Privacy Policy

Last updated: August 4, 2026

Who we are

This Privacy Policy explains how AS Labs ApS ("we", "us", "our") collects and processes personal data when you use 9 Hats ("the Service"), available at https://9hats.app.

We are the data controller for personal data processed through your account.

Contact:

AS Labs ApS Hvedemarksvej 18 2605 Brøndby Denmark hello@9hats.app

Summary

The short version of what follows:

  • We collect what we need to run your account, the meeting notes you choose to send to us, and the content you create in the Discovery feature.
  • We send meeting content and Discovery inputs to Anthropic's Claude API for processing. Anthropic does not train its models on this data.
  • We use Convex, Vercel, Resend, Stripe, Cloudflare, Google, and PostHog for hosting, email, billing, infrastructure, login, and product analytics.
  • We don't sell your data. We don't show ads. We don't use your data for purposes beyond running the Service.
  • You can export your data, delete your account, and contact Denmark's data protection authority if you want to file a complaint.

What we collect

Account information

When you create an account, we collect:

  • Email address
  • Display name and profile picture (only if you log in with Google)
  • Authentication tokens issued by Google or our magic-link provider

Meeting content you connect

If you connect Granola, we read meeting notes and transcripts from your Granola account using the access you authorize. This content typically includes:

  • Meeting titles, dates, and times
  • Transcripts and notes
  • Participant names and email addresses where Granola has them
  • Anything else captured in the notes

Discovery content

When you use the Discovery feature, we store:

  • Discovery briefs, interview guides, synthesis documents, and PRDs you generate
  • Inputs you provide (research signals, interview content, project context)
  • Generated outputs

Billing information

If you subscribe to a paid plan, billing is handled by Stripe. We do not store your card number. We store a Stripe customer ID, your plan, and the status of your subscription.

Usage and technical data

When you use 9 Hats we automatically collect:

  • IP address
  • Browser type, operating system, and approximate location (country/region) derived from your IP
  • Pages and features you use within the Service
  • Error logs and diagnostic data

We do not collect precise location (GPS) data.

Data we receive from third parties

We receive:

  • Your Google profile (name, email, profile picture) when you sign in with Google
  • Meeting content from Granola when you connect it
  • Subscription status from Stripe

Special categories of data

We do not intentionally collect sensitive personal data (data about health, race, religion, sexual orientation, political opinions, trade union membership, biometric or genetic data).

However, meetings can contain anything participants discussed. If your meeting transcripts contain sensitive personal data, that data will pass through our Service. You are responsible for ensuring you have a legal basis to upload meeting content containing sensitive data about other people.

Data about other people in your meetings

Meeting transcripts contain personal data about meeting participants, including people who never signed up for 9 Hats. When you upload, connect, or process this content:

  • You confirm you have the legal right to do so under GDPR – either because participants have consented, because you have another lawful basis, or because you have informed them as required.
  • You are the controller of that personal data. We act as your processor for the purposes of running the Service.
  • You are responsible for responding to requests from meeting participants about their data. We will support you if you forward such a request.

If you don't have the right to upload someone's meeting data to a service like 9 Hats, don't connect that meeting. You can disconnect Granola or delete specific notes from your account at any time.

How we use your data and our legal bases

| Purpose | Legal basis | |---|---| | Create and manage your account | Contract (GDPR Art. 6(1)(b)) | | Run the core Service: meeting processing, suggestions, Discovery artifacts | Contract | | Send account, security, and service emails | Contract / Legitimate interest | | Process payments | Contract / Legal obligation | | Keep records required by Danish accounting law | Legal obligation | | Detect, prevent, and respond to abuse, fraud, and security incidents | Legitimate interest | | Improve the Service through aggregate, anonymised usage analysis | Legitimate interest | | Send marketing emails | Consent (you can withdraw any time) | | Comply with legal requests from courts or regulators | Legal obligation |

We do not sell personal data. We do not use it to target ads.

AI processing

The core of 9 Hats is processing your meeting content and Discovery inputs using a large language model.

What we send: Meeting content (titles, transcripts, notes), Discovery inputs, and surrounding context required for generation.

Who processes it: Anthropic, PBC (United States). We use Anthropic's Claude API on Anthropic's commercial terms.

Anthropic's commitments:

  • Anthropic does not train its models on data sent through its commercial API.
  • Inputs and outputs are retained by Anthropic only as long as needed to provide the service and detect abuse, subject to Anthropic's own commercial terms.
  • Anthropic's full data handling terms are at https://www.anthropic.com/legal/commercial-terms and https://privacy.anthropic.com.

Why we use a US provider: Claude is the model that gives 9 Hats its core value. Equivalent EU-hosted alternatives don't currently match the quality we need for meeting extraction. We transfer data to the US on the basis of the European Commission's Standard Contractual Clauses (SCCs), and we monitor adequacy developments under EU law.

Sub-processors

We use the following sub-processors to run 9 Hats:

| Provider | Purpose | Location | Transfer mechanism | |---|---|---|---| | Anthropic, PBC | LLM inference (Claude API) | United States | SCCs | | Convex, Inc. | Application backend and database | United States | SCCs | | Vercel, Inc. | Frontend hosting | United States | SCCs | | Resend, Inc. | Transactional email (magic link, notifications) | United States | SCCs | | Stripe Payments Europe, Ltd. / Stripe, Inc. | Payments and subscription billing | Ireland (EU) / United States | EU processing where possible; SCCs for US | | Google Ireland, Ltd. / Google LLC | Login (OAuth) | Ireland (EU) / United States | EU processing where possible; SCCs for US | | Cloudflare, Inc. | DNS, edge network, email routing, cookieless web analytics | United States (global edge) | SCCs | | PostHog, Inc. | Product analytics (authenticated users only) | Germany (EU) / United States | EU processing; SCCs for US entity |

We will update this list if we add or change sub-processors. Material changes will be reflected on this page.

Integrations you connect

You can connect 9 Hats to third-party services so we can read from or write to them on your behalf:

  • Granola – we read meeting notes you authorize.
  • Google Meet – we access conference records, meeting transcripts, and participant display names via the Google Meet API under the read-only meetings.space.readonly scope, only for meetings you choose to sync. Disconnecting stops access and revokes 9 Hats' authorization.
  • Slack – we receive the content of individual messages you explicitly choose to send via the "Send to 9 Hats" action, plus the channel name, workspace, and author display names needed to format the note. We do not read your Slack history and we do not monitor channels. When you send a message that is part of a thread, we retrieve that thread's replies so the note captures the whole conversation. Disconnecting revokes 9 Hats' access.
  • Linear, Jira, and other export targets – we write content you choose to export.

9 Hats' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

When you authorize an integration, that third-party service operates under its own privacy policy and terms. We pass data to or from it under your direction. We are not responsible for what those services do with your data after you transfer it there, except for our role in the transfer itself.

You can disconnect any integration at any time from Settings.

How long we keep your data

| Data | Retention | |---|---| | Account profile | While your account is active | | Meeting notes and derived suggestions | While active; deleted within 30 days of account closure | | Discovery artifacts | While active; deleted within 30 days of account closure | | Billing records (invoices, transactions) | 5 years from the end of the relevant accounting year (Danish Bookkeeping Act) | | Logs and security data | Up to 90 days | | Backups containing the above | Purged on the next backup rotation cycle, typically within 35 days |

When you delete your account, we delete your data on the schedule above. We cannot retrieve content from Anthropic, Granola, or other third parties on your behalf – you'll need to handle deletion there directly.

Your rights

If you are in the EEA or the UK, you have the following rights under GDPR / UK GDPR:

  • Access – receive a copy of the personal data we hold about you.
  • Rectification – correct inaccurate or incomplete data.
  • Erasure – request deletion of your data (subject to legal retention duties).
  • Restriction – restrict our processing in certain cases.
  • Portability – receive your data in a machine-readable format.
  • Objection – object to processing based on legitimate interest.
  • Withdraw consent – for processing based on consent, with no effect on past processing.
  • Lodge a complaint with a supervisory authority.

To exercise any of these rights, email hello@9hats.app. We respond within 30 days. We may ask you to verify your identity before we act.

If you believe we are processing your data unlawfully, you have the right to lodge a complaint with the data protection authority in your country of residence.

Security

We protect your data with:

  • TLS encryption for all data in transit
  • Encryption at rest for stored data
  • Role-based access controls within our team
  • Authentication via Google OAuth or magic link (no passwords for us to leak)
  • Logging and monitoring of access

No security is perfect. If we discover a personal data breach that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and notify affected users without undue delay where required by GDPR.

Cookies and similar technologies

9 Hats uses essential cookies to keep you logged in and to operate the Service. We do not use advertising cookies or third-party tracking cookies. 9 Hats uses cookieless, aggregate web analytics that set no cookies and store no per-visitor identifier. Our product analytics for signed-in users stores its identifier in your browser's local storage rather than in cookies, records no session replays, and includes no third-party advertising trackers. If we add analytics or marketing cookies in the future, we will update this policy and request your consent before activating them.

Children

9 Hats is not intended for users under 18. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact hello@9hats.app and we will delete it.

Changes to this policy

We may update this policy. The "Last updated" date at the top reflects the latest version. If we make material changes, we will notify active users by email or in-app notice.

Contact

For any privacy question or to exercise your rights:

hello@9hats.app

AS Labs ApS Hvedemarksvej 18 2605 Brøndby Denmark