1. Scope
This Privacy Notice explains how Heho.ai handles personal data and workspace data when you use the service. This notice is effective as of March 7, 2026, and was last updated on September 21, 2026.
2. Product reality: private workspace
Heho.ai is currently a private workspace product. Lyrics and projects are private by default. Heho.ai currently does not provide a public lyrics publishing feature. Access is limited to the account owner and authorized workspace collaborators.
3. Person responsible for personal information protection
Under Quebec's Act respecting the protection of personal information in the private sector (Law 25), the person with the highest authority within the organization is responsible for personal information protection by default.
For questions, access requests, or complaints related to personal information, contact support@heho.ai.
4. Data we collect
Account and workspace data
- account identifiers (such as email and authentication IDs);
- organization and workspace identifiers;
- role and permission settings.
Billing and subscription data
- plan tier, billing status, and subscription metadata;
- transaction references from payment providers, including Stripe, Apple App Store, and Google Play;
- subscription management identifiers and entitlement metadata via RevenueCat.
Heho.ai does not intentionally store full payment card numbers. Payment processing is handled by Stripe for web purchases and by Apple or Google for mobile app purchases. RevenueCat is used to manage mobile subscription status and entitlements.
Product content data
- lyrics, project structures, and editing history;
- chat sessions and prompts used for writing assistance;
- imported or exported text artifacts;
- audio files you upload to the Audio Workbench and the audio it produces (see section 7.3).
Technical and usage data
- device and browser data, IP address, and request metadata;
- logs for errors, security events, and performance monitoring.
Cookies and browser storage
We use strictly necessary cookies for authentication, payment processing, and preference management. We do not use advertising, marketing, or behavioral tracking cookies. For a complete list of cookies and browser storage technologies used, see our Cookie Policy.
5. How we use data
We use data to:
- provide and operate core features;
- secure accounts and prevent abuse;
- process subscriptions and billing;
- provide support and respond to requests;
- maintain and improve quality, reliability, and safety.
Heho.ai may use your prompts, inputs, outputs, workspace content, and related usage data to operate, train, improve, and evaluate product features, including AI-enabled features, directly or through third-party AI providers. This does not apply to audio processed in the Audio Workbench, which is never used to train or improve models (see section 7.3).
If we materially change how we use data, we will update this Privacy Notice before those changes take effect.
6. Consent
Where required by law, we collect and use personal information based on your consent. Consent is obtained at or before the time of collection, and is specific to each stated purpose.
You may withdraw your consent at any time by contacting support@heho.ai or, for cookies, by using the cookie settings option in the site footer. Withdrawal of consent does not affect the lawfulness of processing performed before withdrawal. If you withdraw consent for data that is necessary to provide the service, some features may become unavailable.
7. Data sharing
We do not sell personal data. We share data only when necessary, including:
- service providers for hosting, authentication, billing, and infrastructure;
- legal disclosures when required by law or to protect rights, safety, and security;
- transaction-related disclosures during merger, acquisition, or asset transfer.
Service providers are expected to process data under contractual safeguards. This includes providers such as Clerk (authentication), Stripe, Apple, and Google (payments), RevenueCat (subscription management), Sentry (error monitoring), Cloudflare (bot protection on public tools and forms), and third-party AI infrastructure providers.
7.1 Third-party platform APIs used by our own publishing tools
Heho publishes its own marketing content (short videos and tips) to its own social media accounts through the official developer interfaces of those platforms: the YouTube API Services (Google), the Instagram, Facebook and Threads APIs (Meta), the TikTok Content Posting API, and the X API. These tools act only on accounts that Heho owns. They do not access, collect, or store data about Heho users or about other users of those platforms.
Our use of YouTube API Services is subject to the YouTube Terms of Service and to the Google Privacy Policy. Through these services we store, in our own systems, the authorization token that lets our scheduling tool upload videos to the Heho channel, together with the channel identifier and name, video titles and descriptions, and publishing status. We do not share this data with third parties and we do not use it for advertising. Access can be revoked at any time from the Google security settings page; revoking access deletes the stored token from our systems at the next synchronisation, and stored channel data is removed within 30 days.
The same applies to the Meta, TikTok and X authorizations: tokens and account identifiers for Heho-owned accounts only, stored to publish on schedule, revocable from each platform's connected-apps settings, and never shared.
7.2 Public tools that work without an account
Some tools on heho.ai, such as the Suno lyrics check, work without signing in. The text you paste into them (lyrics and style descriptions) is processed in your browser and a copy is stored on our servers, together with the result, the page you came from and the campaign parameters in the address, so that we can improve the checks and understand what people are trying to do. This text is never shown to other visitors, is not used to train models, and is not linked to a person unless you later create an account in the same browser session, in which case it becomes part of your project. Words or phrases you report through a tool's "report" form are reviewed by us and may be added, without any personal information, to the public word lists the tool uses. If you ask for a result by email, we store the address together with that result and send it once; if you also tick the box for new checks and lyric tips, we may send occasional emails until you unsubscribe, and every such email carries a way to do so.
7.3 Audio Workbench
The Audio Workbench processes audio you upload, with or without an account. We store your file only long enough to process it: it is deleted as soon as processing finishes, whether it succeeds or fails, and an upload that is never processed is deleted within about an hour. The processed audio is kept so you can listen to it and download it, for about 1 hour if you are not signed in and about 24 hours if you are, and is then deleted. A short record of each job (the file name, the settings you chose, its status and whose job it is) is kept for one hour longer than its result.
If you are not signed in, a random identifier stored in your browser tab keeps your results visible only to that tab, and your IP address is used to limit how many files can be processed per hour. These limits expire within an hour. Uploads from visitors who are not signed in first go through Cloudflare's bot check. Downloads by signed-in users are recorded with your plan's billing data, like any other use of credits.
Workbench audio is not reviewed by us, is never used to train or improve models, and is not shared with anyone other than the hosting and storage providers that run the service for us.
8. Retention and deletion
We retain data while your account is active and as needed to provide the service. Audio Workbench files are kept only for the much shorter periods described in section 7.3. You may request account deletion through the account deletion option in the mobile app settings or by contacting support@heho.ai. After account closure or deletion requests, we delete or de-identify data within reasonable operational timelines, except where retention is required for legal, security, fraud-prevention, or backup integrity purposes.
9. International data transfers
Heho.ai and its service providers may process data outside of Quebec and Canada, including in the United States. The following services may process data in the United States: Clerk (authentication), Stripe (payments), RevenueCat (subscription management), Sentry (error monitoring), Vercel (hosting), Cloudflare (bot protection), and third-party AI infrastructure providers.
Before transferring personal information outside Quebec, we conduct a privacy impact assessment as required by Law 25. Transfers are made only when the destination jurisdiction provides adequate protection, or when contractual safeguards are in place to provide an equivalent level of protection.
10. Security
We use technical and organizational safeguards designed to protect data, including encryption in transit, access controls, and monitoring. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Your rights
Depending on your location, you may have the following rights:
- Access: request a copy of the personal information we hold about you;
- Rectification: request correction of inaccurate or incomplete information;
- Deletion: request deletion of your personal information, subject to legal retention requirements;
- Portability: request a copy of your personal information in a structured, commonly used format;
- Withdrawal of consent: withdraw consent at any time, as described in Section 6;
- De-indexing: request that personal information indexed by a search engine cease to be disseminated, where applicable.
To exercise any of these rights, contact support@heho.ai. We may need to verify your identity before completing a request. We will respond within 30 days of receiving a complete request, or within the timeframe required by applicable law.
12. Children and sensitive data
Heho.ai is not intended for children under the age of majority in their jurisdiction. Do not upload sensitive personal data unless the service explicitly supports that use case.
13. Incident response
In the event of a confidentiality incident involving personal information that presents a risk of serious injury, we will notify the affected individuals and the relevant supervisory authority as required by applicable law, including Quebec's Commission d'acces a l'information where applicable.
14. Changes to this notice
We may update this Privacy Notice from time to time. If changes are material, we will provide notice in-app, by email, or both, with an updated effective date.
15. Contact
For privacy questions, access requests, complaints, or to exercise any of the rights described in this notice, contact support@heho.ai.