Privacy Policy

Hey Action (the “App”) respects your privacy. This Privacy Policy explains how information is handled when you use the App.

Information Collection

Last updated: August 31, 2026.

The App does not require an account and does not collect names, email addresses, or other directly identifying information.

The App allows users to configure HTTP requests and trigger them manually from the App or through Apple Shortcuts, Siri, and Home Screen shortcuts.

All configurations (such as URLs, headers, and request bodies) are stored locally on the user’s device only.

The App uses Google Firebase Analytics to understand aggregate feature usage and improve the App. Analytics may collect an app-instance or device identifier, app and device information, and product interactions such as opening the editor or Shortcuts, saving or importing an action, running an action from the App or a shortcut, whether the run succeeded, the HTTP result status, a privacy-safe error category and code, broad response-time and response-size ranges, rating-prompt eligibility, and notification preference changes.

Network Requests

When you trigger an action, the App sends an HTTP request only to the endpoint you explicitly configure.

The App does not log, store, or transmit request or response data to any external servers operated by the developer.

Notifications

The App may display local notifications to show request results (such as status codes and timing).

These notifications are generated entirely on the device and are not sent to any external service.

Third-Party Services

Firebase Analytics processes the analytics data described above. The data is used only for analytics and is not used for advertising or cross-app tracking. Google may process this data under its privacy policy: https://policies.google.com/privacy

Data Security

The App never sends action names, pasted commands, request URLs or hosts, header keys or values, request bodies, response bodies, tokens, or API keys to analytics. Analytics may include the HTTP status code and privacy-safe diagnostics such as launch source, request method, failure stage, error domain and code, timeout flag, and broad timing or response-size ranges. Request configurations remain stored locally on the device.

Children’s Privacy