Askheap · last updated 16 July 2026
Askheap is software published by Kyle Newton. Contact: info@kylenewton.co.uk.
Everything is on your own computer. There is no cloud copy.
| What | Where it lives |
|---|---|
| Your task board, and how far each source has been read | A SQLite file in your Mac's application-data folder |
| Access tokens for services you connect, and your Anthropic API key | The macOS Keychain, protected by your login password |
| Your settings (e.g. which WhatsApp chats you opted in) | The same local database |
Deleting the app and its application-data folder deletes everything. There is nothing to request from us, because we hold nothing.
Nothing is connected until you explicitly connect it, and each source can be connected or disconnected on its own.
| Source | What is read |
|---|---|
| Slack | Messages in the channels your account can already see, via Slack's official API after you authorise it. |
| Gmail | Metadata and previews only — the sender, the subject line, and the short
snippet Gmail itself generates. Askheap does not download or read the
body of your emails, and never sends, drafts, deletes, or modifies mail. Access is
read-only (gmail.readonly). |
| Messages are read from the WhatsApp Desktop app's own local database already on your Mac. Askheap does not log in to WhatsApp, does not connect to WhatsApp's servers, and cannot send messages. Only the specific chats you tick are read — if you tick none, nothing is read. |
This is the one place your message content leaves your machine, so it deserves plain language.
To turn messages into tasks, Askheap sends recent message text to Anthropic's API
(api.anthropic.com) using an API key you supply from your own Anthropic
account. That request contains the message text, the channel or chat name, the sender's
display name, and the titles of tasks already on your board.
Because the request is made with your key, it is governed by your agreement with Anthropic, not ours. We are not a party to it and we never see it. Anthropic's commercial terms state that API inputs are not used to train their models; their current policies apply and are worth reading.
Askheap has no server in this path. There is no intermediary, no proxy, and no copy kept anywhere by us.
Askheap reads conversations, so it necessarily processes information about the people who message you — their names and what they wrote. That data stays on your Mac and goes to Anthropic under your key, exactly as described above.
If you use Askheap for work, you are the one deciding to process your colleagues' and contacts' information this way, and you are responsible for making sure that is permitted by your employer's policies and by law in your country. The WhatsApp chat picker exists precisely so you can exclude personal or sensitive conversations — we recommend using it.
Askheap contains no analytics, no telemetry, no crash reporting, no advertising identifiers, and no automatic update service that reports back. It makes no network requests other than to the services listed on this page. There are no user accounts, so there is nothing for us to hold, sell, or lose in a breach.
Askheap's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: Google user data is used only to show you your own action items inside the app; it is never sold, never used for advertising, and never used to train any general-purpose model. Only the sender, subject and snippet are accessed, and they are stored solely on your own device.
Askheap is a workplace tool and is not directed at children under 13.
Under UK and EU data protection law you have rights of access, correction and erasure over your personal data. In Askheap's case these are satisfied directly: the data is on your own computer, under your own control, and deleting the app's data folder erases it completely. We hold no copy to disclose or delete. To revoke Askheap's access to a connected service, disconnect it in the app or remove the app from that service's own account settings (for example, Google's Security page or your Slack workspace's app directory).
If this policy changes materially — in particular if any data ever begins flowing to a server we operate — the change will be published here with an updated date, and disclosed in the app's release notes.