HEARD BY THE CODE
Privacy Notice
HEARD's Round 1 staging beta is for up to 15 verified testers. It runs a guided text conversation and analyses typed vents in your browser with small, transparent rules. Your chat messages are not sent to OpenAI, TypeSafe, Anthropic, Google or another model provider by HEARD. The rules can miss risks or misunderstand your situation. This is not generative AI or a clinical assessment.
Who handles your information
AT THE CODE is responsible for the HEARD beta account, waitlist and product feedback records. AT THE CODE is registered with the Information Commissioner’s Office (ICO). Registration reference supplied by AT THE CODE: 00015761464. Registration does not mean the ICO endorses HEARD.
What HEARD stores
If you create a device vault, your chosen Studio cards, check-ins, problem titles, reflections, evidence files, and practical life map are encrypted with a key derived from your passphrase before they are written to this browser's IndexedDB storage. The passphrase and key stay in memory while the vault is open. HEARD has no recovery key or cloud sync. A different device, browser profile or cleared browser storage will not contain your vault.
Earlier preview accounts may still contain email, sessions, billing metadata and unencrypted cloud Studio or life map records from previous versions. You can open “Manage earlier cloud records” to sign in and erase active Studio and life map records. Payment, account and transaction records may have separate legal retention requirements; contact AT THE CODE about those records. This staging change does not retrospectively encrypt information already processed under the earlier version.
Round 1 access and waitlist
To enter Round 1, request a one-time sign-in code and verify your email. The first 15 people who complete verification get places automatically; requesting a code does not reserve one. HEARD stores your email, activation and last-use dates, and counts of chat starts and 15-second local voice blocks. A tester has three chat starts and up to three minutes of guided voice in this round. Only counts are sent for these limits; no words or audio accompany the usage requests. The owner can remove a tester and reopen the place. The removed email is kept on a Round 1 blocklist until AT THE CODE deletes it, so it cannot rejoin. Removal revokes access on a new request but cannot erase a vault already stored on that person's device. Sign-in uses an emailed code and an account session cookie.
If you choose the waitlist, we ask for your email and send a confirmation code through Resend. Only an email confirmed with that code enters the owner waitlist. The owner can delete a waitlist entry. Confirmation codes expire in 10 minutes; expired code records are deleted when the waitlist is used or reviewed. Waitlist emails older than 180 days are deleted from the active database when someone joins or the owner reviews it; a dormant database may keep them longer. Provider backups can persist temporarily. You may request waitlist removal through AT THE CODE's published contact route. We use waitlist emails for HEARD beta place contact, not a general marketing list.
What HEARD does not store by default
Chat messages and typed vents are not saved to the vault automatically. The active conversation stays in this page's memory. “Clear conversation and plan” removes the messages and copied plan from the active page; leaving the page also clears HEARD's active chat state. We do not claim to erase copies made by your browser, operating system, keyboard, backups or screenshots. HEARD does not collect a card number or CVC in this preview.
On-device chat, analysis and voice
The guided chat and “Find one next step” use local text matching and templates in your browser. They make no model API request and no provider receives or trains on your words through those actions. The optional guided voice preview activates only when the browser verifies local recognition and a local speaking voice; it may not work on your device. It is not a natural AI conversation. The old cloud analysis and voice session routes reject new requests.
Professional referrals
Family-solicitor and independent-social-worker referral forms are transient handoffs. HEARD does not create a referral database record. The information is emailed to the referral reviewer so they can decide whether to pass it to an appropriate professional. After the handoff, the working referral email is deleted from the reviewer's inbox and deleted-items/trash. Email providers necessarily process the message while delivering and storing it. A professional who receives a referral is responsible for their own record under their own privacy notice.
Optional product feedback
If you choose “Tell us what you think,” the part of HEARD you tried, what worked, what you would improve, what confused you, what broke, and whether you would use it again are sent to HEARD's Cloudflare-hosted feedback inbox for the owner to review and improve the preview. This is separate from your private chat and device vault: neither is attached automatically. The feedback record contains no account ID, email, file or raw IP address. Do not include private vents, names, contact details or sensitive records in the feedback fields. Cloudflare Turnstile checks that a person is submitting the form. Feedback is not emailed to a model provider or published.
After you submit, HEARD shows a deletion code. Keep it if you may want to remove your feedback; HEARD does not store the code itself, only a hash used to find the record. You can enter the code in “Erase feedback I sent earlier,” or the owner can delete a record from the inbox. Records older than 90 days are removed from the active database when new feedback arrives or the owner opens the inbox; if neither happens, the record can remain longer. Provider backups may persist temporarily. This feedback process and its privacy terms need independent review before a public launch.
Service providers
Cloudflare hosts the site and receives ordinary website requests and connection metadata; it does not receive chat messages or typed vents through the local conversation and analysis actions. The beta sign-in, waitlist and optional feedback form load Cloudflare Turnstile when you choose those flows, and Resend processes sign-in, waitlist confirmation and referral emails. Stripe handled earlier payments and billing records. External advice or video links open only when you select them; HEARD does not include your writing in those links. Referral forms explicitly send the details you enter through Resend when you submit them.
Retention
Deleting an individual card or evidence file removes its active encrypted record from the browser vault. “Erase this device vault” deletes the active IndexedDB database, including its encryption key check and encrypted evidence. Browser storage internals, device backups and exported copies may persist outside our control. Earlier cloud erasure removes active Studio and life map database rows; provider backups may persist for a limited period. We will not call either action a secure wipe of every physical copy.
Your choices and rights
Round 1 typed guidance requires an email-verified tester account while a place is available. You choose whether to save a board or evidence, lock or erase the device vault, and whether to open an external link or send a referral. Avoid putting bank security details or another person's sensitive records in the staging preview. Depending on applicable law, you may have rights to access, correct or erase service account information; use AT THE CODE's published contact route for those requests.
Safety
HEARD is not an emergency service, therapy service, law firm or medical provider. If you or someone else is in immediate danger in the UK, call 999 or go to A&E. For urgent mental-health help that is not an emergency, use NHS 111.
Version: 2 October 2026. This notice should be reviewed before public launch and whenever the service or processors materially change.