Privacy Policy
What Hestana does with your data, why, where it lives, who else touches it, and how to get it back or have it erased.
Last updated: 2026-09-30
Who is responsible
Hestana is built and operated by Javier Pérez, from Switzerland. For the account data described below, that is the controller. You can reach a human at [email protected] — there is no ticket queue in front of it.
Hestana was called Coalia until 30 September 2026. Only the name changed: the service, the operator and the commitments in this document are the same.
This policy covers coalia.io (the marketing site), app.coalia.io (the product), admin.coalia.io (the staff control plane) and the MCP endpoint your agents connect to.
Two different roles, and the difference matters
Hestana holds two kinds of data and treats them differently.
- Account data — your email, your name, your sessions, your organisation. Hestana decides what happens to it, so Hestana is the controller. This policy governs it.
- Workspace content — the objects, files, tasks, notes and events you and your agents write into your spaces. That is yours. Hestana stores and processes it on your instructions and does not decide what it is used for. For that content Hestana is a processor, and a customer who needs one can request a data processing agreement.
What Hestana collects
Nothing is collected that the product does not need to work.
- Sign-in identity: your email address, your display name, whether the address is verified, and — if you sign in with Google — a link to your Google profile picture and a copy of it, used as your avatar.
- Sessions: a session token, its expiry, and the IP address and browser user-agent that created it. These exist so you can be shown where you are signed in and so a stolen session can be told apart from you.
- Organisation and membership: which organisation you belong to, your role in it, which spaces you are a member of, and the field-level permissions others have granted you.
- Workspace content: whatever you or your agents write into a space — objects, documents, file attachments, tasks, notes, messages and the events they generate.
- Agent credentials: API keys and OAuth tokens are stored as SHA-256 hashes and never in clear text. Once shown, a secret cannot be retrieved from Hestana — not by you, and not by us.
- Audit and usage records: who did what, when, and how many writes an organisation has spent against its plan.
- Error reports: when something breaks, a stack trace and the route it happened on.
Signing in with Google
When you sign in with Google, Hestana asks Google for exactly three scopes — openid, email, profile — and for nothing else. Those scopes return your Google account identifier, your email address, your name and your profile picture.
That is the entire purpose: to create your Hestana account, to recognise you when you come back, to match you to invitations sent to the same verified address, and to show your picture as described below. Signing in does not request access to Gmail, Drive, Calendar, Contacts or any other Google service. Calendar access is asked for only if you choose to connect Google Calendar, separately, as described in the next section.
Alongside your account Hestana stores the provider name, your account identifier at that provider, the granted scopes and the OAuth tokens Google issues. The tokens stay on the server and are never exposed to the browser or to an agent.
If Hestana has no picture of you, it copies your Google profile picture once, re-encoded as a small image without any metadata, and shows it as your avatar to you and to the people you share an organisation or a space with. It is never shown to agents or outside Hestana. You can remove it from your profile at any time; once removed, Hestana does not copy it again. Removing it deletes the copy; the link to the picture that Google sends at each sign-in stays with the sign-in record described above, and goes with it on erasure.
Hestana does not sell this data, does not use it for advertising, and does not use it to train any model. Revoking Hestana in your Google account settings stops any further exchange; to remove what is already stored, ask for erasure as described below.
Connecting Google Calendar and other calendar apps
Connecting Google Calendar is optional and separate from signing in. When you connect it, Hestana asks Google for https://www.googleapis.com/auth/calendar.app.created, which lets Hestana create calendars of its own in your Google account — one per space you choose, named «Hestana · <space>» — and read and change only the events in those calendars. Hestana cannot see or change any other calendar with this permission.
If you also switch on «Show my other Google calendars», Hestana asks for https://www.googleapis.com/auth/calendar.calendarlist.readonly, https://www.googleapis.com/auth/calendar.events.readonly so it can list your other calendars and show the events of the ones you tick, read-only and only to you. Hestana never writes to those calendars.
What travels: the title, time and place of the tasks and events of the spaces you choose to sync, limited to what you yourself can see in Hestana. Changes you make in the «Hestana · <space>» calendars come back to Hestana. Other members of a space you sync see a notice that you connected it, without your Google account details.
What Hestana stores: your Google account identifier and email, the granted scopes, and the OAuth tokens Google issues, encrypted with a key held only on the server. Disconnecting removes the «Hestana · <space>» calendars from your Google account, revokes the grant where no other connection of yours still uses it, destroys the stored tokens, and clears the account details. You can also revoke Hestana at any time in your Google account settings.
Hestana's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. It is not sold, not used for advertising, not used to train any model, and not read by people at Hestana except when you ask for support or the law requires it.
Other calendar apps: you can publish your tasks and events to Apple Calendar, Outlook or any app through a private calendar link. Anyone who has that link can read what it contains, so treat it like a password; resetting it stops the old one immediately. You can also show another calendar in Hestana by pasting its link: Hestana fetches it from the address you gave, stores its events, and shows them only to you.
Why Hestana processes it, and on what legal basis
Under the GDPR and the Swiss Federal Act on Data Protection, each purpose below has a basis.
- To provide the service you asked for — accounts, spaces, agents, sharing and governance. Basis: performance of a contract.
- To keep the service safe: rate limits, abuse prevention, the audit trail, and error monitoring. Basis: legitimate interests, and Hestana has weighed them against the fact that a shared-state product without an audit trail is not trustworthy.
- To measure aggregate traffic on the public marketing site. Basis: legitimate interests, with cookieless analytics that build no profile.
- To meet legal obligations, such as responding to a lawful request or keeping accounting records. Basis: legal obligation.
Where the data lives
The database and the application run on a dedicated server in Frankfurt, Germany, inside the EU. File attachments and avatars are stored as objects in Cloudflare R2.
Every organisation carries a residency region, and Business customers can have their instance and their data hosted where their own rules require, including self-hosting on infrastructure Hestana never touches.
Who else touches it
Hestana uses a short list of providers, each for one job. There are no data brokers on it, and nothing is sold or rented to anyone.
- Resend — delivers sign-in links and the mail an agent sends from its mailbox. Sees the recipient address and the message.
- Cloudflare — stores file attachments in R2, fronts the public site, and receives the mail sent to an agent’s mailbox before Hestana stores it. Sees the bytes you upload, the messages addressed to agents, and ordinary request metadata.
- The hosting provider of the Frankfurt server — operates the machine the database runs on.
- Sentry — receives error reports. It is configured not to attach cookies, request headers, request bodies or IP addresses, so a crash report says what broke and not who was using it.
- Umami — counts visits to the public marketing site only. It sets no cookies, records no identifiers, and is never loaded inside the product.
- Google — only if you choose to sign in with Google, and only for the three scopes listed above.
- OpenAI — runs the AI model behind the instruction compiler and Hestana Agents, reached only through Hestana’s own gateway. Sees the text a task needs, as described below. Under OpenAI’s API terms it is not used to train their models.
- TypeSafe (TypeSafe AI, Inc., United States) — runs Jev, the classifier that reviews mail that arrives at an agent’s mailbox before the agent sees it, as described below. Sees the sender, the subject and the text of that mail, including its HTML part turned into plain text.
When Hestana sends content to an AI model
Most of Hestana never involves a model: storing, sharing, searching and permissions run without one. Folding a long note thread into a summary uses a deterministic digest, not a model.
Three features do use one. Two of them only when you use them. The instruction compiler: when you ask Hestana to write or improve an agent’s instructions, it sends the model what you typed and what it needs to read to do that — which can include documents you can read in your spaces. It proposes; nothing changes until you apply it. Hestana Agents: an agent you launch works with what you granted it, and when it acts the model sees the content that task needs, within those grants.
For these two the request goes through Hestana’s own gateway to OpenAI, billed to Hestana, with a spending limit per account. Hestana does not use your content to train models, and OpenAI does not either: under its API terms, data sent through the API is not used for training unless the customer opts in, and Hestana has not. OpenAI acts as Hestana’s processor under its Data Processing Addendum; for customers in the EEA and Switzerland the contracting entity is OpenAI Ireland Ltd. OpenAI may keep requests and responses for up to 30 days to detect abuse, then deletes them. Where OpenAI processes that content outside the EEA or Switzerland, including in the United States, the transfer relies on the European Commission’s standard contractual clauses included in OpenAI’s Data Processing Addendum. An agent you connect yourself (Claude, ChatGPT, your own code) uses its own provider; what it sends is between you and that provider.
The third is the review of incoming agent mail. When a message arrives at an agent’s mailbox — including one the owner writes — the sender, the subject and the text of the message, its HTML part turned into plain text, but not its attachments, are sent to TypeSafe’s Jev model before the agent sees it. Jev only classifies the message as clean, spam or malicious; it writes nothing, and a message it flags is held in quarantine for the owner instead of reaching the agent. Two kinds of mail skip the review: automatic replies, and mail from a sender the owner marked as trusted whose domain passes DMARC.
TypeSafe acts as Hestana’s processor under its Data Processing Agreement dated 24 April 2026. It processes that text in the United States, and the transfer relies on the European Commission’s standard contractual clauses included in that agreement. TypeSafe states that it does not use the content it receives to train its models. Its agreement does not set a fixed retention period: it keeps the data for as long as necessary for the purpose it was sent for, and Hestana has not contracted zero retention.
Agent mailboxes
Hestana Mail gives mailboxes to agents, not to people: an agent’s owner can switch on an address for it, and every message it holds belongs to that agent and is supervised by its owner. Hestana no longer offers mailboxes to people.
Every message an agent sends ends with a fixed line that says it was written by AI and on whose behalf, which the agent cannot remove or edit: «Este mensaje lo ha escrito un agente de IA que actúa en nombre de {owner}, a través de Hestana.», with the owner’s name in place of {owner}, or «su dueño» when the owner has not given one.
When a mailbox is switched off it is archived: mail to its address is refused, and the messages and attachments it held are kept for 30 days — so switching it back on within that time brings them back — and then deleted. The address itself is never given to anyone else, not even after that deletion.
An attachment that arrived in more than one mailbox is stored once. Deleting one mailbox’s mail deletes the file when no other mailbox still refers to it; until then it stays, for the mailboxes that still hold it.
Mail that reaches Hestana is first kept as a raw copy while it is delivered to the mailbox; that copy is deleted as soon as delivery succeeds, and a copy whose delivery failed is deleted after 30 days at the latest.
How long it is kept
Account data is kept while your account exists. Sessions expire on their own and are removed after expiry.
Workspace content is kept while your organisation keeps it. On the Free plan, version history and audit entries older than a rolling 7-day window stop being shown; the data is filtered from view, not deleted, and the whole history reappears if the organisation moves to a paid plan.
No organisation is closed, frozen or switched off for being unused: one you leave alone for a month, or for a year, keeps its content and its settings, and how long it has been quiet changes nothing. What does expire is credentials — your sessions, and the OAuth tokens an agent connects with — because a credential nobody uses is a security risk rather than a tidiness problem. Signing in again, or reconnecting the agent, restores access to everything that was always still there.
The audit trail is append-only by design: it is what makes cross-owner sharing accountable, so it is not edited after the fact.
Deletion, and what "deleted" honestly means here
Hestana keeps an append-only, content-hashed history, which is exactly what makes it auditable — and it is also why "delete a row" is not the whole answer. Erasure works in two ways, and they are not the same thing.
- Workspace content is erased one object at a time: the version rows survive, so the history and the audit trail stay consistent, and the content stops being served on every read path — absent when a space is enumerated, a marked gap when a person reads a sequence. Deleting a task, a note or an issue erases its object that way, and the erasure is written to the audit trail with the actor who did it.
- File attachments are deleted outright: every version of the object is removed from storage, the descriptor is tombstoned and redacted everywhere it would have appeared, and your storage quota is credited back.
- Mail attachments are the one exception to «outright»: the same file received in several agent mailboxes is stored once, so deleted means deleted once no mailbox refers to it any more, as described under «Agent mailboxes».
Your rights
You can ask for a copy of your data, correct it, have it erased, restrict or object to how it is processed, and receive it in a portable format. Write to [email protected]; you will get an answer within 30 days. If you are in the EU or in Switzerland and you are not satisfied with that answer, you can complain to your national data protection authority.
Hestana makes no automated decisions with legal or similarly significant effects about you.
Cookies
Hestana sets a session cookie so you stay signed in across app.coalia.io and admin.coalia.io, and stores your light/dark preference. That is all. There are no advertising cookies, no third-party trackers inside the product, and the marketing analytics are cookieless — which is why you are not being asked to dismiss a consent banner.
Children
Hestana is a tool for building software and is not directed at children. Do not create an account if you are under 16.
Changes, and how you will know
When this policy changes, the date at the top changes with it. If a change materially affects how your data is handled, account holders are notified by email before it takes effect.
Contact
Questions, requests, or a data processing agreement for your company: [email protected].