Heap

Privacy notice

Effective date: August 29, 2026

This notice explains how Bitsick Productions LLC processes information for Heap. It supplements the general Bitsick privacy policy. If the two notices conflict about Heap, this product-specific notice controls.

Information Heap stores

  • your Google account identifier, verified email address, profile name, and profile image when supplied by Google;
  • inventories, memberships, invitations, items, locations, categories, custom fields, ownership descriptions, and notes you create;
  • photos, PDFs, and other supported files you attach, plus sanitized derivatives, thumbnails, hashes, and file-processing status;
  • AI suggestion drafts and operational metadata such as model, prompt and schema versions, provider request ID, confidence, and token usage; and
  • security, diagnostic, audit, job, API-token, and request records needed to operate and protect the service. Personal access tokens are stored only as hashes.

Access and household sharing

Your personal inventory is private. A household inventory is visible only to its owner, editors, and viewers. Item ownership fields are descriptive and never grant access. Invitations are limited to the exact verified email address named by the inviter, expire after seven days, and can be used only once.

Attachments

Uploads enter private quarantine. Heap verifies file signatures and hashes, scans for malware, strips image metadata, re-encodes images, sanitizes accepted PDFs, and publishes only the private processed copy. Raw uploads are deleted after processing. Files are delivered through short-lived signed access after authorization and cannot be linked across inventories.

AI processing

Heap sends only the sanitized images you select to OpenAI to produce draft item suggestions. Heap sets store: false, so foreground Responses API requests are not retained as provider application state. OpenAI may still retain prompts, outputs, and selected images in abuse-monitoring logs for up to 30 days, or longer where legally or safety required. Image inputs are scanned for child-safety enforcement, and flagged images may be retained for manual review. OpenAI states that API data is not used to train its models unless the customer opts in; Heap has not opted in. Heap does not put image bytes in its own job records and never creates an item from AI output until you review and confirm it.

Do not upload sensitive documents or images for AI recognition. You can use Heap without the recognition feature.

Service providers

  • Google Cloud Platformhosts Heap's application compute, database, private files, workflow system, and encrypted backups in the europe-west4 region. Google authentication and operational services such as logging and monitoring use Google's global or multi-region control planes and are not represented as europe-west4-only.
  • Google provides the Google account sign-in flow you choose to use.
  • OpenAIprocesses selected sanitized images only when you request AI recognition. Heap disables Responses API application-state storage, while OpenAI's abuse-monitoring and image-safety retention described above still applies.

Heap's workflow system is self-hosted within its Google Cloud environment. Staging and production use separate projects, credentials, databases, and storage.

Retention, export, and deletion

  • Trashed items and unlinked attachments are recoverable for 30 days.
  • Completed export downloads expire after 24 hours.
  • Enrollment and household invitation records, including the intended email address, are scheduled for deletion 30 days after acceptance, revocation, or expiry. Security and audit events are scheduled for deletion after two years, without copying invitation or OAuth email addresses into audit metadata. Email-only invitation traces can be erased sooner on request; doing so invalidates matching active invitation links.
  • Account deletion starts a 30-day recovery period. After it expires, Heap erases the active personal inventory, authentication identity, API tokens, files, exports, and account-linked personal data. Application file buckets disable provider soft delete, and Heap removes every live and noncurrent file generation. Encrypted production database backups retain up to 14 daily restore points and seven days of transaction logs before aging out; they are isolated and used only for disaster recovery. Named pre-release backups are removed after 28 days. Through a 90-day restore-safety window after final erasure, Heap retains three narrow deletion records: an anonymized request and completed cleanup status in the operational database; a database tombstone containing a one-way provider-identity hash; and an immutable external ledger containing that hash plus opaque request, account, and inventory IDs. Cleanup status may retain opaque storage prefixes needed to verify erasure. These records contain no email, name, raw provider subject, item or inventory content, or files. They prevent an older backup from reviving an erased account and are scheduled for automatic purge when the window ends. Database maintenance and cloud-storage lifecycle processing may complete shortly afterward. Narrow legal or fraud-prevention records may be retained where required.
  • A household owner must transfer or schedule deletion of owned households before deleting the account.

You can request JSON, CSV, and sanitized attachment exports from Heap before deletion.

Your choices and contact

Use Heap's account settings to export data or schedule deletion. For access, correction, privacy, or deletion questions, email privacy@bitsick.com. For a security report, email security@bitsick.com and do not include inventory contents, credentials, or private files.

General help is available on the Heap support page.