Privacy Policy
You're sending us telemetry from your devices, so you deserve a straight answer about what happens to it. Here's what we collect, why we need it, and what you can ask us to do with it.
This is an earlier version. The current privacy policy is at /privacy.
Who We Are
Heapwatch is built and run by Viktor Jamrich Enterprises s.r.o., a company registered in Slovakia at Dolná Poruba 10, 914 43 Dolná Poruba, Slovakia, EU (IČO 50657461; DIČ 2120415561; IČ DPH SK2120415561). We're the data controller for both heapwatch.com and the app at app.heapwatch.com.
Anything privacy-related reaches us at info@heapwatch.com.
What We Collect
- Your account - name, email, a hash of your password, workspace name, and whatever else you fill in while setting things up.
- Billing - your plan, billing interval, invoices, and whether payments went through. Card details go straight to Stripe; we never see or store a full card number.
- What your devices send - device identifiers, telemetry (memory, CPU, threads, logs, events, your own custom values), core dumps, firmware metadata, and connector configuration. This is your content and you stay in control of it. If your devices handle personal data out in the field, it can end up in here too, so send only what you need.
- How the product gets used - pages and features you touch on heapwatch.com and in the app, browser and device type, rough location from your IP, timestamps. We use this to keep the service running, spot abuse, and work out what to build next.
- How you found us - on heapwatch.com we store first-party marketing attribution in your browser (for example UTM campaign parameters, the landing page path, referrer, and ad click identifiers when they appear in the URL). If you register, we attach that to your account so we can see which pages or campaigns led to signups.
- Conversations with us - emails and contact form messages, kept so we can actually follow up on them.
- Cookies - a small set that remembers your cookie choice and preferences like light or dark mode. Optional analytics cookies on the marketing site load only if you say yes.
Why We Need It
Everything above earns its place. We use it to:
- run Heapwatch - accounts, workspaces, device ingest, crash decoding, billing;
- hold up our end of the contract and enforce our Terms and Refund Policy;
- keep the platform secure, catch abuse, and meet our legal obligations;
- send messages that matter: security notices, billing, meaningful product changes;
- improve the product, working from aggregated or anonymised patterns wherever we can;
- understand which marketing pages and campaigns bring people to Heapwatch, without selling that data to anyone;
- answer you when you write in.
In GDPR terms, that rests on performing our contract with you (Art. 6(1)(b)), our legitimate interest in running a secure and improving service and measuring our own marketing (Art. 6(1)(f)), and legal obligations around tax and accounting (Art. 6(1)(c)). Anonymous website statistics via Plausible and first-party campaign attribution on heapwatch.com also fall under legitimate interest: no ad-network profiles, no sale of personal data. Optional PostHog analytics on the marketing site rely on your consent (Art. 6(1)(a)). PostHog in the signed-in app is part of delivering and improving the service you signed up for.
Cookies, Analytics, and Attribution
The essential cookies just remember your cookie decision and site preferences. They don't track you across sites and don't need consent.
We use Plausible on heapwatch.com for anonymous page statistics. It does not set cookies, does not track you across sites, and does not build a personal profile. It is always on.
If you accept analytics in Cookie Settings on heapwatch.com, we also load PostHog (EU-hosted) for optional marketing-site analytics; PostHog may set cookies. You can change your mind in Cookie Settings any time.
When you use the app at app.heapwatch.com while signed in, we run PostHog (EU-hosted) product analytics tied to your account email so we can understand feature usage and improve the product. That is separate from the marketing-site cookie banner.
Separately, heapwatch.com stores first-party marketing attribution in your browser's local storage (not cookies): campaign tags from the URL (such as utm_source), the first and latest landing page, referrer, and ad click identifiers when present. This helps us decorate register links and, if you sign up, record how you arrived. It does not load third-party ad pixels and does not follow you on other websites. You can clear it by clearing site data for heapwatch.com in your browser.
Who Else Touches Your Data
A short list of suppliers who process data on our instructions and nobody else's: our EU hosting and infrastructure providers, the MQTT and ingest layer that carries device traffic, Stripe for payments, our email provider for transactional and support mail, Plausible for anonymous website statistics on heapwatch.com, and PostHog (EU-hosted) for product analytics on the marketing site (if you opted in) and in the app while you use the service.
Telemetry and dumps stay on EU-hosted infrastructure. Stripe handles billing data under its own terms and privacy notice, as payment processors do.
We may hand over data if the law genuinely requires it, or to protect our users, our rights, or someone's safety. We don't sell your personal data.
How Long We Keep It
Account and billing records stick around while your account is active, and afterwards for as long as Slovak tax and accounting law makes us hold them. Marketing attribution stored on your account is kept with your account and removed when we delete your account data. Crash history and telemetry follow the retention window of your plan and are purged automatically after that. You can delete a workspace yourself, or email us and we'll wipe your account data.
Your Rights
If you're in the EEA or UK, you can ask us for a copy of your data, get it corrected or deleted, restrict or object to how we use it, take it elsewhere in a portable format, or pull your marketing-site analytics consent whenever you like. One email is enough - we won't make you fill in a form.
If we ever handle a request badly, you can complain to the Slovak Office for Personal Data Protection (Úrad na ochranu osobných údajov SR) or the supervisory authority where you live. We'd appreciate the chance to fix it first.
If This Policy Changes
A new version gets its own permanent URL (for example /privacy/2026-09-05) and /privacy always shows the one currently in force. If we change optional cookies in a way that matters, we'll reset the consent banner so you get to make the choice again rather than inheriting an old one.