calendar entry, a form to file. Nothing takes effect in the world except through Den's approval flow, on terms your household set.
- Never training data. We do not use your household's content to train generalized AI or machine-learning models, ours or anyone else's.
- Never sold, never advertised against. We don't sell or rent your data, and we run no advertising business. There is nothing to monetize here but the subscription.
- You can see what Den knows. Den shows its work, and you can ask it what it has on file for your household.
Den's use of Google user data (Gmail and Google Calendar)
Households can connect a Google account so Den can spot family logistics — school emails, appointments, sign-up deadlines — and help coordinate them. Den's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Here is exactly what that connection does:
- Calendar, read-only (
calendar.readonly). Den reads the connected calendar to build your household's schedules and daily briefs, to place a detected obligation in context, and to check for conflicts and duplicates before proposing anything. It cannot change your calendar with this permission. - Calendar events (
calendar.events), asked for separately. Den does not request this at connect time. It asks only at the moment your household first tells Den to add or update an event, and uses it only for the events your household explicitly approves. - Gmail, read-only (
gmail.readonly). Read access to email so Den can find the logistics buried in it, like the deadline in a school newsletter or the time in a confirmation, and turn it into reminders and calendar entries your household reviews. Den never sends mail as you, and never labels, archives, marks read, or deletes anything. This connection is in use by our founding household today; it will be offered more broadly later. - What we never do with it. We do not sell Google user data, do not use it for advertising, and do not use it to train generalized AI or machine-learning models. We do not transfer it to anyone except the providers below, who process it only to run these features for you, or where security or the law requires it.
- Humans and your data. People at Den do not read your Google user data except with your explicit permission (for example, when you ask for help with a problem), for security investigations, or to comply with the law.
- Disconnecting and deletion. Disconnecting an account stops ingestion immediately. You can also revoke access from your Google account settings, and you can ask us to delete stored Google user data at hello@den.house.
Who else processes data for us
Den runs on a small set of providers, each doing one job. They are bound to process your data only to provide the service to you, not for their own purposes:
- Cloud hosting. Fly.io, where the Den application and its database run.
- Web and CDN. Cloudflare, which serves den.house and handles requests to it.
- Email delivery and receiving. Resend, which carries mail to and from your household's Den address.
- Payments. Stripe, which handles subscriptions. Den never sees or stores your card number.
- Messaging delivery. An iMessage service provider that carries messages between Den and your family's thread.
- AI inference. Model providers that process content to draft Den's proposals, under terms that prohibit using it to train their models.
Children
Kids are never users. Den has no child-facing features and no accounts for anyone under 13, and it never messages a child directly. Adults may of course mention their kids in their own notes and requests (pickup times, allergies, a permission slip), and Den treats anything about a child with its highest sensitivity handling.
Security
- Data is encrypted in transit, and credentials for connected accounts are encrypted at rest.
- Each household's data is isolated from every other household's at the database level.
- Access to production systems is limited to the people who operate them, and secrets are held in managed key storage rather than in code.
Den is an early product built by a small team. These are the practices we actually follow; we don't claim certifications or audits we haven't done.
Keeping your data, and deleting it
- We keep your household's data while the account is active, so Den can do its job.
- You can disconnect any integration at any time. Ingestion stops immediately.
- Email hello@den.house to delete your data: a single connection's data, or your household's account and everything in it.
This website and the waitlist
- Waitlist email. If you join the waitlist, we store the email address you submit, when you submitted it, your browser's user-agent string, and the country your request came from. Nothing else is recorded. We use it for one thing: contacting you about Den's waitlist and launch. We never sell it, rent it, or share it with advertisers.
- Anonymous usage analytics. This site uses PostHog to understand, in aggregate, how visitors use these pages (pages viewed, buttons clicked). We run no ad pixels and never share this data with advertisers. Fonts and all other assets are served from den.house.
- Hosting. The site and waitlist signups are served and stored with Cloudflare, which processes requests to serve this site and, like any host, sees standard request metadata.
- Want off the list? Email hello@den.house and we'll delete your record.
Changes to this policy
This version, effective August 19, 2026, is Den's full product privacy policy. It replaces the earlier version of this page (August 13, 2026), which covered only the website, the waitlist, and Google account connections. If we make a material change, we'll update the effective date above and tell households before it takes effect.
Contact
Questions about privacy: hello@den.house.