A Million MomentsWhat shapes your core.

Privacy & security

Your story deserves clear boundaries.

This page explains what Heartwood protects today, which systems process your data, and what has not yet been implemented. We only promise what can be technically verified.

Active today

Private by default

New answers and recordings are linked only to your account. Sharing is item-specific and begins only after your explicit approval.

No content in the admin area

Administration shows account, plan, answer count and technical status – never answer text, recordings, locations or personal profiles.

Your data is portable

You can export text, metadata and recordings. Individual answers and revisions can be removed from your archive.

Location remains optional and coarse

A recording location is stored only after device permission and can remain disabled for all new answers. It is stored rounded to about 100 metres – enough to recognise a town or a valley, too little for an address.

Honest about the technical boundary

Not end-to-end encrypted yet.

Heartwood currently needs to process text and recordings on the server so transcription, profiles, exports and legacy features work. Authorized people with direct infrastructure access could technically access raw data. The regular admin area cannot, and operational access is tightly restricted – but this is why we do not yet claim: “Not even Heartwood can read your content.”

Which services are used and why
01

Heartwood & hosting

Accounts, text, permissions and technical metadata are stored to operate the application.

02

Private audio storage

Original recordings are kept in private object storage and are not publicly accessible.

03

AI processing

Voice recordings are sent to OpenAI for transcription, and approved text is used for profile and archive features. Transcription is on by default and can be switched off in the menu under “Transcribe recordings”; after that no recording is sent for transcription, your browser's speech recognition is not started, and no transcript, search or profile is created. The recording itself is still stored – in the private audio store named above. Typed answers reach the AI only when you explicitly use one of those features.

04

Email delivery

Your email address is sent to the delivery provider for sign-in links and invitations; answer content does not belong in those messages.

05

Your browser's speech recognition

While recording, your browser transcribes live – in Chrome, Edge and other Chromium browsers it sends the microphone signal to a Google service to do so. This happens only when transcription is enabled. Switch it off and the recognition is never started.

06

Place names

If you enabled location capture, coordinates rounded to about 100 metres are sent to the OpenStreetMap mapping service to turn them into a place name. No account, no content, no precise position.

07

Network and backups

All traffic between your device and Heartwood runs through Cloudflare, which also holds the recordings and the nightly backups. Backups are kept for 30 days.

Your control

Review, secure and decide.

Manage permissions

Review who may see which answer and revoke access.

Go to legacy

Your legacy is never released by surprise

It is only released after 90 days without a sign-in, followed by 30 days of enquiries and a further notice period of 30 days. A single sign-in stops everything immediately.

See the steps

Security roadmap

Three verifiable stages instead of one sweeping promise.

Stage 1 · active

Transparency and visible control

Clear data flows, private defaults, a content-free admin area, export, item-specific sharing and an understandable security status.

Stage 2 · next

Keys separated from data

Per-user encryption, separate key management, encrypted backups, stricter operational roles and auditable access logs.

Stage 3 · Private Vault

Only the user can decrypt

Optional end-to-end encryption with a passkey and recovery code. Shares receive separate keys; AI features then require explicit, time-limited decryption.

A new privacy claim is published only after its feature has been implemented, automatically tested and verified in both test and live environments.