# Privacy on heedeo.com

This page covers heedeo.com, the website. For what the Heedeo product sends from your app, see https://heedeo.com/docs/security.md.

## What we collect

Only what you send in a call request, made through the form on the site or `POST /api/book`:

- your email
- your site, if you give it
- your note about what agents are doing on your site (the `pain` field), if you give it
- whether a person or an agent submitted the call request, and the agent's name if one was given or recognised from the user agent
- whether the request carried Web Bot Auth signature headers (presence only)
- the status of the call request (pending or confirmed) and timestamps: when it was created, when it was confirmed, and when an agent last submitted it

## Where it is stored

In a Cloudflare D1 database. The site runs on Cloudflare Workers, and Cloudflare processes requests to it as our host.

## What we use it for

Only to contact you about access to Heedeo.

## What we don't do

- No analytics scripts, no advertising trackers and no cookies set by the site.
- `GET /api/visitor` and `/api/decide` compute their answer and return it. They don't store what you send. To check signatures, `/api/visitor` keeps operators' public key directories and recently seen signatures in memory for a short time; see https://heedeo.com/docs/security.md.

## Agents submitting for you

A call request made by an agent is stored as pending until you confirm, by booking yourself or when we check with you.

## Removing your data

To have your call request deleted, ask us on the call or reply to the email we send you.

---

Docs index: https://heedeo.com/docs.md. How to verify our claims: https://heedeo.com/trust.md. Book a call: https://cal.com/heedeo/30min

Updated: 2026-10-02
