Heisenbug

Privacy Policy

Last updated: August 16, 2026

The short version. Heisenbug makes two products: Interview Questions (a website) and Vibe Meet (a desktop app). Both use one Heisenbug account, which is a Google sign-in. We collect the minimum needed to run each product: your Google name and email, your progress and purchases, and — for paid Vibe Meet plans — a usage ledger for the AI credits you spend. We do not sell personal data, we do not run advertising, and we do not store your meeting audio, transcripts, or the questions you ask an AI. Payments are handled by Paddle. Anything you make with Vibe Meet stays in a folder on your own computer.
  1. Who we are
  2. What this policy covers
  3. Your Heisenbug account
  4. The websites
  5. Interview Questions
  6. Vibe Meet
  7. Payments
  8. Companies that process data for us
  9. How long we keep data, and deletion
  10. Your rights
  11. Security
  12. Children
  13. Changes to this policy
  14. Contact

1. Who we are

Heisenbug is an independent software business established in Brazil and operated by its owner as a sole proprietor. For the purposes of data-protection law (including Brazil's LGPD and, where it applies, the EU/UK GDPR) Heisenbug is the controller of the personal data described here. You can reach us at [email protected].

2. What this policy covers

This one policy covers everything Heisenbug runs:

Where a section applies to only one product, it says so. Everything else applies to all of them.

3. Your Heisenbug account

Signing in is optional for browsing the websites and for the free tier of Vibe Meet. You need an account to save progress in Interview Questions, to buy anything, and to use a paid Vibe Meet plan.

The only sign-in method is Google. When you sign in, Google sends us your name, your email address, your profile-photo URL and a Google account identifier. We never see your Google password. One Google account gives you one Heisenbug account, valid across all our products, so a purchase made on one site is recognised on the others.

Accounts are stored in Firebase Authentication, a Google Cloud service. Product data linked to your account (sections 5 and 6) is stored in Firebase's Firestore database, also on Google Cloud, in the United States.

4. The websites

The pages on www.theheisenbug.com and vibe-meet.theheisenbug.com are static pages. They run no analytics, no advertising and no tracking scripts. Two things do leave your browser when you open them:

The Interview Questions web app additionally uses Firebase Analytics — see section 5.3.

5. Interview Questions

5.1 Data we store for your account

5.2 Ask AI

When you use "Ask AI", the text you selected, a small piece of surrounding context, and your question are sent through our server to DeepSeek, an AI provider based in China, to produce the answer. Our server does not keep the question or the answer; it only records that a request happened, for the daily limit and for error logs. DeepSeek processes the request under its own API terms. Do not paste personal data about other people into Ask AI.

5.3 Analytics

The web app uses Firebase Analytics (Google) to collect aggregated usage statistics — which pages and features are used, in which country, on which kind of device. We use this to decide what to improve. It is not used for advertising, and we do not combine it with your name or email.

6. Vibe Meet

Vibe Meet is a desktop app. Its main job — capturing your microphone and system audio, producing live captions and suggestions, and saving a recording, transcript, report and notes — happens on your computer. What leaves your computer depends on how you use it, so this section is split by that.

6.1 What always stays on your computer

The app contains no telemetry, no analytics SDK and no crash reporter. It makes two kinds of maintenance requests: it checks GitHub for new releases, and, if you enable an on-device engine, it downloads that engine's model files from Hugging Face. Both requests expose your IP address to those services, nothing more.

6.2 The free tier, with your own keys or on-device engines

In this mode there is no Heisenbug account and nothing is sent to us at all. Audio goes directly from the app to the caption provider you configured — OpenAI, Speechmatics or Groq — under your own key, or nowhere if you use the on-device engine. Caption text goes directly to the AI provider you configured (for example DeepSeek, OpenAI or Groq) under your own key. Those providers process the data under the terms of your own account with them.

6.3 Paid plans (Pro and Pro AI)

Paid plans need a Heisenbug account. For a paid account we store:

6.4 How included AI credits are processed (Pro AI)

When you spend included credits instead of your own keys, the requests go to the same kind of providers, but under Heisenbug's provider accounts:

The providers we use for included credits are OpenAI, Groq, DeepSeek and Speechmatics. They process the content under their API terms for business customers. Note that DeepSeek is based in China. Which provider is used for a given feature is shown in the app's settings; you can always switch a feature to your own key or to an on-device engine.

6.5 Recording other people

Vibe Meet can record and transcribe conversations. When you record other people, you are the one processing their personal data, and the laws on recording and consent where you and they are located apply to you. Heisenbug does not receive those recordings and cannot control how you use them. Recording is optional; captions and suggestions work without it.

7. Payments

Purchases are made through Paddle (Paddle.com Market Ltd, UK, or Paddle.com Inc., US, depending on your location), which acts as the merchant of record. Paddle collects your payment details, billing address and tax information and processes the payment. We never see your card number or bank details. Paddle sends us your name, email address, country, the product bought, the amount, and the transaction and subscription status, which we store so that we can unlock what you paid for and handle support and refunds. Paddle's own privacy policy is at paddle.com/legal/privacy.

Interview Questions purchases made before Paddle was introduced were processed by Stripe. For those purchases Stripe holds the payment record under its own privacy policy, and we hold the confirmation that the purchase succeeded.

8. Companies that process data for us

CompanyWhat forProducts
Google (Firebase and Google Cloud)Sign-in, database, file storage, hosting, cloud functions, analytics (Interview Questions only)All
Google FontsWeb font on the static pagesWebsites
PaddleMerchant of record: checkout, invoices, tax, refunds, customer portalAll
StripePayment records for Interview Questions purchases made before PaddleInterview Questions
DeepSeekAI answers for "Ask AI"; AI provider for included creditsInterview Questions, Vibe Meet
OpenAI, GroqCaptions and AI features for included creditsVibe Meet
SpeechmaticsLive captions for included creditsVibe Meet
GitHubHosting app releases; the app checks it for updatesVibe Meet
Hugging FaceHosting the model files that on-device engines downloadVibe Meet

Providers you configure yourself with your own keys are not our processors — you have a direct relationship with them.

Some of these companies are outside Brazil and outside the EU/UK (mainly in the United States, and DeepSeek in China). Where a transfer needs a legal basis, we rely on the provider's standard contractual terms for business customers.

9. How long we keep data, and deletion

10. Your rights

Under the LGPD, the GDPR and similar laws you can ask us to: tell you what personal data we hold about you; correct it; delete it; give you a copy in a portable format; restrict or object to some uses; and withdraw consent where processing is based on consent. Deleting your account (section 9) covers most of this by itself. For anything else, email [email protected] from the address on your account. You also have the right to complain to your data-protection authority (in Brazil, the ANPD).

11. Security

Data in Firestore is protected by rules that let each user read and write only their own documents; server-side operations run with separate credentials. Premium content is served through short-lived signed links. API keys you enter in Vibe Meet live in your OS credential store. All traffic uses HTTPS. No system is perfectly secure; if we learn of a breach affecting you, we will tell you.

12. Children

Our products are not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child has created an account, contact us and we will delete it.

13. Changes to this policy

When we change this policy we update the date at the top. For changes that matter — new data, new purposes, new processors — we will also tell signed-in users inside the product or by email.

14. Contact

[email protected]