Skip to content

Heatpoints security and image handling

An image can contain confidential information. Here is how the current product handles captures and results, and which assumptions you should not make.

Processing happens on the server

The web image tool and Chrome extension send images to Heatpoints for inference. HTTPS protects transport to the public site. This is not an offline or exclusively on-device model.

Review what is visible before capturing a signed-in tab. Browser access to a private page does not imply that its contents are suitable for upload to another service.

Storage depends on the workflow

Account media analysis can store reduced originals and overlays in a library capped at the latest 12 analyses. The ad and thumbnail creative tools store an original and a map and serve them through result URLs. These URLs are not a substitute for account-level access control.

Do not assume that every uploaded image is immediately deleted. The exact workflow matters. Comparison exports also create files on your device that you control.

References: Data handling by feature

Accounts and shared computers

The application uses browser-stored session tokens. Sign out on a shared device and protect the email account used for verification. Avoid sharing result URLs containing sensitive material.

Settings provide the available profile and connection controls. No enterprise certification, independent penetration test or universal security guarantee is claimed on this page.

References: Open settings

Hosting and retention commitments

We do not claim that all processing occurs in France or that data never leaves the EU without a verified hosting and subprocessor inventory. Consult the privacy policy for the current published information, and obtain clarification before sending regulated or confidential material.