Heicode Docs

Heicode Privacy Policy & Secret Vault Notice

Heicode's privacy policy, secret vault, and rules for account dormancy, account deactivation, and service suspension.

This document explains how Heicode handles user data, connects resources, safeguards secrets, and manages credentials in the secret vault in the event of account dormancy, account deactivation, or service suspension.

Terms may vary across different models, regions, plans, BYOK arrangements, or third-party channels; if this document conflicts with the original provider's latest policy or a separately signed agreement, the corresponding official terms or signed agreement shall prevail.

Privacy Policy

Heicode processes only the data necessary to authenticate accounts, run Agent software tasks, connect authorized resources, route model requests, process billing, and safeguard service security.

Data Heicode May Process

  • Account identifiers, organization or team affiliation, roles, login status, device and network security signals, subscription status, and usage records.
  • Task content, such as prompts, selected files, repository summaries, SK references, tool calls, execution logs, generated plans, code diffs, deployment records, and user feedback.
  • Resource metadata, such as repository names, branches, cloud resource names, model names, token usage, approval records, risk levels, and secret_ref.

Purposes of Data Processing

  • Authenticating accounts, authorizing roles, controlling resource scope, routing model requests, running Agents, executing approved tools, and delivering product functionality.
  • Measuring usage, calculating consumption, processing subscriptions, preventing abuse, investigating security incidents, debugging stability issues, and maintaining service quality.
  • Using necessary logs, metadata, aggregated statistics, or de-identified information within an appropriate scope to improve product operations.

Model & Third-Party Processing

  • Inputs, outputs, tool results, files, and logs may be processed by the selected model provider, cloud services, deployment services, payment services, or other processors necessary to provide Heicode.
  • Data-processing rules may differ across APIs, enterprise, consumer, free, paid, BYOK, proxy, or marketplace channels, regions, and feature configurations.
  • Unless the corresponding model channel has been confirmed suitable for processing that category of data, customers should not send sensitive, confidential, personal, regulated, or third-party-restricted data to a model.

Data Retention & User Control

  • Heicode retains personal data, task records, security logs, billing records, and audit records only as needed for product operation, security, compliance, dispute handling, and legal requirements.
  • Users or administrators can remove resource authorizations, rotate credentials, revoke sessions or tokens, delete configuration data that supports deletion, and request account or organization changes through available support channels.
  • Backups, immutable audit records, anti-fraud records, and records that must be retained by law may continue to be retained for a limited time after a standard deletion request.

Client Error Telemetry (Diagnostics)

  • The Heicode desktop client may upload diagnostic telemetry when an error occurs, used solely to investigate stability issues. This capability is disabled by default and is only enabled after being truthfully disclosed in this privacy policy.
  • Telemetry includes only: crash or error category, error codes and their hashes, redacted stack traces, runtime environment (app version, platform, OS version, architecture, region), and an in-session sequence number; it does not include prompts, code body content, tokens, email addresses, full file paths or username-containing paths, raw IP addresses, or other identifiable content — out-of-scope fields are dropped or redacted server-side.
  • Telemetry includes a device identifier (device_id), which can be linked to an account; client error telemetry is therefore account-linkable data, not anonymous data.
  • Telemetry is not used for billing, is not counted toward usage records, and is deleted periodically according to the set retention period.

Secret Vault

The secret vault is used to store or reference the Git, cloud, database, deployment, payment, and model-provider credentials needed to connect authorized resources; it is not used to store ordinary account passwords or MFA recovery codes.

Scope of Secret Vault Use

  • The secret vault is used only for storing credentials related to authorized resources and approved tasks.
  • Heicode stores only the necessary secret_ref metadata and encrypted or protected credential material.
  • Raw secrets must not appear in ordinary product UI, front-end payloads, Git, Markdown, screenshots, ordinary logs, or Agent memory.
  • Agents and tools are granted only the specific credential capabilities needed within the scope of an approved task, resource scope, and time window.

Handling of Secrets After Account Deactivation

  • When a resource authorization is removed, an account is deactivated, an organization is closed, or a subscription is terminated, available credentials in the secret vault immediately stop being used for new tasks.
  • Recoverable raw secret material in production secret stores will be deleted or rendered unrecoverable within 30 days of deactivation.
  • Encrypted backups or disaster-recovery copies may be retained until the backup rotation cycle completes, but for no more than 90 days.
  • Except where required by law, security incident investigation, anti-fraud purposes, billing disputes, or otherwise agreed in an enterprise agreement, Heicode will not retain recoverable secret material for a deactivated account beyond 90 days.

Account Dormancy, Deactivation & Service Suspension

  • Heicode may treat an account as dormant when there has been no login, no paid usage, no running tasks, no organization activity, or no active subscription activity for 180 consecutive days.
  • After a dormancy notice is sent via the product, email, or an administrator channel, if the account is not restored to active use, Heicode may restrict login, stop new Agent tasks, disable model calls, disconnect resource access, and begin the secret vault cleanup process.
  • Heicode may suspend, restrict, or terminate service in cases of illegal activity, violation of model provider policies, unauthorized security testing, data exfiltration, malware, credential theft, fraud, abuse, payment failure, chargebacks, reselling or sharing accounts or credentials, attempts to bypass approval or security controls, requests from a resource owner or administrator, legal orders, immediate security risk, or prolonged dormancy after notice.

Official Policy References

  • OpenAI API data controls
  • OpenAI Usage Policies
  • Claude Code data usage
  • Claude Code legal and compliance
  • Anthropic API and data retention
  • Gemini API Additional Terms
  • Alibaba Cloud Model Studio
  • Qwen Code terms and privacy

Last updated on

On this page