Privacy Policy
Last updated: August 16, 2026
- Who we are
- What this policy covers
- Your Heisenbug account
- The websites
- Interview Questions
- Vibe Meet
- Payments
- Companies that process data for us
- How long we keep data, and deletion
- Your rights
- Security
- Children
- Changes to this policy
- Contact
1. Who we are
Heisenbug is an independent software business established in Brazil and operated by its owner as a sole proprietor. For the purposes of data-protection law (including Brazil's LGPD and, where it applies, the EU/UK GDPR) Heisenbug is the controller of the personal data described here. You can reach us at [email protected].
2. What this policy covers
This one policy covers everything Heisenbug runs:
- the websites
www.theheisenbug.com,vibe-meet.theheisenbug.comandinterview-questions.theheisenbug.com; - Interview Questions, the interview-preparation web app at
interview-questions.theheisenbug.com; - Vibe Meet, the desktop meeting-copilot app for Windows, macOS and Linux (its installer and settings folder may still show the internal name "MeetCopilot"), and the account service behind its paid plans.
Where a section applies to only one product, it says so. Everything else applies to all of them.
3. Your Heisenbug account
Signing in is optional for browsing the websites and for the free tier of Vibe Meet. You need an account to save progress in Interview Questions, to buy anything, and to use a paid Vibe Meet plan.
The only sign-in method is Google. When you sign in, Google sends us your name, your email address, your profile-photo URL and a Google account identifier. We never see your Google password. One Google account gives you one Heisenbug account, valid across all our products, so a purchase made on one site is recognised on the others.
Accounts are stored in Firebase Authentication, a Google Cloud service. Product data linked to your account (sections 5 and 6) is stored in Firebase's Firestore database, also on Google Cloud, in the United States.
4. The websites
The pages on www.theheisenbug.com and vibe-meet.theheisenbug.com are static
pages. They run no analytics, no advertising and no tracking scripts. Two things do
leave your browser when you open them:
- They are served by Firebase Hosting (Google), which keeps ordinary web-server logs (IP address, time, page requested, browser type) for security and operations.
- They load the Inter font from Google Fonts, which means Google's font servers receive your IP address and browser type.
The Interview Questions web app additionally uses Firebase Analytics — see section 5.3.
5. Interview Questions
5.1 Data we store for your account
- Which questions you have marked as read, and which learning chapters you have finished.
- The text highlights and notes you create on answers and chapters.
- Whether you have bought premium access, and the record of that purchase (see section 7).
- A daily counter of how many "Ask AI" questions you have asked, used only to apply the daily limits of your plan.
5.2 Ask AI
When you use "Ask AI", the text you selected, a small piece of surrounding context, and your question are sent through our server to DeepSeek, an AI provider based in China, to produce the answer. Our server does not keep the question or the answer; it only records that a request happened, for the daily limit and for error logs. DeepSeek processes the request under its own API terms. Do not paste personal data about other people into Ask AI.
5.3 Analytics
The web app uses Firebase Analytics (Google) to collect aggregated usage statistics — which pages and features are used, in which country, on which kind of device. We use this to decide what to improve. It is not used for advertising, and we do not combine it with your name or email.
6. Vibe Meet
Vibe Meet is a desktop app. Its main job — capturing your microphone and system audio, producing live captions and suggestions, and saving a recording, transcript, report and notes — happens on your computer. What leaves your computer depends on how you use it, so this section is split by that.
6.1 What always stays on your computer
- Recordings, transcripts, reports and notes. They are written only to the folder you chose. We never receive or upload them. Deleting the folder deletes them.
- Your own API keys (if you use "bring your own keys"). They are stored in your operating system's credential store — Windows Credential Manager, macOS Keychain, or libsecret on Linux — and never sent to us.
- Settings and your local cost ledger.
The app contains no telemetry, no analytics SDK and no crash reporter. It makes two kinds of maintenance requests: it checks GitHub for new releases, and, if you enable an on-device engine, it downloads that engine's model files from Hugging Face. Both requests expose your IP address to those services, nothing more.
6.2 The free tier, with your own keys or on-device engines
In this mode there is no Heisenbug account and nothing is sent to us at all. Audio goes directly from the app to the caption provider you configured — OpenAI, Speechmatics or Groq — under your own key, or nowhere if you use the on-device engine. Caption text goes directly to the AI provider you configured (for example DeepSeek, OpenAI or Groq) under your own key. Those providers process the data under the terms of your own account with them.
6.3 Paid plans (Pro and Pro AI)
Paid plans need a Heisenbug account. For a paid account we store:
- your account identity (section 3);
- your plan, its status and dates, and your Paddle customer identifier (section 7);
- a credits ledger: every credit grant (from your plan or a top-up) and every debit, with the amount, the time, the AI provider and model used, the number of tokens or minutes billed, and the identifier of the device that made the request. This is what makes your balance correct and auditable. It never contains the content of a meeting;
- your devices: a random identifier that our server creates the first time the app signs in on a computer, and the date it was last seen. It is a random number, not a hardware fingerprint, and it lets us limit how many computers one paid account uses at once;
- a record of each live-caption session started with included credits (provider, time, duration), used to enforce concurrency limits and to bill by the minute. Not the audio.
6.4 How included AI credits are processed (Pro AI)
When you spend included credits instead of your own keys, the requests go to the same kind of providers, but under Heisenbug's provider accounts:
- Audio still goes directly from the app to the caption provider. Our server only issues a short-lived key (about ten minutes) for that session. Audio never passes through, and is never stored on, our servers.
- Text and images — caption text used for suggestions and reports, and any screenshot you deliberately attach to an "Ask" — pass through our proxy on their way to the AI provider. The proxy forwards them and returns the answer. It does not store the content; it records only the usage figures needed for the ledger.
The providers we use for included credits are OpenAI, Groq, DeepSeek and Speechmatics. They process the content under their API terms for business customers. Note that DeepSeek is based in China. Which provider is used for a given feature is shown in the app's settings; you can always switch a feature to your own key or to an on-device engine.
6.5 Recording other people
Vibe Meet can record and transcribe conversations. When you record other people, you are the one processing their personal data, and the laws on recording and consent where you and they are located apply to you. Heisenbug does not receive those recordings and cannot control how you use them. Recording is optional; captions and suggestions work without it.
7. Payments
Purchases are made through Paddle (Paddle.com Market Ltd, UK, or Paddle.com Inc., US, depending on your location), which acts as the merchant of record. Paddle collects your payment details, billing address and tax information and processes the payment. We never see your card number or bank details. Paddle sends us your name, email address, country, the product bought, the amount, and the transaction and subscription status, which we store so that we can unlock what you paid for and handle support and refunds. Paddle's own privacy policy is at paddle.com/legal/privacy.
Interview Questions purchases made before Paddle was introduced were processed by Stripe. For those purchases Stripe holds the payment record under its own privacy policy, and we hold the confirmation that the purchase succeeded.
8. Companies that process data for us
| Company | What for | Products |
|---|---|---|
| Google (Firebase and Google Cloud) | Sign-in, database, file storage, hosting, cloud functions, analytics (Interview Questions only) | All |
| Google Fonts | Web font on the static pages | Websites |
| Paddle | Merchant of record: checkout, invoices, tax, refunds, customer portal | All |
| Stripe | Payment records for Interview Questions purchases made before Paddle | Interview Questions |
| DeepSeek | AI answers for "Ask AI"; AI provider for included credits | Interview Questions, Vibe Meet |
| OpenAI, Groq | Captions and AI features for included credits | Vibe Meet |
| Speechmatics | Live captions for included credits | Vibe Meet |
| GitHub | Hosting app releases; the app checks it for updates | Vibe Meet |
| Hugging Face | Hosting the model files that on-device engines download | Vibe Meet |
Providers you configure yourself with your own keys are not our processors — you have a direct relationship with them.
Some of these companies are outside Brazil and outside the EU/UK (mainly in the United States, and DeepSeek in China). Where a transfer needs a legal basis, we rely on the provider's standard contractual terms for business customers.
9. How long we keep data, and deletion
- Account and product data are kept for as long as your account exists.
- Deleting your account. In Vibe Meet you can delete your account from Settings; for Interview Questions, or for everything at once, email us. Deletion removes your sign-in identity, your progress and highlights, your devices, and your remaining credits. Files on your own computer are not touched.
- Financial records. Records of purchases, refunds and the credit ledger entries that justify them are kept for as long as tax and accounting law requires, in a form that no longer identifies you where that is possible.
- Server logs are kept for a short period (weeks) for security and debugging.
10. Your rights
Under the LGPD, the GDPR and similar laws you can ask us to: tell you what personal data we hold about you; correct it; delete it; give you a copy in a portable format; restrict or object to some uses; and withdraw consent where processing is based on consent. Deleting your account (section 9) covers most of this by itself. For anything else, email [email protected] from the address on your account. You also have the right to complain to your data-protection authority (in Brazil, the ANPD).
11. Security
Data in Firestore is protected by rules that let each user read and write only their own documents; server-side operations run with separate credentials. Premium content is served through short-lived signed links. API keys you enter in Vibe Meet live in your OS credential store. All traffic uses HTTPS. No system is perfectly secure; if we learn of a breach affecting you, we will tell you.
12. Children
Our products are not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child has created an account, contact us and we will delete it.
13. Changes to this policy
When we change this policy we update the date at the top. For changes that matter — new data, new purposes, new processors — we will also tell signed-in users inside the product or by email.