Skip to content

Privacy Policy

Effective date: July 19, 2026

HaveTheWhy ("we", "us") is an AI-powered user research platform. Customers describe a research goal, we create an AI interviewer, and the people they invite ("respondents") talk to that interviewer through web chat, Telegram, or WhatsApp. The platform turns those conversations into transcripts and a Snapshot — our analysis of what respondents said — for the customer.

This policy explains what personal data we handle, why, and what your choices are. It applies to:

  • havethewhy.com — our public website;
  • app.havethewhy.com — the HaveTheWhy dashboard;
  • interview conversations run through HaveTheWhy links and channels (web chat, Telegram, and WhatsApp where offered).

1. Two kinds of people, two roles

We handle data about two groups, and our role is different for each:

  • Customers (account holders). If you create a HaveTheWhy account, we decide how your account data is handled, and this policy describes that directly.
  • Respondents. If you talk to an AI interviewer, you were invited by one of our customers. We process your interview data on that customer's behalf — in GDPR terms, the customer is the controller of the interview data and we are their processor. For questions about the research itself — why you were invited, what the answers are used for, or to have your responses removed — contact the customer who sent you the invitation. For questions about how the platform itself works, contact us at supporthavethewhy [dot] com.

2. Information we collect

If you have a HaveTheWhy account

  • Account details. When you sign up or log in — with email and password, Google, or a Microsoft account — our identity provider passes us your email address and name. Your email identifies your account across the platform.
  • Workspace content. Research goals, AI interviewer settings, and anything you add to your knowledge base: uploaded files, pasted text, and links (for links, we retrieve the page text or video transcript — using a content-extraction service — so the interviewer can use it).
  • Usage and billing records. Your credit balance and a record of credit usage per conversation. We do not process payments or store payment card details — credits are managed by our team.
  • Communications. Emails you send us for support or feedback.

If you talk to an AI interviewer

  • Conversation content. The messages you exchange with the interviewer. Voice messages are converted to text; we keep the transcript, not the audio — audio files are deleted immediately after transcription.
  • Channel identifiers. These depend on how you connect: your phone number and profile name on WhatsApp; your Telegram ID, name, and username on Telegram; or a random anonymous ID on web chat. Web chat does not require an account or any real-world identity.
  • Information you choose to share. If the interviewer asks for something like your email address and you provide it, it is stored with your responses.
  • Snapshot data. Summaries, tags, and profile notes that our AI generates from the conversation for the customer's Snapshot, plus your language preference.

Technical data (both roles). Like most online services, our servers and infrastructure providers keep short-lived technical logs — IP address, browser and device type, timestamps — used only for security, debugging, and abuse prevention.

3. Google user data

If you sign in with Google, we receive your basic Google profile: your name, your email address, and your profile picture, through our identity provider.

  • We use your name and email address solely to create your account, sign you in, and identify you inside the app. We do not currently use the profile picture.
  • We do not use Google user data for advertising, do not sell it, and do not transfer it to anyone except as needed to operate sign-in, comply with applicable law, as part of a business transfer as described in Section 6 (with notice to you), or with your explicit consent.
  • We do not use Google user data to train AI models.

HaveTheWhy's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Signing in with a Microsoft account works the same way: we receive your name and email address and use them only for authentication and account identification.

4. How we use information

  • To run the service: conduct interviews, generate transcripts and Snapshot analyses, and deliver them to the customer's workspace.
  • To operate accounts: authentication, credit accounting, and support.
  • To keep the platform safe: preventing abuse, debugging, and securing accounts and data.
  • To meet legal obligations where they apply to us.

Where laws such as the GDPR apply, we rely on our contract with the customer (and their instructions, for respondent data), our legitimate interest in running and protecting the platform, and consent where consent is required.

We do not use personal data for advertising, and we do not sell it — to anyone, ever.

5. AI processing

Interviews are conducted and analyzed by large language models. To do this, conversation content is processed by third-party AI providers acting as our sub-processors — currently OpenAI, whose models generate interviewer replies, transcribe voice messages, and produce analysis, and LangChain (LangSmith), which we use for prompt management and AI observability. We use these providers through their API services, under terms where data submitted via the API is not used to train their models.

Our own commitment is the same: we do not use your content or your respondents' data to train AI models. Your research stays your research.

6. When we share information

"Sharing" here means the customer whose research it is, the vendors that run the platform for us, and the messaging platform a respondent chooses to talk through — never data brokers, advertisers, or buyers.

  • With the customer who invited you (respondents): your conversation, transcript, and the Snapshot built from it appear in that customer's workspace. That is the purpose of the interview.
  • With service providers that help us run the platform, under contracts that limit them to providing the service: our identity provider (Auth0), AI providers (OpenAI and LangChain's LangSmith — see Section 5), a content-extraction service we use to fetch text from links you add to your knowledge base, and cloud infrastructure — hosting, database, file storage, and workflow tooling. Our website and the app dashboard also use privacy-focused, EU-hosted analytics (PostHog — see Section 7).
  • Through the messaging platform you choose (respondents): if you talk to the interviewer on WhatsApp or Telegram, your messages pass through that platform's systems — Meta's WhatsApp Cloud API or Telegram's Bot API — to reach us, and your use of those platforms is also governed by their own terms and privacy policies (Meta's for WhatsApp, Telegram's for Telegram).
  • When the law requires it: we may disclose data to comply with a valid legal obligation, court order, or enforceable government request, and to protect the rights and safety of our users or the public.
  • In a business transfer: if HaveTheWhy is ever involved in a merger, acquisition, or sale of assets, data would transfer under the same protections, and we would notify affected account holders.

We do not sell personal data, share it with data brokers, or share it for advertising.

7. Cookies and similar technologies

We keep this minimal. havethewhy.com uses cookieless, privacy-focused analytics (PostHog, hosted in the EU) to understand how visitors use the site — pages viewed, where visitors come from, clicks and scrolling, and anonymized session replays with any typed text masked. On the public website it sets no cookies, stores nothing on your device, and does not identify you or track you across other sites or across sessions.

In the app (app.havethewhy.com), we use the same EU-hosted analytics to understand how account holders use the product — pages visited and key actions such as creating an AI interviewer, sharing an invitation link, or generating a Snapshot. In the app this is tied to your account (your email) and uses browser storage. It never records session replays, the content of what you type, or anything a respondent does — interview conversations and the respondent web chat are not tracked at all.

There are no advertising trackers anywhere. The app also uses cookies and browser storage for functional purposes: keeping you signed in, remembering interface preferences, and holding the anonymous web chat session ID (which lives only for your browser tab's session). Our pages load fonts from Google Fonts, which means your browser requests those font files from Google's servers.

8. How long we keep data

  • Account and workspace data is kept while your account is active. When an account is closed, we delete its workspace and interview data promptly after closure, except records we must keep for legal or accounting reasons.
  • Interview data is kept until the customer deletes it. Customers can delete individual respondents from the dashboard, which removes the conversation, the respondent profile, the full message history, and the underlying technical records (raw message-delivery logs).
  • Support access logs (records of our staff accessing a customer account for support) are automatically deleted after 90 days.
  • Custom retention arrangements: if your organization needs a specific retention schedule, contact us and we will discuss what we can support.

To close your account and have your data deleted, email supporthavethewhy [dot] com and we will complete the deletion.

9. Security

We protect data with encryption in transit (HTTPS/TLS), access controls that limit who can see what, and encrypted storage of channel credentials such as bot tokens. When our support staff access a customer account to help with an issue, that access is logged and auditable. No system is perfectly secure, but if we ever learn of a breach affecting your personal data, we will notify affected users and authorities as the law requires.

10. International transfers

Our service providers process data in the United States, the European Union, and the countries where the messaging channel you choose operates. When personal data covered by European data-protection law is transferred internationally, we rely on appropriate safeguards, such as the standard contractual clauses offered by our sub-processors.

11. Your rights

Depending on where you live, you may have the right to access, correct, delete, export, or object to or restrict the processing of your personal data. Here is how to exercise them:

  • Customers: much of this is self-serve — you can edit your workspace, export conversations and respondent data as CSV or JSON, and delete respondents directly from the dashboard. For anything else, including account deletion, email supporthavethewhy [dot] com.
  • Respondents: the fastest route for requests about your interview data is the customer who invited you — they control the research and can delete your data from their workspace. You can also contact us directly and we will help, coordinating with the customer where needed. You can stop an interview at any time simply by not replying, and you can ask not to receive follow-up messages.

We do not discriminate against anyone for exercising their privacy rights, and we respond within the timeframes required by applicable law.

12. Children

HaveTheWhy is not directed at children under 16, and we do not knowingly collect their personal data. Customers must not direct interviews at children. If you believe a child has provided personal data through the platform, email us and we will delete it.

13. Changes to this policy

When we update this policy, we will post the new version here with a new effective date. If a change is material, we will give account holders reasonable advance notice by email or in the app.

14. Contact us

Questions, requests, or concerns about privacy: supporthavethewhy [dot] com. We read everything and reply personally — HaveTheWhy is a small team, and that includes privacy.