Last updated: May 2026 · UK GDPR · EU GDPR · CCPA · DSA · Online Safety Act compliant · Common sense compliant
Classification Policy · Acceptable Use · Cookies · GDPR · CCPA · Contact
We don't collect your personal data. We don't want it. We don't have a use for it. We don't have a shady data broker waiting eagerly in the shadows. We're an intelligence map, not an intelligence agency.
The map is public. You can watch geopolitical chaos unfold in real time without us knowing a single thing about you. Your IP address passes through our server to fetch data, then we promptly forget it existed. This is how the internet used to work before everyone got greedy.
Absolutely nothing. Zero. The map works without an account. When your browser requests data from our API, our server processes the HTTP request, sends you the data, and immediately moves on with its life. No logs are kept. Period. No access logs, no error logs, no IP addresses. Your request is processed and forgotten immediately.
We don't use Google Analytics. We don't use Facebook Pixel. We don't use any third-party tracking scripts. We use a map library (MapLibre) and some fonts (Google Fonts — yes, your browser connects to Google for those; sorry, they are self-hosted — no requests are made to Google's servers). That's it.
An account is required to use the vertical dashboards (Cyber, Aviation, Maritime, Physical Security, Energy) and chat features; the public OSINT map works without one. When you sign up we store:
a*****@example.com). Never shared, sold, or used for marketing without your explicit opt-in.•••• 1234). Used solely as a recovery fallback. We do not SMS you for marketing.Every account starts with an automatic 30-day free trial. In addition to the data above, we also store:
professional:auto:ISC2, professional:asisonline-cert-12345, journalist:approved), verified date, expiry. Renewed annually.professional_verifications table. Retained while the discount is active plus 12 months after for audit; deleted on account deletion.We retain payment records for 6 years as required by UK tax law (HMRC). This is a legal obligation we cannot override. After 6 years, records are permanently deleted.
All system mail (verification, receipts, trial-expiry notices, password reset) is sent From: [email protected] with Reply-To: [email protected]. The footer of every message states the same. [email protected] is a monitored mailbox; noreply@ discards replies. Outbound transit goes via a UK-/EU-resident commodity mail provider over TLS.
Zero tracking cookies. Zero advertising cookies. Zero third-party cookies. Everything below is first-party and strictly necessary for the site to work — no consent banner, because there's nothing to consent to that you weren't already consenting to by clicking "Log in".
| Name | What it holds | Lifetime | Purpose |
|---|---|---|---|
hl_token |
Signed session token (JWT) | 15 minutes | Authenticated API calls. HttpOnly, Secure, SameSite=Lax — your browser sends it on requests to our API and JavaScript on the page can't read it. |
hl_refresh |
Refresh token (opaque) | 30 days | Refreshes hl_token when it expires so you don't get logged out every 15 minutes. Scoped to /v1/auth/ — never sent on any other endpoint. Same HttpOnly protections. |
Both cookies are cleared by your browser when you press "Log out" — our logout endpoint expires them server-side.
Technically not cookies, but the lawyers want them listed:
hl_lang (localStorage) — your UI language preference. Persists across visits.hl_theme (localStorage) — light or dark mode. Persists across visits.auth_return_to (sessionStorage) — the page you were on when you clicked "Sign in", so we can send you back there after login. Cleared once consumed.pending_promo (sessionStorage) — a promo code from a /r/{code} link, redeemed after you sign in. Cleared once consumed.None of these leave your device. None are read by third parties.
If you've used other websites recently, you've probably accepted 47 cookie notices for things like "personalisation partners" and "legitimate interest." We are not that. We are aggressively boring when it comes to cookies.
HyveHeim is operated from the United Kingdom and complies with both the UK General Data Protection Regulation (UK GDPR, as retained under the Data Protection Act 2018) and the EU GDPR for European users. Under both regulations, you have the following rights:
| Data | Lawful Basis | Retention |
|---|---|---|
| Username + password hash + recovery hash | Contract (Art. 6(1)(b)) | Until account deleted |
| Email (optional) | Consent (Art. 6(1)(a)) + Legitimate interest (Art. 6(1)(f)) for verification/recovery | Until account deleted or consent withdrawn |
| Phone (optional) | Consent (Art. 6(1)(a)) | Until account deleted or consent withdrawn |
| Company name (optional) | Consent (Art. 6(1)(a)) | Until account deleted |
| Trial state (start / end / verticals) | Contract (Art. 6(1)(b)) | Until account deleted |
| Discount records (percent, reason, expiry) | Contract (Art. 6(1)(b)) | Until account deleted |
| Professional-verification submissions | Contract (Art. 6(1)(b)) + Legitimate interest (audit) | Discount duration + 12 months |
| Email-verification tokens | Contract (Art. 6(1)(b)) | 24h (Redis), one-shot |
| Stripe customer ID + payment records | Contract (Art. 6(1)(b)) + Legal obligation (Art. 6(1)(c)) | 6 years (UK tax law) |
| Encrypted messages | Contract (Art. 6(1)(b)) | Max 48 hours (relay only) |
| Nginx attacker logs (4xx / 5xx only) | Legitimate interest (Art. 6(1)(f)) — defending against probes | 14 days, rotated |
| PIN hash (app lock) | Contract (Art. 6(1)(b)) | Until disabled |
Your data is processed on infrastructure within Switzerland and the EU/EEA, plus two relay-only points that hold no personal data. Switzerland has an EU adequacy decision; the remainder are in the EU/EEA. No additional cross-border safeguards (such as Standard Contractual Clauses) are required for these transfers.
Payment data is processed by Stripe, Inc. (US) under their own privacy policy and EU-US Data Privacy Framework certification.
AI processing of event data (classification, geocoding, summarisation) runs primarily on self-hosted models on our own hardware in the EU — the data does not leave our infrastructure for these tasks. A small fraction of generative work falls back to an EU-based commercial LLM API when local capacity is exceeded. Only event titles and source headlines are sent to either path — never user data, never DM content.
Data controller: HyveHeim, United Kingdom. ICO registration number: C1896848. For data protection enquiries, use the contact form.
Supervisory authority: If you are unsatisfied with our response, you may complain to the Information Commissioner's Office (ICO) at ico.org.uk (UK), or your local EU/EEA data protection authority.
We do not have a Data Protection Officer because we are not a large organisation processing sensitive data at scale. We do have a person who reads privacy-related messages and takes them seriously. They are the same person. They are also writing this privacy policy. Hello.
California residents have rights under the California Consumer Privacy Act. Since we don't sell personal information (we have no personal information to sell), most of the CCPA is not directly applicable. Specifically:
HyveHeim integrates with the following third-party services. Here's the honest rundown:
support@, noreply@, etc. into our mailbox provider. The router relays the message; it does not retain content.That is a comprehensive and complete list of third-party data flows. We are not hiding any others in footnotes.
/admin, /.env, /wp-login, etc.) are logged for security purposes only, kept for 14 days, then rotated out. Successful 2xx/3xx requests are never logged. This was the deliberate result of a security audit — defending the platform against botnet floods requires knowing what they're trying.We take security seriously (we built an intel platform; ignoring our own security would be a bad look).
SELECT * FROM users WHERE password = 'hunter2' would help us, and we have a sense of humour about that.a*****@example.com, •••• 1234); the full values never come back from any client-facing API.If you're a security researcher who just read all that and got the urge to test it: please do. Coordinated disclosure via the contact form, we'll fix it, we'll credit you, and we won't be weird about it. Black-hatting us is rude.
If you discover a security vulnerability, please email us before publishing it. We will take it seriously, fix it promptly, and credit you if you'd like.
If we materially change this policy (i.e., start collecting more data), we will notify account holders via in-app notification or website announcement. Changes that reduce data collection require no notification because they are good news.
We are not going to add 14 pages of "we may share your data with trusted partners" boilerplate in the future. If that ever happens, it means this project has been acquired by someone terrible and you should leave immediately.
Privacy questions, data requests, or if you just want to yell at us about GDPR:
mail Contact UsThe legal stuff. We've tried to make it human-readable.
HyveHeim provides a real-time global intelligence map aggregating publicly available open-source information. The service is provided for informational and situational awareness purposes only.
HyveHeim is not:
In short: we're showing you what people on the internet are saying about events. Treat it like a very sophisticated news aggregator, not like ground truth. Always verify from primary sources before making decisions.
You may use HyveHeim for:
You may not use HyveHeim to:
Mímir is the discussion forum attached to the OSINT platform. It's for serious, accountable analysis of public-domain intelligence signals. It is not, and will never become:
If a post would be at home on Instagram, Facebook, TikTok, X, Truth Social, Reddit, or your group chat — post it there. Mímir is for the work that wouldn't fit on any of those.
You post under a forum handle you choose. The platform doesn't blind you (this isn't anonymous chat) — your handle persists, your post history is visible, and operators can see your underlying account. That accountability is the point: it raises the floor on what gets posted.
Disagree without contempt. Cite sources. Quote-reply rather than misrepresent. Flag rather than feud.
Operator action (mute / shadowban / ban) for:
Bans are appealable: contact form. A different operator handles your appeal. We respond within 7 days.
THE SERVICE IS PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. WE DO NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, OR THAT EVENT DATA WILL BE ACCURATE OR COMPLETE. THE SERVICE IS AGGREGATED FROM PUBLICLY AVAILABLE SOURCES WHICH WE DO NOT CONTROL.
(Yes, we have to shout this bit. Lawyers insist.)
TO THE MAXIMUM EXTENT PERMITTED BY LAW, HYVEHEIM SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES ARISING FROM YOUR USE OF OR INABILITY TO USE THE SERVICE.
If you make a bad decision based on something you saw on our map, that is, respectfully, on you.
We reserve the right to terminate accounts that violate these terms. You can delete your account at any time from the profile settings.
These terms are governed by and construed in accordance with the laws of England and Wales. Any disputes arising from or in connection with these terms shall be subject to the exclusive jurisdiction of the courts of England and Wales.
If you're accessing the service from outside the UK, you're still bound by these terms — but we won't chase you across international borders for using a map wrong. We're reasonable people.
You must be at least 16 years old to create an account on HyveHeim. This is the minimum age for data processing consent under the UK GDPR (via the Age Appropriate Design Code). If you're under 16, you may use the public map without an account — no data is collected, so no age restriction applies to anonymous use.
The HyveHeim platform, including its code, design, branding, and original content, is the property of HyveHeim. OSINT data aggregated from third-party sources remains the property of those sources and is displayed under fair use / fair dealing provisions for the purposes of news reporting, research, and public interest.
User-submitted reports and tips are granted to HyveHeim under a perpetual, royalty-free licence for display on the platform. You retain ownership of your submissions but grant us the right to use them. You can request removal at any time via contact.
You agree to indemnify and hold HyveHeim harmless from any claims, damages, or expenses arising from your violation of these terms or your misuse of the service. In plain English: if you do something illegal with our platform, that's on you, not us.
If any provision of these terms is found to be unenforceable by a court of competent jurisdiction, the remaining provisions continue in full force. We wrote these terms in good faith — if a court disagrees with one clause, the rest still stand.
These terms, together with our Privacy Policy and Fair Use Policy, constitute the entire agreement between you and HyveHeim. No prior conversations, promises, or side agreements override what's written here.
We'll notify account holders via in-app notification or website announcement of material changes to these terms. Your continued use of the service after changes constitutes acceptance. We will provide at least 30 days' notice for any changes that materially affect your rights.
HyveHeim is operated from the United Kingdom. For legal correspondence or formal notices, please use the contact form.
These terms were last updated in March 2026.