Private by default
New answers and recordings are linked only to your account. Sharing is item-specific and begins only after your explicit approval.
Privacy & security
This page explains what Heartwood protects today, which systems process your data, and what has not yet been implemented. We only promise what can be technically verified.
New answers and recordings are linked only to your account. Sharing is item-specific and begins only after your explicit approval.
Administration shows account, plan, answer count and technical status – never answer text, recordings, locations or personal profiles.
You can export text, metadata and recordings. Individual answers and revisions can be removed from your archive.
A recording location is stored only after device permission and can remain disabled for all new answers. It is stored rounded to about 100 metres – enough to recognise a town or a valley, too little for an address.
Honest about the technical boundary
Heartwood currently needs to process text and recordings on the server so transcription, profiles, exports and legacy features work. Authorized people with direct infrastructure access could technically access raw data. The regular admin area cannot, and operational access is tightly restricted – but this is why we do not yet claim: “Not even Heartwood can read your content.”
Accounts, text, permissions and technical metadata are stored to operate the application.
Original recordings are kept in private object storage and are not publicly accessible.
Voice recordings are sent to OpenAI for transcription, and approved text is used for profile and archive features. Transcription is on by default and can be switched off in the menu under “Transcribe recordings”; after that no recording is sent for transcription, your browser's speech recognition is not started, and no transcript, search or profile is created. The recording itself is still stored – in the private audio store named above. Typed answers reach the AI only when you explicitly use one of those features.
Your email address is sent to the delivery provider for sign-in links and invitations; answer content does not belong in those messages.
While recording, your browser transcribes live – in Chrome, Edge and other Chromium browsers it sends the microphone signal to a Google service to do so. This happens only when transcription is enabled. Switch it off and the recognition is never started.
If you enabled location capture, coordinates rounded to about 100 metres are sent to the OpenStreetMap mapping service to turn them into a place name. No account, no content, no precise position.
All traffic between your device and Heartwood runs through Cloudflare, which also holds the recordings and the nightly backups. Backups are kept for 30 days.
Your control
Download your own copy of your data regularly.
Go to import & export →Review who may see which answer and revoke access.
Go to legacy →It is only released after 90 days without a sign-in, followed by 30 days of enquiries and a further notice period of 30 days. A single sign-in stops everything immediately.
See the steps →Sign out after using Heartwood on somebody else's device.
Go to personal area →Security roadmap
Clear data flows, private defaults, a content-free admin area, export, item-specific sharing and an understandable security status.
Per-user encryption, separate key management, encrypted backups, stricter operational roles and auditable access logs.
Optional end-to-end encryption with a passkey and recovery code. Shares receive separate keys; AI features then require explicit, time-limited decryption.