Privacy

Privacy Policy

Last updated: 20 July 2026

This policy describes how the Hedy website (hedy.one) and the Hedy product handle data. It reflects a core architectural fact: the Hedy product is deployed on your own infrastructure, so operational data does not flow to us.

The product

  • Self-hosted. Hedy runs in your environment (your VPC, or fully air-gapped). Your knowledge base, conversation memory, audit logs and token metering are stored in your own database on your own machines.
  • No sub-processors. Because the product runs on your infrastructure, your operational data is not transmitted to Hedy or to any third party on our behalf. If you configure external model providers, your own agreements with those providers govern that traffic; air-gapped deployments with local models make no external calls at all.
  • Secrets. Credentials are injected through your deployment environment and are never transmitted to us.
  • No training on your data. We do not collect your operational data, so we cannot and do not train on it.

This website

  • hedy.one is a static marketing site. It does not set advertising cookies.
  • If you email us, we process your message and contact details solely to respond and to discuss a possible engagement.

Your rights

For any question about data we hold from your correspondence, or to request its deletion, contact hello@hedy.one. Enterprise customers can request a Data Processing Agreement as part of a deployment.