← back to HeyBio

Privacy Policy

Last updated: 10 August 2026

The short version

We store as little as possible. From you as a customer: your email address, an encrypted password and whatever you put on your page yourself. From your visitors: no IP address, no cookie and no profile. We never sell anything on, and we do not use your data for advertising.

What we store about you

Your email address and an encrypted version of your password (we never see the password itself), the content of your page (text, links, photos), your subscription and payment status, any domain order you place, and a log of actions that cost money or leave our systems. We need that log to investigate errors and abuse.

What we store about your visitors

Only anonymised click data: which button was clicked, the country (from the network layer, not from an IP address we store), and whether the click came from an in-app browser and was handed over to the real browser. No IP address, no cookie and no device profile ever reaches our database. To filter out double counts and bots we briefly create an irreversible, salted hash; it cannot be traced back to a person and it disappears on its own.

Cookies

Two functional cookies, no trackers. One keeps you signed in. One remembers who referred you if you arrived through another creator's referral link; it expires after ninety days. No cookie banner is needed for these, because they are strictly necessary for the service.

How long we keep things

Your account and page for as long as you are a customer, and for thirty days after you cancel. Click data is kept in detail for a maximum of ninety days; after that only totals remain. Invoices are kept for seven years, because tax law requires it. Password reset links expire after an hour and are cleaned up afterwards.

Who else sees it

We outsource parts of our technology, and those companies only see what they need: Railway (hosting and database, servers in the EU), Cloudflare (network layer and security), Vercel (domain registration and DNS), Resend (sending our emails) and Whop (payments). A data processing agreement is in place with each of them. Payment details such as your card number never reach us; they stay with the payment provider.

Security

Everything runs over an encrypted connection. In the database every customer is technically isolated from every other customer, and that is tested automatically on every change. Passwords are only ever stored encrypted. Our backups are encrypted and the key is not held by the hosting provider. If there is a data breach that puts you at risk despite all this, we report it to the Dutch Data Protection Authority within 72 hours and inform you directly.

Your rights

You can view, correct, take away or delete your data. Viewing and taking it with you works right away: your dashboard has an export button that hands you your entire page and all your images. Deletion happens when you cancel, or you can email us at support@heybio.io. We respond within thirty days. If you disagree with how we handle your data, you can file a complaint with the Dutch Data Protection Authority.

Contact

Questions about privacy, or a report about a page that breaks the rules: support@heybio.io.

See also our terms of service.