I hear everything. I repeat it to no one.
I sit in your most sensitive conversations: deals, salaries, strategy, the stuff you'd never put in an email. So let's be adults about it. Here's exactly how your data is protected, what I will never do with it, and the one certification I won't pretend to have yet.
SOC 2 certification is in progress, not claimed. Everything else here, EU hosting, GDPR, encryption in transit and at rest, and no third-party AI training, is in force today.
Is my meeting data safe with Heidi?
Heidi is an AI meeting copilot built in Strasbourg, France. Your data is EU-hosted on every plan, encrypted in transit and at rest, never sold, and never used to train third-party AI models. Only you see your meetings and coaching layer, and you can delete everything in one click. SOC 2 certification is in progress.
Six guarantees. No asterisks.
Not aspirations, not roadmap items. This is how Heidi handles your data today, on every plan.
Encrypted, both directions
Your data is encrypted in transit and at rest. Between your call and Heidi's servers, and while it sits in storage, it stays locked.
EU-hosted, by default
Your data lives in the European Union, on every plan. Not an enterprise add-on, not a checkbox upgrade. The default.
Never trains anyone's AI
Your recordings, transcripts and notes are never used to train third-party AI models. And never sold. Full stop.
Only you see your data
Your meetings, your scores, your coaching layer: yours alone. The cues Heidi whispers mid-call are visible only to you.
One click, and it's gone
Deletion is user-controlled. Wipe a meeting or your whole account whenever you choose. Your data, your kill switch.
A real DPA, on request
Business customers get a Heidi-owned Data Processing Agreement. Ask our team and they'll handle it directly.
French company. European rules. Your rights.
What GDPR means here, concretely
- Heidi is built by ID DIGITAL LAB, a company registered in Strasbourg, France, operating under EU law rather than adapting to it from outside.
- Your data is processed on a lawful basis and hosted in the EU.
- You hold your GDPR rights in full: access, rectification, deletion.
- A Data Processing Agreement is available for business customers.
Why it's structural, not marketing
Plenty of tools bolt an "EU option" onto a US product for enterprise deals. Heidi is the other way round: a French product where EU hosting and GDPR are the foundation every plan sits on. If your compliance team asks where the data lives, the answer is one word, Europe, with no tier conditions attached.
Access, payments, and the coaching layer.
The coaching layer is yours alone
When Heidi whispers a cue mid-call, the objection save, the trust warning, the next line, no one else in the meeting sees it. Participants see that a standard, transparent meeting assistant has joined. The coaching, the scores and the reads are for your eyes only. Heidi gossips to you, never about you.
Your workspace, your control
Access to your meetings, transcripts, scores and Contact IQ data is under your control. Heidi remembers exactly what you let it remember and nothing more, and what it remembers, you can wipe. Deletion isn't a support ticket, it's a click.
Payments live with Stripe, not with Heidi
The card you enter for the 14-day trial is processed by Stripe, a PCI-DSS certified payment processor. Heidi never stores your card details on its own servers. €0 today, one-click cancel, and your payment data was never Heidi's to hold in the first place.
HeidiThe cues I whisper are for you and only you. Participants just see a transparent assistant in the room, never your coaching layer.
Certifications: the honest status.
Here's where most security pages start waving badges. Heidi would rather tell you the truth, because you'll verify it anyway, and because honesty here is exactly what you'd want from a tool that sits in your meetings.
- Encryption in transit & at restIn placeYour data is encrypted moving and stored.
- EU data hostingIn placeEvery plan, by default.
- GDPR complianceIn placeFrench company, EU rules, your rights in full.
- No third-party AI trainingIn placeYour meetings never feed anyone's model.
- DPA for business customersAvailableOn request. Ask our team.
- SOC 2In progressNot certified yet. We won't pretend otherwise.
Why say it out loud? Because a security page that overclaims is itself a security risk: it tells you the vendor bends the truth under pressure. If a formal SOC 2 attestation is a hard requirement for your org today, Heidi isn't there yet and says so. If encryption, EU hosting, GDPR and honest answers are what you need, Heidi is ready now, and the certification is on its way.
What Heidi will never do with your data.
Never, on any plan
- Sell your data. To anyone. For anything.
- Use your meetings to train third-party AI models.
- Show your coaching layer to other participants.
- Store your card details on Heidi's servers.
- Hold your data hostage. Deletion is yours, in one click.
Always, on every plan
- Encryption in transit and at rest.
- EU hosting and GDPR rights.
- You control what Heidi remembers.
- A transparent, visible assistant in the room.
- A human answer on security questions. info@hi-heidi.ai
The security questions, straight.
Security questions? Talk to a person.
Doing a security review, or spotted something you want to report? Email us directly. A human reads it, keeps you posted, and gives you a straight answer.
info@hi-heidi.aiyour meetings stay yours
Trust is earned in the details.
14 days of the full copilot, €0 today. Encrypted, EU-hosted, and honest about the rest.
Card up front, held by Stripe, not Heidi. Zero tricks, €0 for 14 days. Cancel anytime.