Who we are
HeavyFeather ("HeavyFeather," "we," "us," or "our") is a commerce decision and execution platform in active development. HeavyFeather Operator helps sellers research products, evaluate evidence, prepare commerce work, connect services, and review consequential actions before they occur.
This policy explains how HeavyFeather handles information when you visit www.heavyfeather.ai, request or use an account, use a workspace, contact support, or authorize a connected service.
Information we collect
- Account information, such as your email address, password hash, early-access approval status, session records, and authentication state.
- Early-access review information, such as encrypted IP address, country code, browser and user-agent details, time zone, language, platform, screen dimensions, device pixel ratio, touch capability, referral source, and privacy-preserving comparison hashes used to identify duplicate or automated requests.
- Business and workspace information you provide, including business goals, product details, supplier references, pricing, economics, listings, decisions, and support messages.
- Public contact information you submit, including your name, email address, subject, and message, which is delivered to the private staff support inbox.
- Connected-service information, such as account identifiers, authorization tokens, provider status, and the provider data needed for the feature you request.
- Operational and security information needed to run and protect the service, such as application events, approval history, error records, and hosting logs.
- Public-site analytics information, when you allow analytics, such as page views, approximate location, device and browser characteristics, referral source, and interaction events collected through Google Tag Manager and Google Analytics. We do not intentionally send workspace content, account identifiers, or contact and signup form entries to analytics.
- Bot-prevention signals generated when score-based Google reCAPTCHA or Cloudflare Turnstile is enabled for login, account creation, or contact. These providers may process browser, device, network, and interaction signals to assess automated abuse; HeavyFeather receives the verification result and risk signal rather than an image challenge response.
Analytics and your choices
HeavyFeather uses Google Tag Manager to manage Google Analytics on public website pages. Analytics is not loaded for private dashboards or staff workspaces. You can prevent HeavyFeather from loading analytics in your browser by selecting Analytics choices in the website footer and choosing Necessary only. Your choice is stored in that browser.
Google may process analytics information under its own terms and privacy policy. Selecting Necessary only prevents HeavyFeather from loading the analytics container in that browser. Essential authentication, security, and provider-authorization technologies are not controlled by the analytics choice.
Google user data
When an authorized staff user connects Google Ads, HeavyFeather requests the Google Ads OAuth scope. HeavyFeather receives an OAuth refresh token and may access the authorized Google Ads account identifier and read-only keyword historical metrics, including average monthly search volume and competition information.
HeavyFeather uses this Google user data only to provide a visible market-validation feature: evaluating demand and competition evidence for product candidates and reporting the evidence back inside the authorized HeavyFeather workspace. The current integration cannot create campaigns, publish ads, change bids or budgets, upload conversions, manage audiences, or spend money.
HeavyFeather's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not sell Google user data, use it for advertising, use it to determine creditworthiness, or use it to train a generalized artificial-intelligence model.
How we use information
- Provide, maintain, secure, and improve the HeavyFeather features you request.
- Authenticate users, enforce workspace boundaries, and record approvals and business actions.
- Review early-access requests, compare duplicate-risk signals, and help detect automated signup abuse. These technical signals support staff review but do not independently prove a person's identity.
- Calculate economics, organize provider evidence, prepare recommendations, and explain current system state.
- Respond to support requests, investigate errors or abuse, and comply with applicable legal obligations.
- Communicate material service, security, or policy updates.
How information is shared
We do not sell personal information or Google user data. We disclose information only as needed to operate requested features, protect the service, comply with law, or complete a business transaction with appropriate notice and consent where required.
- Infrastructure providers, including Cloudflare, that host and protect the application and production database.
- Services you choose to connect, such as Google Ads, Shopify, or a supplier platform, when communication with that provider is required to perform the requested feature.
- Professional advisers or authorities when reasonably necessary for security, fraud prevention, legal compliance, or the establishment or defense of legal claims.
Storage and security
Production application data is stored in a tenant-scoped Cloudflare D1 database. Passwords are stored as one-way hashes. Integration credentials, including OAuth refresh tokens and provider secrets, are encrypted at rest using AES-256-GCM, masked by default, and used only on the server. Access is limited by account, workspace, and staff authorization controls.
No security measure is perfect. We use reasonable technical and organizational safeguards, monitor the service, and will respond to material security issues as required.
Retention, deletion, and revocation
We retain account and workspace information while it is needed to provide the service, preserve authorized business and approval records, meet security needs, or satisfy legal obligations. Retention periods may vary by record type and connected provider.
You may revoke HeavyFeather's Google access at any time from your Google Account permissions. You may also ask us to disconnect a provider or delete your account and associated personal information by contacting us. We will complete verified requests subject to records we must retain for security, fraud prevention, dispute resolution, or legal compliance.
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or obtain a copy of personal information. You may also object to certain processing or withdraw consent where consent is the basis for processing. Contact us to make a request; we may need to verify your identity before acting.
Children and international use
HeavyFeather is intended for adults building and operating commerce businesses and is not directed to children under 18. The service is operated from the United States. If you use it from another country, information may be processed in the United States and other locations where our providers operate.
Changes and contact
We may update this policy as the platform and its integrations change. We will update the date above and provide additional notice when a material change requires it. We will not use Google user data for a newly disclosed purpose without any notice and consent required by Google's policies or applicable law.
For privacy questions, data requests, provider disconnection, or account deletion, use the Contact form linked from the HeavyFeather website footer.