Privacy Policy & Terms

Last updated: May 2026  ·  UK GDPR · EU GDPR · CCPA · DSA · Online Safety Act compliant  ·  Common sense compliant

Classification Policy · Acceptable Use · Cookies · GDPR · CCPA · Contact

🍵 The honest summary (before the boring legal stuff)

We don't collect your personal data. We don't want it. We don't have a use for it. We don't have a shady data broker waiting eagerly in the shadows. We're an intelligence map, not an intelligence agency.

The map is public. You can watch geopolitical chaos unfold in real time without us knowing a single thing about you. Your IP address passes through our server to fetch data, then we promptly forget it existed. This is how the internet used to work before everyone got greedy.

1. Data We Collect

If you don't have an account (most people)

Absolutely nothing. Zero. The map works without an account. When your browser requests data from our API, our server processes the HTTP request, sends you the data, and immediately moves on with its life. No logs are kept. Period. No access logs, no error logs, no IP addresses. Your request is processed and forgotten immediately.

We don't use Google Analytics. We don't use Facebook Pixel. We don't use any third-party tracking scripts. We use a map library (MapLibre) and some fonts (Google Fonts — yes, your browser connects to Google for those; sorry, they are self-hosted — no requests are made to Google's servers). That's it.

If you create a free account

An account is required to use the vertical dashboards (Cyber, Aviation, Maritime, Physical Security, Energy) and chat features; the public OSINT map works without one. When you sign up we store:

If you start a free trial or subscribe to a paid plan

Every account starts with an automatic 30-day free trial. In addition to the data above, we also store:

We retain payment records for 6 years as required by UK tax law (HMRC). This is a legal obligation we cannot override. After 6 years, records are permanently deleted.

Outbound email — who sends and where replies go

All system mail (verification, receipts, trial-expiry notices, password reset) is sent From: [email protected] with Reply-To: [email protected]. The footer of every message states the same. [email protected] is a monitored mailbox; noreply@ discards replies. Outbound transit goes via a UK-/EU-resident commodity mail provider over TLS.

What we emphatically do NOT collect

2. Cookies & browser storage

Zero tracking cookies. Zero advertising cookies. Zero third-party cookies. Everything below is first-party and strictly necessary for the site to work — no consent banner, because there's nothing to consent to that you weren't already consenting to by clicking "Log in".

Cookies we set

NameWhat it holdsLifetimePurpose
hl_token Signed session token (JWT) 15 minutes Authenticated API calls. HttpOnly, Secure, SameSite=Lax — your browser sends it on requests to our API and JavaScript on the page can't read it.
hl_refresh Refresh token (opaque) 30 days Refreshes hl_token when it expires so you don't get logged out every 15 minutes. Scoped to /v1/auth/ — never sent on any other endpoint. Same HttpOnly protections.

Both cookies are cleared by your browser when you press "Log out" — our logout endpoint expires them server-side.

localStorage / sessionStorage

Technically not cookies, but the lawyers want them listed:

None of these leave your device. None are read by third parties.

If you've used other websites recently, you've probably accepted 47 cookie notices for things like "personalisation partners" and "legitimate interest." We are not that. We are aggressively boring when it comes to cookies.

3. UK GDPR & EU GDPR

HyveHeim is operated from the United Kingdom and complies with both the UK General Data Protection Regulation (UK GDPR, as retained under the Data Protection Act 2018) and the EU GDPR for European users. Under both regulations, you have the following rights:

Lawful Basis for Processing

Data Lawful Basis Retention
Username + password hash + recovery hash Contract (Art. 6(1)(b)) Until account deleted
Email (optional) Consent (Art. 6(1)(a)) + Legitimate interest (Art. 6(1)(f)) for verification/recovery Until account deleted or consent withdrawn
Phone (optional) Consent (Art. 6(1)(a)) Until account deleted or consent withdrawn
Company name (optional) Consent (Art. 6(1)(a)) Until account deleted
Trial state (start / end / verticals) Contract (Art. 6(1)(b)) Until account deleted
Discount records (percent, reason, expiry) Contract (Art. 6(1)(b)) Until account deleted
Professional-verification submissions Contract (Art. 6(1)(b)) + Legitimate interest (audit) Discount duration + 12 months
Email-verification tokens Contract (Art. 6(1)(b)) 24h (Redis), one-shot
Stripe customer ID + payment records Contract (Art. 6(1)(b)) + Legal obligation (Art. 6(1)(c)) 6 years (UK tax law)
Encrypted messages Contract (Art. 6(1)(b)) Max 48 hours (relay only)
Nginx attacker logs (4xx / 5xx only) Legitimate interest (Art. 6(1)(f)) — defending against probes 14 days, rotated
PIN hash (app lock) Contract (Art. 6(1)(b)) Until disabled

International Data Transfers

Your data is processed on infrastructure within Switzerland and the EU/EEA, plus two relay-only points that hold no personal data. Switzerland has an EU adequacy decision; the remainder are in the EU/EEA. No additional cross-border safeguards (such as Standard Contractual Clauses) are required for these transfers.

Payment data is processed by Stripe, Inc. (US) under their own privacy policy and EU-US Data Privacy Framework certification.

AI processing of event data (classification, geocoding, summarisation) runs primarily on self-hosted models on our own hardware in the EU — the data does not leave our infrastructure for these tasks. A small fraction of generative work falls back to an EU-based commercial LLM API when local capacity is exceeded. Only event titles and source headlines are sent to either path — never user data, never DM content.

Data controller: HyveHeim, United Kingdom. ICO registration number: C1896848. For data protection enquiries, use the contact form.

Supervisory authority: If you are unsatisfied with our response, you may complain to the Information Commissioner's Office (ICO) at ico.org.uk (UK), or your local EU/EEA data protection authority.

We do not have a Data Protection Officer because we are not a large organisation processing sensitive data at scale. We do have a person who reads privacy-related messages and takes them seriously. They are the same person. They are also writing this privacy policy. Hello.

4. CCPA (California Users)

California residents have rights under the California Consumer Privacy Act. Since we don't sell personal information (we have no personal information to sell), most of the CCPA is not directly applicable. Specifically:

5. Third-Party Services

HyveHeim integrates with the following third-party services. Here's the honest rundown:

That is a comprehensive and complete list of third-party data flows. We are not hiding any others in footnotes.

6. Data Retention

7. Security

We take security seriously (we built an intel platform; ignoring our own security would be a bad look).

If you're a security researcher who just read all that and got the urge to test it: please do. Coordinated disclosure via the contact form, we'll fix it, we'll credit you, and we won't be weird about it. Black-hatting us is rude.

If you discover a security vulnerability, please email us before publishing it. We will take it seriously, fix it promptly, and credit you if you'd like.

8. Changes to This Policy

If we materially change this policy (i.e., start collecting more data), we will notify account holders via in-app notification or website announcement. Changes that reduce data collection require no notification because they are good news.

We are not going to add 14 pages of "we may share your data with trusted partners" boilerplate in the future. If that ever happens, it means this project has been acquired by someone terrible and you should leave immediately.

9. Contact

Privacy questions, data requests, or if you just want to yell at us about GDPR:

mail Contact Us

Terms of Service

The legal stuff. We've tried to make it human-readable.

1. What This Service Is

HyveHeim provides a real-time global intelligence map aggregating publicly available open-source information. The service is provided for informational and situational awareness purposes only.

2. What This Service Is Not

HyveHeim is not:

  • A replacement for official government travel advisories, emergency services, or professional security assessments.
  • A source of verified, fact-checked news. Events are aggregated from open sources and may contain errors, misidentifications, or outdated information.
  • A real-time emergency response platform. Do not rely on HyveHeim in a life-threatening situation.
  • Legal, medical, or security advice.

In short: we're showing you what people on the internet are saying about events. Treat it like a very sophisticated news aggregator, not like ground truth. Always verify from primary sources before making decisions.

3. Acceptable Use

You may use HyveHeim for:

  • Personal situational awareness, travel planning, research, and journalism.
  • Academic and educational purposes.
  • Public-domain open-source intelligence analysis and discussion (Mímir).
  • Commercial use via an API subscription (see Pricing).

You may not use HyveHeim to:

  • Harass, threaten, dox, or harm individuals or groups.
  • Circumvent API rate limits or scrape data in violation of the API terms.
  • Redistribute our data commercially without an appropriate API licence.
  • Attempt to access other users' accounts or private data.
  • Use the platform for propaganda, disinformation campaigns, or coordinated inauthentic behaviour.
  • Post extremist material — political, religious, or otherwise. We're not a recruiting ground and we don't carry water for any cause.
  • Post classified, security-restricted, or otherwise protectively-marked material — see Classification Policy. This is automatically blocked at submission and reported to operators.
  • Upload child sexual abuse material. We hash-check on upload, silently reject, and report severe cases.

3.1 Mímir — what this place is for

Mímir is the discussion forum attached to the OSINT platform. It's for serious, accountable analysis of public-domain intelligence signals. It is not, and will never become:

  • A lifestyle feed. Nobody cares what you had for breakfast. Nobody cares that your kid won a well-behaved sticker in the nursery. Nobody cares how cute your Pomeranian is or how you looked in that dress at the wedding. There are entire platforms dedicated to that content. Use those.
  • A political or religious soapbox. We don't host hot takes on what side anyone should be on. Analysis of what happened and what comes next is welcome; tribal rallying is not. There are entire platforms dedicated to that content too.
  • A sports forum. The Champions League is not OSINT. There are many entire platforms dedicated to that content.
  • An extremism amplifier. Apologetics for terrorism, calls to violence, dehumanising rhetoric against any group — instant ban, report to authorities where required by UK Online Safety Act 2023 / EU DSA / equivalent.
  • An attention-seeking outlet. Selfies, vanity posts, anything-for-engagement bait. Not the audience.

If a post would be at home on Instagram, Facebook, TikTok, X, Truth Social, Reddit, or your group chat — post it there. Mímir is for the work that wouldn't fit on any of those.

3.2 Tone + accountability

You post under a forum handle you choose. The platform doesn't blind you (this isn't anonymous chat) — your handle persists, your post history is visible, and operators can see your underlying account. That accountability is the point: it raises the floor on what gets posted.

Disagree without contempt. Cite sources. Quote-reply rather than misrepresent. Flag rather than feud.

3.3 What gets you removed or banned

Operator action (mute / shadowban / ban) for:

  • Anything in section 3 above marked "may not".
  • Repeat off-topic posting after a warning.
  • Coordinated reaction farming / sockpuppet karma boosting.
  • Persistent low-effort content (memes, one-liners, "+1" comments).

Bans are appealable: contact form. A different operator handles your appeal. We respond within 7 days.

4. Disclaimer of Warranties

THE SERVICE IS PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. WE DO NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, OR THAT EVENT DATA WILL BE ACCURATE OR COMPLETE. THE SERVICE IS AGGREGATED FROM PUBLICLY AVAILABLE SOURCES WHICH WE DO NOT CONTROL.

(Yes, we have to shout this bit. Lawyers insist.)

5. Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, HYVEHEIM SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES ARISING FROM YOUR USE OF OR INABILITY TO USE THE SERVICE.

If you make a bad decision based on something you saw on our map, that is, respectfully, on you.

6. Account Termination

We reserve the right to terminate accounts that violate these terms. You can delete your account at any time from the profile settings.

7. Governing Law & Jurisdiction

These terms are governed by and construed in accordance with the laws of England and Wales. Any disputes arising from or in connection with these terms shall be subject to the exclusive jurisdiction of the courts of England and Wales.

If you're accessing the service from outside the UK, you're still bound by these terms — but we won't chase you across international borders for using a map wrong. We're reasonable people.

8. Age Requirement

You must be at least 16 years old to create an account on HyveHeim. This is the minimum age for data processing consent under the UK GDPR (via the Age Appropriate Design Code). If you're under 16, you may use the public map without an account — no data is collected, so no age restriction applies to anonymous use.

9. Intellectual Property

The HyveHeim platform, including its code, design, branding, and original content, is the property of HyveHeim. OSINT data aggregated from third-party sources remains the property of those sources and is displayed under fair use / fair dealing provisions for the purposes of news reporting, research, and public interest.

User-submitted reports and tips are granted to HyveHeim under a perpetual, royalty-free licence for display on the platform. You retain ownership of your submissions but grant us the right to use them. You can request removal at any time via contact.

10. Indemnification

You agree to indemnify and hold HyveHeim harmless from any claims, damages, or expenses arising from your violation of these terms or your misuse of the service. In plain English: if you do something illegal with our platform, that's on you, not us.

11. Severability

If any provision of these terms is found to be unenforceable by a court of competent jurisdiction, the remaining provisions continue in full force. We wrote these terms in good faith — if a court disagrees with one clause, the rest still stand.

12. Entire Agreement

These terms, together with our Privacy Policy and Fair Use Policy, constitute the entire agreement between you and HyveHeim. No prior conversations, promises, or side agreements override what's written here.

13. Changes

We'll notify account holders via in-app notification or website announcement of material changes to these terms. Your continued use of the service after changes constitutes acceptance. We will provide at least 30 days' notice for any changes that materially affect your rights.

14. Company Information

HyveHeim is operated from the United Kingdom. For legal correspondence or formal notices, please use the contact form.

These terms were last updated in March 2026.