Legal
Privacy Policy
Overview
This policy explains what personal data we handle on heysec.com and in our products, Prompt Firewall, heySec Home and Spy Check: why, for how long, who else is involved, and the rights you have under the GDPR.
heySec is run by Kempu OÜ (registry code 14643339), a company registered in Estonia, which is responsible for the data described here unless a section says otherwise. Our supervisory authority is the Estonian Data Protection Inspectorate. If a signed agreement or Data Processing Agreement (DPA) between us and your organisation says something different, that agreement takes precedence.
Our website
Visiting heysec.com
Cloudflare delivers our website and protects it from attacks, and NetiServer hosts it. Both receive what every visit sends, such as your IP address, your browser and the page you ask for, and keep it in their logs.
We count visits with Plausible, a cookieless analytics service made in the EU. The counts pass through our own server, Plausible does not store IP addresses, and we see only totals: page views, referring sites, how far pages are read and how many forms were sent, never what was typed into them. Fonts and images come from our own server, and links to social networks load nothing until you click them.
Contact form
A message sent from our contact page is emailed to our team with your name, email address and company, if you give them. The website keeps no copy; the email stays in our mailbox for as long as we need it to deal with your request.
Waitlist
When you join a waitlist we store your name, email address, company if you give it, which product you chose, that you accepted this policy, whether you want our news, the time, and your IP address and browser details so we can spot fake sign-ups. Entries go to a separate database the website can add to but not read. We use them to invite you when places open, and to send you news only if you asked for it.
Spam protection
Our forms use no third-party CAPTCHA. Your browser solves a small puzzle before a form is sent, and our server keeps a count of recent submissions for each network address, stored as a hash rather than the address itself, which expires after 10 minutes.
Your account
Prompt Firewall and heySec Home share one account and one portal, my.heysec.com, and accounts are by invitation. We store your name, email address and timezone, your password only as a hash that cannot be reversed, the households or organisations you belong to with your role in each, and a billing email if you give one. For Prompt Firewall we also keep your plan, your usage and your API keys, only as one-way hashes.
You sign in with your password and a second step, a passkey or an authenticator app; authenticator secrets and recovery codes are stored encrypted. While you are signed in we keep your session with its IP address and browser details. We remember the browsers you have used, so we can warn you about a sign-in from a new one, and a security log records sign-ins and changes with the IP address they came from. Invitations store the invited person’s email address and expire after seven days.
Prompt Firewall
Prompt Firewall checks the content your AI is about to read for hidden attacks. This section covers our cloud service. When you run Prompt Firewall on your own servers or on disconnected devices, it sends nothing to us and every log stays on your systems; if we run it for you, our agreement with you sets out how data is handled.
We don’t send your content to AI providers. Prompt Firewall does not forward your content to OpenAI, Anthropic, Google or anyone else. It is checked only by our own systems in the EU. You call your own AI model yourself, and we never see its responses.
Content you send
For each request we receive the text or files you send (text is also read from images), the network address and user agent of the server that called us, a request ID, a timestamp and the result of the check. If you send us feedback about a result, it is stored encrypted. For personal data inside that content, your organisation is the controller and we process it on its behalf.
How we protect it
Before a request is saved, an automated step finds personal data and replaces each item with a neutral placeholder that cannot be traced back to it: names, postal and email addresses, phone numbers, ID and payment numbers, and sensitive data such as health or biometric information. When it is not sure, it removes the data anyway. The original content waits only in an encrypted processing buffer, which deletes it automatically; only the redacted version is kept.
That redacted log is your request history and usage in the portal, a record for you and your auditors of what was checked and what we found, and material for improving our threat detection. It does not identify anyone, and we never use it to train general-purpose AI models.
heySec Home
heySec Home, in private testing, turns phones, tablets and computers into sensors for your home. They recognise movement, people and sounds on the device itself and stream nothing to us. This is what reaches our servers:
- Your homes: name, timezone, address and map position, the areas and Wi-Fi networks that count as being at home, and floor plans. A room scan sends only outlines, doors, windows and furniture positions in metres, never a camera image or 3D model.
- Devices: name, model, operating system and app version, battery, when each last checked in and what it can sense. HomeKit and Home Assistant bridges also send their accessories’ names, rooms and readings.
- Events and alarms: what was noticed, such as a person or glass breaking, on which device and when, the alarms raised and who dealt with them.
- Photos: a still photo when there is movement or a person while the house is armed, or when an owner or admin asks for one.
- Video and sound around an alarm: while the house is armed, an alarm makes every watching camera send the 20 seconds of video around it, without sound, and a sound that sets off an alert makes every listening microphone send the 20 seconds of sound. Until then the last minute is held only in the device’s memory; no clip is made while the house is disarmed, and one cancelled during the entry delay is deleted on the device.
- Home or away: if you turn it on, your phone works out by itself whether you are home, from the home’s area, its Wi-Fi or a Bluetooth device you pick, and sends only “in” or “out”, what told it so, and the time. For this we store the name and address of that Bluetooth device.
- Alerts: your phone’s push token, so Apple or Google can deliver them.
Everyone invited to a home, viewers included, sees its alarms, photos, clips and floor plan, and who is home or away. Our support tools show accounts and devices, not photos or clips. If your sensors can see or hear other people, such as guests, a babysitter or the street, tell them, and follow the local rules for home cameras.
Spy Check
Spy Check runs only on your Mac, and nothing it reads or finds is sent to us: no phone data, no results, no analytics and no crash reports. The one connection it makes is to download the latest list of spyware traces from the MVT project’s public sources on GitHub, which, like any download, sees your IP address.
The copy of your phone made for a check stays on your Mac and is deleted when the check finishes or you cancel it. If a check stops partway, the encrypted backup is kept so you can carry on, until you continue, give up or delete it. The findings stay until you delete them. Your backup password is passed to the checking tools and never saved.
Why we use it
- To provide what you signed up for: your account, Prompt Firewall checks, heySec Home’s monitoring and alerts, and support. Legal basis: our contract with you (GDPR Art. 6(1)(b)).
- To answer your messages and run the waitlists, because you asked us to (Art. 6(1)(b)).
- To keep our services and website secure and working: logs, spam and abuse protection, sign-in warnings and troubleshooting. Legal basis: our legitimate interest in security (Art. 6(1)(f)).
- To understand how the website is used, from cookieless totals, and to improve our threat detection from redacted Prompt Firewall logs. Legal basis: our legitimate interests (Art. 6(1)(f)); you can object.
- To send you news only if you asked for it (consent, Art. 6(1)(a)), which you can withdraw at any time.
- To keep accounting records when we bill you (legal obligation, Art. 6(1)(c)).
We do not sell personal data, use it for advertising or use it to train general-purpose AI models.
Storage & retention
Prompt Firewall and heySec Home run on our servers in Helsinki, Finland, and the website in Estonia. Data leaves the EU only through the providers in the USA listed under Sharing.
- heySec Home events, photos, video and sound are deleted after 30 days, or at once when you delete the home. Alarm history, notifications, the security log and past invitations are kept while your account exists.
- Content sent to Prompt Firewall is deleted from the processing buffer within 14 days, and cached results within 72 hours. The redacted log no longer identifies anyone, so we keep it; we delete entries on request.
- Account records are kept while you have an account, and accounting records as long as the law requires.
- Server logs are kept for a limited time for security and troubleshooting, the portal’s for 14 days.
- Waitlist entries are kept until we invite you or you ask us to remove them, and contact messages as long as we need them for your request.
When you close your account or ask us to erase your data, we delete it or anonymise it permanently, except what the law requires us to keep. Our encrypted backups roll over within two years, so deleted data can remain in them until then.
Sharing & sub-processors
We work with as few providers as possible:
- Hetzner (Germany) runs the servers, storage and backups of Prompt Firewall and heySec Home in its data centre in Helsinki, Finland.
- NetiServer (Estonia) hosts our website, our email and the waitlist database.
- Plausible (Estonia) provides our cookieless website analytics.
- Cloudflare (USA) delivers and protects heysec.com.
- Apple and Google (USA) deliver heySec Home’s alerts as push notifications, which carry the home’s name and what happened on which device. Their maps in the portal and apps see the area you look at or the address you search for.
Cloudflare, Apple and Google may process data outside the EU. Those transfers are covered by the EU’s Standard Contractual Clauses, and for Cloudflare and Google also by the EU–US Data Privacy Framework.
Content sent to Prompt Firewall, and photos, video and sound from heySec Home, never go to any analytics, AI or advertising company. We disclose data only when the law or a valid legal order requires it, and tell the affected customer whenever we are allowed to. We will update this list when our providers change.
Your rights
Under the GDPR you can ask to access, correct, erase, restrict or port your personal data, and object to how we process it. Where we rely on your consent, you can withdraw it at any time. Write to [email protected]; we reply within one month.
Closing an account and downloading your data are not in the portal or apps yet, so write to us and we will do it. Deleting a home deletes its events, photos and clips at once, and you can leave a household you were invited to at any time.
For personal data inside content sent to Prompt Firewall, your organisation is the controller, so those requests go through your organisation and we help it answer them. Because we remove personal data before storing that content, we can only export the redacted version.
You can also complain to the Estonian Data Protection Inspectorate ([email protected]) or the supervisory authority where you live.
Cookies
heysec.com sets no cookies for visitors. The portal at my.heysec.com sets only the cookies it needs: one that keeps you signed in, one that protects its forms against cross-site request forgery, one that recognises your browser so we can warn you about sign-ins from new ones, kept for up to five years, and, only if you tick “remember me”, one that keeps you signed in for longer. We use no advertising or tracking cookies, and our apps contain no analytics or advertising trackers.
Children
Our services are not meant for children, and we do not knowingly create accounts for anyone under 16. heySec Home’s cameras and microphones can capture anyone in a home, children included; the household decides where its sensors go and who can see what they send.
Contact & DPO
For questions about this policy or your data, contact our Data Protection Officer:
Data Protection Officer
Kempu OÜ (reg. 14643339), operating as heySec
Tallinn, Estonia
[email protected]
When we change this policy we update the date at the top, and we tell customers before a significant change applies to them.