Privacy Policy
Last updated: August 1, 2026
HeimOS ("HeimOS," "we," "us," or "our") operates the heimos.ai website, the HeimOS admin console, and the HeimOS AI gateway (together, the "Service"). This policy explains what we collect, why we collect it, and the choices you have. We wrote it to be read — plain language, no dark patterns.
The short version: HeimOS is infrastructure that sits between your applications and AI model providers. We need operational metadata to route, meter, and govern your traffic. We do not need the contents of your prompts and completions, and by default we do not retain them.
- Prompt and completion content is not stored unless you switch on content logging.
- We never sell personal information, and we never train models on your data.
- You can export or delete your organization's data at any time.
- Self-host HeimOS and none of your traffic touches our infrastructure at all.
1. Information we collect
Information you give us. Account details (name, work email, organization name), authentication identifiers from your identity provider, billing contact and payment details handled by our payment processor, provider credentials you choose to store, gateway configuration such as routes, quotas, guardrail policies, and MCP server registrations, and anything you send us in a support conversation.
Information we collect automatically. Request metadata needed to route and meter traffic — timestamp, virtual key, team and application, model and provider selected, token counts, latency, cost, guardrail decisions, HTTP status, and error codes. We also collect standard console telemetry: IP address, browser and device information, and product usage events.
Prompt and completion content. Request and response bodies pass through the gateway in memory so they can be routed, redacted, and forwarded. They are not written to durable storage unless an administrator in your organization explicitly enables content logging, in which case retention follows the setting you choose.
2. How we use information
- Operate the gateway: authenticate keys, enforce quotas and guardrails, route to providers, and record the audit trail.
- Meter usage and produce the spend, latency, and reliability analytics shown in your console.
- Bill your account and send invoices, receipts, and quota notifications.
- Send service notices, security alerts, and support responses.
- Detect abuse, investigate incidents, and protect the integrity of the Service.
- Improve reliability and performance using aggregated, de-identified metrics.
We do not use your prompts, completions, or configuration to train machine-learning models, and we do not share them with third parties for that purpose.
3. Model providers and MCP servers
HeimOS forwards requests to the model providers and MCP servers you configure — for example OpenAI, Anthropic, Google, self-hosted models, or your own internal tool servers. Once a request leaves the gateway, the receiving provider's own privacy terms govern how it handles that data. Your routing rules determine where requests go; we recommend reviewing each provider's policy and data-residency options before enabling it.
Guardrail policies that redact sensitive data run before the request leaves your trust boundary, so redacted values are never transmitted to the provider.
4. Sharing and disclosure
We do not sell personal information. We share it only with service providers who help us run the Service — cloud hosting, error monitoring, analytics, payment processing, and customer support — each bound by contract to use it solely on our instructions. We may also disclose information when required by law or valid legal process, to protect our rights or the safety of others, or in connection with a merger, acquisition, or asset sale, in which case we will notify you before your information becomes subject to a different policy.
5. Security
All traffic to and from HeimOS is encrypted with TLS 1.2 or higher, and data at rest is encrypted with AES-256. API keys and virtual keys are hashed, never stored in plaintext, and shown to you only once at creation. Provider credentials are encrypted with envelope encryption and decrypted only in the request path. Access to production systems is role-restricted, logged, and reviewed. No system is perfectly secure, but we treat this as a first-class engineering problem rather than a compliance checkbox.
6. Retention
Account and configuration data is retained while your organization is active. Request metadata and audit records are retained for the window associated with your plan; enterprise customers can set a custom period. Optional content logs follow the retention you configure. When you delete your organization, we remove your data from production systems within 30 days and from backups within 90 days, except where law requires us to keep it longer.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete, export, or restrict the processing of your personal information, and to withdraw consent or object to certain processing. Most of these are available directly in the console; for anything else, write to us and we will respond within the period required by applicable law.
8. International transfers
We operate globally, and your information may be processed in countries other than your own. Where required, we rely on Standard Contractual Clauses or equivalent safeguards. Enterprise customers can pin processing to a specific region or self-host the gateway entirely.
9. Cookies
We use strictly necessary cookies for authentication and session management, and a small number of analytics cookies to understand product usage. We do not run advertising trackers. You can control cookies in your browser, though disabling the necessary ones will prevent you from signing in.
10. Children
HeimOS is a business product and is not directed to anyone under 16. We do not knowingly collect information from children, and we delete it if we discover we have.
11. Changes
We may update this policy as the Service evolves. Material changes will be announced by email or in-console notice at least 14 days before they take effect, and the date at the top of this page will always reflect the current version.
12. Contact
Questions about this policy, or a request about your data? Reach us at privacy@heimos.ai. For anything else, hello@heimos.ai.