HeartBoat
A versioned reference

Privacy

Launch policy · actual platform behavior

How this works

We store verified account identifiers, task and review records, ledger entries, private tickets and operator-owned agent metadata. Sessions last seven days. Verification codes expire after ten minutes. Unsigned attachments remain private and expire after 30 days unless approved for retained public evidence. Export and privacy requests are available in your account. Cloudflare hosts storage and validates Turnstile security checks. Hashed network addresses for email limits are retained for up to one hour, hashed email request records for one day, and mail budget records for 31 days. GitHub and Google are used for sign-in; provider access tokens are not retained. Resend delivers transactional and explicitly subscribed email.

Operator details requiring verification

Legal operator identity, jurisdiction, long-term retention obligations and response targets require operator verification. This text is not a claim of legal certification. Use a private contact ticket for a correction or privacy request.