Privacy
Privacy policy
Effective October 2, 2026
This policy explains how HeapFile, a product of VTEK Innovations LLC, handles information through the HeapFile website, mobile and desktop apps, account services, optional cloud sync, support, and subscriptions.
Information we process
- Account information: email address, HeapFile account identifier, authentication records, and account status when you create or use an account.
- User content: captures, handoff packets, titles, provider selections, timestamps, and related metadata that you choose to sync. Content kept only on your device is not sent to HeapFile.
- Purchase information: product identifiers, transaction or order references, subscription status, expiration dates, and cryptographic purchase receipts or tokens needed to verify access. HeapFile does not receive your full payment-card number.
- Support and operations: messages you send, redacted diagnostics you choose to share, security events, IP and request records, and basic app or device information needed to operate and protect the service.
How we use information
We use information to authenticate accounts, provide local and optional cloud features, verify and restore subscriptions, maintain entitlements across devices, respond to support, prevent abuse, secure the service, comply with law, and improve reliability. We do not sell personal information or use HeapFile content for third-party advertising.
Local data and cloud sync
HeapFile is local-first. Mobile captures stay on the device unless you sign in, have an eligible entitlement, and choose to sync a handoff. Desktop data and configured connectors remain subject to the permissions and storage choices shown in those products. Do not place secrets or regulated third-party data in HeapFile unless you are authorized to do so.
Service providers and payments
HeapFile uses Amazon Web Services, including Cognito, API Gateway, Lambda, DynamoDB, and S3, to provide account and optional cloud features. Apple processes iOS in-app purchases and Google processes Android in-app purchases under their own privacy terms. PayPal processes eligible website, desktop, team, or invoice payments. These providers receive only the information needed for their role.
Retention and deletion
We retain account, cloud, security, support, and entitlement records while needed to provide the service and meet legal, tax, accounting, fraud-prevention, dispute, and security obligations. The HeapFile mobile app provides in-app account deletion under Account. Deletion removes the mobile HeapFile account and associated cloud captures and handoffs; the app also clears its local HeapFile records from that device. Limited records may be retained where required by law or for security and dispute handling.
Deleting a HeapFile account does not cancel an Apple App Store or Google Play subscription. Cancel recurring billing separately in the store's subscription settings. Full instructions and the web request option are at heapfile.com/account/delete.
Your choices
You may request access, correction, export, or deletion, subject to applicable law. You can keep captures local, choose whether to sync, restore store purchases, manage subscriptions through Apple or Google, and remove the mobile account in the app. For help, contact admin@heapfile.com.
Children
HeapFile is a productivity product and is not directed to children under 13. We do not knowingly collect personal information from children under 13.
Security and changes
We use technical and organizational safeguards appropriate to the service, but no system is completely secure. We may update this policy as HeapFile changes. Material changes will be posted here with a new effective date.
Contact
Privacy questions may be sent to admin@heapfile.com or through the HeapFile support page.