Security isn’t a feature. It’s the foundation.
You’re uploading personal footage — your life, your work, your face. We take that seriously. Here’s exactly what we do with it.
Four things we promise, with no asterisks.
Your footage is never used to train AI
The videos you upload are used exclusively to create your content. They are never shared, never used to train our models, never sold to third parties. When you delete a clip, it’s gone. Not archived. Not anonymized. Gone.
End-to-end encryption
Every upload is encrypted in transit using TLS 1.3 and stored at rest with AES-256. The same encryption standard banks use for wire transfers. Your footage is never sitting on a server unprotected.
You own everything
The content HEVEA Pulse creates from your footage belongs entirely to you. We claim no rights whatsoever — not to the Reels, not to the captions, not to the story arcs, not to a single frame we helped you edit. It’s yours.
Delete anytime, permanently
Delete a clip or your entire account — it’s immediate and permanent. We don’t keep backups of deleted content beyond 24 hours. There’s no “recovery period” that secretly means we’re still holding your data.
Technical specifications.
| Specification | Detail |
|---|---|
| Transport encryption | TLS 1.3 |
| Storage encryption | AES-256 |
| Compliance | GDPR SOC 2 Type II (in progress) |
| Primary data center | European Union |
| Asia-Pacific region | Singapore |
| Footage retention after processing | 30 days — unless you save to your library |
| Retention after account deletion | 24 hours, then permanently purged |
| Third-party data sharing | None. Zero. |
| AI training use of your footage | Never. |
Who can see your data.
Default: nobody.
Your footage, your account data, your generated content — none of it is visible to anyone at HEVEA Pulse by default. Not to engineers, not to support staff, not to anyone.
Support access: explicit, logged, revocable.
If you contact us about a technical issue and we need to look at something in your account, we’ll ask for your explicit permission before accessing anything. Every access is logged with a timestamp and reason. You can revoke consent at any time. We will never access your account without your knowledge.
No marketing use of your data.
We don’t use your account behavior, your footage metadata, or your usage patterns to build advertising profiles. We don’t sell data. We don’t share it. The business model is the subscription — not you.
Things we can’t promise.
No system is 100% breach-proof.
We’re not going to claim that a breach is impossible. Any company that makes that claim is lying to you. What we can tell you is that we’ve built multiple layers of protection specifically designed to minimize the impact of any single point of failure.
If a breach were to occur, we commit to: notifying affected users within 72 hours, publishing a full post-mortem, and cooperating with regulators as required under GDPR. We don’t sweep incidents under the rug.
We also commit to not collecting more data than we need in the first place — which means there’s less to breach. The simplest security architecture is one where you never store what you don’t have to.
Found a vulnerability? Tell us.
If you discover a security issue, we want to know. Write to security@heveapulse.com with as much detail as you can. We respond within 48 hours.
We take responsible disclosure seriously. Significant findings that help us protect our users will be rewarded — reach out and we’ll discuss specifics.
We don’t have a formal bug bounty program yet — but we’re building toward one. In the meantime, we handle this case by case.
Read the details, or get in touch.
