Privacy policy
Last updated 22 July 2026
This policy covers two different relationships. When you sign up for Hepo we are the controller of your account data. When your customers talk to you through Hepo we are a processor acting on your instructions, and you are the controller. The obligations differ, so they are separated below.
Data we hold about you, our customer
- Account details: name, email address, password hash, workspace and site names.
- Billing records: subscription payments, invoices and the identifiers our payment processor needs.
- Product telemetry: which console screens are opened and when, for diagnosing faults.
- Correspondence: what you write to us and what we write back.
We do not sell any of it, we do not share it with advertising networks, and we do not build a profile of you for anything other than running the service you are paying for.
Data we process on your behalf
Everything your visitors generate is yours. We hold it so the product can function and we act on your instructions about it.
- Conversation transcripts and attachments.
- Visitor metadata: approximate location from IP, network operator, browser and operating system, first and current visit times.
- Session recordings, captured as DOM changes rather than video, with all input values masked in the browser before transmission.
- Analytics events: page views, referrers and conversion signals keyed to the same visitor id.
- Any attributes you pass through the identify call.
Masking, and what it means
Values typed into form fields are replaced before the recording event leaves the visitor browser. Keystroke timing survives, characters do not. There is no configuration that disables this. Payment card fields normally live in a cross-origin frame belonging to your processor and are unreachable to our recorder by construction.
Retention
- Session recordings expire on the window you set per site and are then deleted from object storage, not hidden.
- Transcripts are kept until you delete them or close the account.
- Account and billing records are kept while the account is open, then for as long as tax law in our jurisdiction requires.
- Closing an account deletes everything after a seven day grace period, or immediately on request.
Where it lives
Hosted deployments site data in the European Union on encrypted object storage. Self-hosted deployments site data wherever you put the machine, and we have no access to it at all.
Sub-processors
Object storage, and for hosted plans the provider serving the model your agent uses. Both are named in the data processing agreement. Self-hosted installations have no sub-processors.
Rights
You can export everything from the console at any time on any plan, in formats that are useful without us. If a visitor asks you to erase them, deleting the visitor record removes their transcripts, recordings and analytics rows together, including the objects in storage. There is an API for the same operation so you can wire it into your own privacy tooling.
For your own account data, mail support@hepo.ai and we will action access, correction or erasure requests within thirty days.
Model training
Conversation content is not used to train models, ours or anyone else. Translation on hosted plans runs on a model we operate, so message bodies are not sent to a third-party translation API.
Contact
Hepo, reachable at support@hepo.ai. If you are not satisfied with our response you may complain to your local supervisory authority.