Security & data protection
Short version: TLS everywhere, data in France, no cookies, nothing kept longer than needed. The details:
Encryption in transit
All traffic is served over TLS (HTTPS only), with HSTS enforced. Browsers refuse to ever downgrade the connection. Certificates are issued and rotated automatically.
Data hosted in France
The images you upload and the heatmaps we generate are handled on infrastructure located in France and never leave the EU. We are a French company, subject to GDPR by default, not as an afterthought.
No tracking, no cookies
Heatpoints sets no analytics cookies and uses no fingerprinting. We don't track visitors across the web or build advertising profiles. The heatmap tool runs in your browser, no account needed.
What we keep, and for how long
Images you drop into the tool are processed to generate your heatmap and are not retained afterwards, we don't keep a copy. If you contact us, we hold only what's needed to reply.
Payments
The core tool is free. When paid plans arrive, payments will be processed by Stripe; your card number never touches our servers.
Hardened by default
Strict security headers (CSP, HSTS, nosniff), rate limiting on every endpoint, bounded and validated uploads, and SSRF protection on our capture service.
Independently verified
Don't take our word for it. These checks are public and re-runnable by anyone:
Responsible disclosure
Found a vulnerability? Tell us first. We answer fast, fix fast, and credit you if you want. Contact and policy: /.well-known/security.txt
