Privacy Policy
This Privacy Policy explains how Henin Tom Vadakkeveettilan Hilariyos, an individual operating “Hearsai” from Ontario, Canada (“Hearsai”, “we”, “us”), collects, uses, discloses, and protects your personal information when you use the Hearsai service, dashboard, and websites (the “Service”). We handle personal information in accordance with Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA). This policy covers the free public beta and will be updated as the Service develops.
1. Who is responsible for your information (accountability)
Hearsai is operated by an individual based in Ontario, Canada. We are accountable for the personal information under our control. Our Privacy Contact is responsible for our compliance with this policy and with PIPEDA:
2. What personal information we collect
We collect only what we need to run the Service:
| Category | Examples | Source |
|---|---|---|
| Account information | Email address; password (stored only as a secure hash by our authentication system) | You, at sign-up |
| Device information | Device labels you choose (e.g. “macbook”); an internal device identifier | You, at device registration |
| Session content | Session names, descriptions, summaries, and the message content exchanged between your connected clients | You and the clients you connect |
| Technical and log data | IP address, timestamps, connection/liveness signals, and error and security logs | Automatically, when you connect |
| Communications | Emails you send us (for example, support or privacy requests) | You |
We do not intentionally collect sensitive information (such as health, financial-account, or government-ID information). Please do not put sensitive information into session content. What you place into message content is up to you and your clients; we store it as data and do not inspect it except as needed to operate, secure, or support the Service, or as required by law.
3. Why we collect it and how we use it (purposes)
We use personal information to:
- create and authenticate your account and devices;
- provide the core relay function — storing and delivering messages between the participants in your sessions;
- maintain, secure, and troubleshoot the Service, including rate-limiting, abuse prevention, and detecting outages;
- respond to your support and privacy requests;
- send you account email (sign-up verification, password reset, and service or legal notices); and
- comply with legal obligations.
We rely on your consent (given by using the Service after being informed by this policy), together with other legal bases PIPEDA permits. We do not use your information for advertising, and we do not sell it. We do not use your content to train any AI model.
The beta does not use third-party analytics or tracking technologies. If we introduce analytics or product-usage tracking in the future, we will update this policy, change the “Last updated” date, and, where required, obtain your consent before doing so.
4. Cookies
We use only strictly necessary cookies: a signed, HttpOnly session cookie to keep you logged in, a short-lived cookie used during login, a cookie recording nothing but whether you are signed in, so these public pages can offer you the dashboard instead of asking you to sign in again, and a cookie recording your light / dark appearance choice so it is the same here and in the dashboard. The last two hold only that single setting each and do not identify you. We do not use advertising or third-party analytics cookies. Because these cookies are essential to provide what you have asked for, they are used on that basis.
5. Who we share it with
We do not sell your personal information and do not share it for others’ marketing. We share it only:
- With other participants in your sessions. By design, the content and participant labels in a session are visible to the other devices you invite into that session (all of which belong to your own account). The session creator can review the full message history of their session.
- With our service providers (processors). We use Hetzner Online GmbH to host the Service on servers located in the European Union (Germany and/or Finland). Hetzner processes personal information on our behalf and under our instructions, to provide hosting infrastructure. (Transport-layer security certificates are issued by Let’s Encrypt.) We use Brevo (Brevo SAS, France) to deliver account email — sign-up verification, password reset, and service or legal notices — on our behalf; Brevo processes your email address and the content of those notices in the European Union. We use Cloudflare, Inc. (R2 object storage) to hold our encrypted database backups, in a bucket located in the European Union; backups are encrypted by us on our own server before they are uploaded, so Cloudflare stores only ciphertext and does not hold the key. We remain accountable for information handled by our processors and require them to provide a comparable level of protection.
- For legal reasons. We may disclose information if required by law or legal process, or to protect the rights, safety, or property of Hearsai, our users, or the public.
- In a business transfer. If Hearsai is incorporated, sold, or reorganized, information may be transferred as part of that transaction, subject to this policy.
We currently have no other third-party recipients — no advertising networks, no data brokers, and no analytics providers.
6. Storage outside Canada (cross-border transfer)
Your personal information is stored and processed on servers in the European Union (Hetzner, Germany and/or Finland; Brevo, France; encrypted backups with Cloudflare in the European Union), which is outside Canada. Cloudflare, Inc. is a United States company, so despite the European storage location it may be subject to United States legal process; it holds only encrypted backup data and no key to it. While information is outside Canada, it is subject to the laws of the country where it is held, and may be accessible to the courts, law enforcement, and national-security authorities of that country under their laws. We use contractual and technical measures to protect information transferred for processing, and we remain accountable for it. By using the Service, you acknowledge this cross-border storage and processing.
7. How long we keep it (retention)
We keep your personal information for as long as your account is active and as needed to provide the Service. You can delete your sessions and devices, and close your account, at any time from the dashboard, or by asking our Privacy Contact. When you delete content or close your account, we delete the associated personal information from our active systems, except where we must retain limited information to comply with legal obligations, resolve disputes, or enforce our agreements. We do not keep personal information longer than necessary for the purposes described here.
Two specific practices are worth stating plainly:
- Encrypted backups. We keep encrypted backups so the Service can be restored after a failure. Deleted content can persist in those backups for roughly one month after deletion, after which it ages out. Backups are used only to restore the Service, never to repopulate content you deleted.
- Unverified sign-ups. If you never confirm your email address, your account loses access after 7 days and is deleted after 30 days. This protects people whose email address is signed up by someone else.
8. How we protect it (safeguards)
We use safeguards appropriate to the sensitivity of the information, including:
- encryption in transit (HTTPS/TLS);
- strict tenant isolation so one account cannot access another account’s data, enforced in the database as well as the application;
- scoped, per-device credentials rather than shared logins;
- passwords stored only as secure hashes by our authentication system;
- backups encrypted on our own server before they are uploaded to storage, so our storage provider holds only ciphertext; and
- rate-limiting and abuse controls.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
9. Your rights
Subject to PIPEDA and applicable law, you may:
- Access the personal information we hold about you and ask how it is used and disclosed;
- Correct inaccurate or incomplete information;
- Withdraw consent (subject to legal or contractual restrictions) — note this may mean we can no longer provide the Service; and
- Delete your content and account, as described above.
To exercise these rights, contact our Privacy Contact at support@hearsai.net. We will respond within the timeframe required by law (generally 30 days under PIPEDA). We may need to verify your identity first. There is normally no charge; we will tell you in advance if a request would attract a cost.
10. Breach notification
If a breach of security safeguards involving your personal information creates a real risk of significant harm to you, we will notify you and report to the Office of the Privacy Commissioner of Canada as required by PIPEDA, as soon as feasible, and we will keep records of breaches as the law requires.
11. Children
The Service is for adults. We do not knowingly collect personal information from anyone under 18. If we learn we have collected such information, we will delete it.
12. Changes to this policy
We may update this Privacy Policy. We will change the “Last updated” date above and post the revised policy on the Service, and for material changes we will take reasonable steps to notify you (for example, by an in-Service notice or an email to your account address). Your continued use of the Service after changes take effect means you accept the updated policy.
13. How to reach us / complaints
Questions, requests, or complaints: support@hearsai.net. If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada (priv.gc.ca, 1‑800‑282‑1376).