Privacy Policy
You're sending us telemetry from your devices, so you deserve a straight answer about what happens to it. Here's what we collect, why we need it, and what you can ask us to do with it.
This is an earlier version. The current privacy policy is at /privacy.
Who We Are
Heapwatch is built and run by Viktor Jamrich Enterprises s.r.o., a company registered in Slovakia at Dolná Poruba 10, 914 43 Dolná Poruba, Slovakia, EU (IČO 50657461; DIČ 2120415561; IČ DPH SK2120415561). We're the data controller for both heapwatch.com and the app at app.heapwatch.com.
Anything privacy-related reaches us at info@heapwatch.com.
What We Collect
- Your account - name, email, a hash of your password, workspace name, and whatever else you fill in while setting things up.
- Billing - your plan, billing interval, invoices, and whether payments went through. Card details go straight to Stripe; we never see or store a full card number.
- What your devices send - device identifiers, telemetry (memory, CPU, threads, logs, events, your own custom values), core dumps, firmware metadata, and connector configuration. This is your content and you stay in control of it. If your devices handle personal data out in the field, it can end up in here too, so send only what you need.
- How the product gets used - pages and features you touch, browser and device type, rough location from your IP, timestamps. We use this to keep the service running, spot abuse, and work out what to build next.
- Conversations with us - emails and contact form messages, kept so we can actually follow up on them.
- Cookies - a small set that remembers your cookie choice and preferences like light or dark mode. Analytics cookies load only if you say yes.
Why We Need It
Everything above earns its place. We use it to:
- run Heapwatch - accounts, workspaces, device ingest, crash decoding, billing;
- hold up our end of the contract and enforce our Terms and Refund Policy;
- keep the platform secure, catch abuse, and meet our legal obligations;
- send messages that matter: security notices, billing, meaningful product changes;
- improve the product, working from aggregated or anonymised patterns wherever we can;
- answer you when you write in.
In GDPR terms, that rests on performing our contract with you (Art. 6(1)(b)), our legitimate interest in running a secure and improving service (Art. 6(1)(f)), and legal obligations around tax and accounting (Art. 6(1)(c)). Anonymous website statistics via Plausible also fall under legitimate interest: no cookies, no personal profiles. Optional PostHog product analytics rely on your consent (Art. 6(1)(a)).
Cookies and Analytics
The essential cookies just remember your cookie decision and site preferences. They don't track you anywhere and don't need consent.
We use Plausible on heapwatch.com for anonymous page statistics. It does not set cookies, does not track you across sites, and does not build a personal profile. If you accept analytics in Cookie Settings, we also load PostHog (EU-hosted) for optional product analytics; PostHog may set cookies. You can change your mind in Cookie Settings any time.
Who Else Touches Your Data
A short list of suppliers who process data on our instructions and nobody else's: our EU hosting and infrastructure providers, the MQTT and ingest layer that carries device traffic, Stripe for payments, our email provider for transactional and support mail, Plausible for anonymous website statistics on heapwatch.com, and PostHog for optional product analytics if you opted in.
Telemetry and dumps stay on EU-hosted infrastructure. Stripe handles billing data under its own terms and privacy notice, as payment processors do.
We may hand over data if the law genuinely requires it, or to protect our users, our rights, or someone's safety. We don't sell your personal data.
How Long We Keep It
Account and billing records stick around while your account is active, and afterwards for as long as Slovak tax and accounting law makes us hold them. Crash history and telemetry follow the retention window of your plan and are purged automatically after that. You can delete a workspace yourself, or email us and we'll wipe your account data.
Your Rights
If you're in the EEA or UK, you can ask us for a copy of your data, get it corrected or deleted, restrict or object to how we use it, take it elsewhere in a portable format, or pull your analytics consent whenever you like. One email is enough - we won't make you fill in a form.
If we ever handle a request badly, you can complain to the Slovak Office for Personal Data Protection (Úrad na ochranu osobných údajov SR) or the supervisory authority where you live. We'd appreciate the chance to fix it first.
If This Policy Changes
A new version gets its own permanent URL (for example /privacy/2026-09-02) and /privacy always shows the one currently in force. If we change optional cookies in a way that matters, we'll reset the consent banner so you get to make the choice again rather than inheriting an old one.