Heyviber
Back to Heyviber

Privacy notice

Privacy in the Heyviber public beta

This notice explains what the current Heyviber beta collects, what becomes public, which service providers are involved, and how to ask about your data. Last updated 16 August 2026.

01

Public by design

Published projects, project-owner details shown on the page, and visible suggestions are available to anyone. Do not publish secrets, confidential material, or personal data you do not have a right to share.

02

Explicit analytics only

Heyviber sends selected product events to PostHog. Event properties must not contain email addresses or free-text project, suggestion, help-request, report, or admin-note content.

03

A human-operated beta

Reports and concierge requests can be reviewed manually. Questions, access requests, corrections, and deletion requests can be sent to [email protected].

Controller and contact

Heyviber is operated by Verstos Oy (Business ID 3429381-6), Finland, which acts as the controller for the personal data described in this notice. Contact the controller and send privacy requests to [email protected].

What Heyviber handles

01

Account and authentication data

Clerk handles sign-in. Heyviber stores the Clerk user identifier, email address, handle, optional name and profile details, role, and language needed to provide the account and owner controls.

02

Projects, suggestions, votes, and decisions

Project content, live and screenshot links, tags, feedback requests, suggestions, votes, and owner decisions are stored to run the public feedback loop. Published content and visible account attribution appear publicly.

03

Reports and concierge requests

Reports store the reported target and reason. Manual Launch Review and expert-help requests can include the project, requester, scope, optional budget and timeline, status, and internal follow-up notes.

Why it is used

01

Provide and protect the beta

Data is used to authenticate users, publish and manage projects, display feedback, prevent duplicate votes, moderate reports, respond to help requests, troubleshoot the service, and protect users and the service.

02

Understand the core funnel

PostHog receives explicit events such as page views and started or completed product actions, with limited properties such as path, locale, source, project slug, and a signed-in account identifier. Autocapture and session recording are disabled.

03

Send service emails

Resend is used to deliver operational messages, including a project-owner notification about a new suggestion and an admin notification about a concierge request. These messages can contain the information needed to handle that event.

Legal bases and data sources

Account, publishing, feedback, owner-control, and requested support data is processed to provide the beta service and take steps requested by the user. Security, abuse prevention, moderation, service reliability, and limited product analytics are processed for Verstos Oy’s legitimate interests in operating and improving a safe beta, balanced against users’ rights. Data can also be processed where needed to meet a legal obligation or establish, exercise, or defend legal claims. Data comes from you, your Clerk sign-in account, your use of Heyviber, other users’ reports or contributions, and public project destinations you choose to link.

Service providers and external destinations

01

Clerk, PostHog, Resend, and hosting

Heyviber relies on Clerk for authentication, PostHog US Cloud for limited product analytics, Resend for service email, and Railway and its database services for hosting and storage. Each provider and its subprocessors processes data needed for its part of the service.

02

Beehiiv product links

Free digital-product links open pages operated through Beehiiv and include campaign parameters. If you submit an email address or order on Beehiiv, Beehiiv handles that information under its own interface and terms; Heyviber does not copy subscriber email addresses into PostHog.

03

Project and other external links

Project websites, screenshot hosts, developer profiles, and other external destinations are controlled by their own operators. Their privacy practices apply after you leave Heyviber.

International transfers

Some providers or their subprocessors process data in the United States or another country outside the European Economic Area. Applicable provider terms and data-processing agreements describe the transfer mechanism, such as an adequacy framework or the European Commission’s Standard Contractual Clauses. You can request more information about the safeguards from [email protected].

Retention, correction, and deletion

The beta does not yet publish one fixed retention period for every record. Account and contribution data is kept while it is needed to operate the account, public feedback history, moderation, support, security, and a limited audit trail. Data can remain temporarily in provider systems and backups after removal. Email [email protected] to ask what data is associated with you, request a correction, or request account or content deletion. The request will be reviewed against the public record, other users’ contributions, security needs, and applicable obligations before action is taken.

Your data protection rights

Depending on the processing and applicable law, you can request access, correction, deletion, restriction, or portability of your personal data and object to processing based on legitimate interests. Where processing is based on consent, you can withdraw it. Heyviber does not make decisions that produce legal or similarly significant effects solely by automated processing. Send a request to [email protected]; identity may need to be verified. You may also lodge a complaint with Finland’s Office of the Data Protection Ombudsman at tietosuoja.fi.

Changes and contact

This notice describes the current public beta and will be updated when data practices or providers change materially. Privacy and data requests use the existing Heyviber contact address: [email protected].