Legal
Privacy Policy
Last updated October 3, 2026 · Terms of Service
Held is a scheduling assistant for people who book meetings with outside clients and prospects. It reads your calendar, flags meetings likely to fall through, gives you a booking link at held.page, and helps you follow up. Held is run by YakShaving Inc., a Washington corporation at 1605 Boylston Ave, Seattle, WA 98122 (“Held,” “we,” “us”). This policy covers meetheld.app, held.page, the Held Mac app, and the emails Held sends.
The short version: we use your data to run Held for you. We don't sell it, we don't show ads, and we don't use it to train AI models.
What we collect
- Your account. When you sign in with Google or Microsoft we get your name, email address and profile photo.
- Your calendar. Events in your connected calendars: titles, times, descriptions, meeting links, and the names, email addresses and responses of attendees. Held focuses on meetings with people outside your company, but it reads your calendar to know when you're busy.
- Zoom, if you connect it. Details of your Zoom meetings and who joined them, including participants' names, email addresses and join and leave times. This is how Held knows whether a prospect showed up.
- Granola, if you add a key. Your meeting notes and summaries, with their attendees, so follow-up drafts remember what was said.
- People who book with you. When someone books through your held.page link we collect their name, email address, time zone and the time they chose.
- Email you paste in. If you use Paste email, we process that text to understand it. We keep a short summary linked to the meeting, not the email itself.
- Professional details about attendees. To show who you're meeting, Held may add business information such as job title, company, company size, city and LinkedIn profile link from professional data sources.
- Payments. Stripe processes payments. We store your Stripe customer ID and your plan, never your card number.
- Your settings. Your held.page name, page colors, tagline and photo, ignored meetings and similar preferences.
- Waitlist. If you joined the waitlist, your email address.
Held uses cookies to keep you signed in, to finish sign-in and connection steps, and for the analytics described below. We don't use advertising cookies.
How we use it
- To run Held for you: syncing your calendar, scoring meeting risk, showing who attended, building your booking page, creating calendar invites and Zoom meetings for bookings, and drafting follow-ups.
- To send booking emails: confirmations, reschedules and cancellations to you and your guests, and, if you turn it on, a day-before “does this still work?” email to the outside guests on meetings you organize. These come from bookings@held.page with replies going to you.
- To bill paid plans and keep your premium name active.
- To keep Held secure, fix problems, and answer you when you write to us.
We don't sell personal information, share it for advertising, or use it to build profiles for anyone else.
Analytics
We use Google Analytics to see how people find and use Held: which pages they visit, which buttons they click, and whether they sign up, book or upgrade. On our marketing pages (held.page, sign-in, download and these legal pages) we also use Microsoft Clarity, which records clicks, scrolling and mouse movement so we can see where the page confuses people. Both set cookies and receive your IP address and device details.
We never send them your calendar, meeting details, notes, or anything a guest types. Clarity doesn't run inside the app or on booking pages, and secret links such as reschedule links are removed before a page is reported. If your browser sends a Global Privacy Control or Do Not Track signal, Held doesn't load either tool. You can also use Google's opt-out add-on.
Google user data
Held asks Google for permission to view and edit events on your calendars (calendar.events), plus your basic profile. It uses this to read your meetings and to create, move and cancel the events booked through your held.page link. It does not read your Gmail.
Held's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We use Google data only to provide and improve the features you see in Held.
- We don't sell it, use it for advertising, or use it to determine creditworthiness.
- We don't use it to train or improve general AI or machine learning models, ours or anyone else's.
- People at Held don't read it unless you ask us to, it's needed for security or to comply with the law, or it has been aggregated and anonymized.
Microsoft and Zoom data gets the same treatment.
AI features
When you ask Held to draft a follow-up or read a pasted email, it sends the relevant meeting details, attendee information and notes to Anthropic's Claude model to write the result. Anthropic processes this under commercial terms that don't allow it to train its models on the data. Held only does this when you use those features. AI output can be wrong, so read drafts before you send them.
Who we share it with
We share data only with companies that help run Held, under contracts that limit what they can do with it, and with the services you choose to connect.
- Vercel hosts the app.
- Neon hosts the database.
- Resend sends Held's emails.
- Stripe processes payments.
- Anthropic powers drafting, as described above.
- Google Analytics and Microsoft Clarity measure how the site is used, as described above.
- Google, Microsoft, Zoom and Granola receive the requests Held makes on your behalf, such as creating a calendar event or a Zoom meeting.
We may also disclose information if the law requires it, to protect people's safety, or as part of a merger or sale of the business, in which case this policy keeps applying to your data.
People who aren't Held users
If you booked time with a Held user or attended one of their meetings, Held processes your details on that user's behalf so they can schedule and follow up with you. You can ask us to delete your information at privacy@meetheld.app. The Held user may still have their own copy, such as the calendar invite.
Security
Data is encrypted in transit. Sign-in tokens and API keys for your connected accounts are encrypted again in our database with AES-256-GCM, and the full values are never shown back in the app. No system is perfectly secure, but we work to protect your data and will tell you promptly if a breach affects it.
Keeping and deleting your data
- We keep your data while your account is open.
- You can disconnect any calendar, Zoom or Granola account in Connections at any time. You can also remove Held's access to Google from your Google account permissions.
- To delete your account and its data, use Settings › Delete account, or email privacy@meetheld.app from the address you sign in with. Deletion in Settings is immediate; email requests are handled within 30 days. Deleted data leaves our backups within a further 30 days.
- We keep billing records as long as tax and accounting law requires.
Your rights
Depending on where you live, you may have the right to see, correct, export or delete your personal information, or to object to how we use it. Email us and we'll respond within 30 days. We won't treat you differently for using these rights.
Children
Held is a business tool and isn't meant for anyone under 16. We don't knowingly collect information from children.
Changes
If we change this policy we'll update the date at the top. If a change materially affects how we use your data, we'll email you before it takes effect.
Questions? Email privacy@meetheld.app or write to YakShaving Inc., c/o Foundations, 1605 Boylston Ave, Seattle, WA 98122.