Privacy Policy

Last updated: 25 September 2026

This Privacy Policy explains how Kirill Shumilov LTDA ("HeyIro", "we", "us") collects, uses, and protects your personal data when you use the HeyIro mobile and web application (the "Service").

We take privacy seriously because the Service is a private space for self-reflection. Your journal entries describe your feelings and personal life, and we treat them accordingly.


1. What data we collect

We only collect what the Service needs to work.

1.1 Data you provide

1.1a Safety classification

Free text you write — journal entries, messages to the assistant, and the goals you describe — is checked automatically for mentions of suicide, self-harm, or intent to harm another person, so the Service can show you crisis resources and stop showing you celebratory or coaching content for a period.

The result is stored as a single category on the entry itself (for example "none" or "self_crisis"). It is not a clinical risk assessment, it contains no quote or excerpt from what you wrote, no score, and no detail about method or means.

We do not contact anyone on the basis of this classification — not emergency services, not a family member, not a therapist — and we never share it with any third party or use it for profiling or advertising. We keep only an aggregate count of how often crisis resources were shown, with no user identifier attached. The full details are in our Crisis handling protocol.

Deleting an entry deletes its classification with it.

1.2 Data collected automatically

We do not collect precise location, contacts from your phone's address book, advertising identifiers, or health data from device sensors.


2. How we use your data

We use your data to:

We do not sell your personal data. We do not use your journal content to train third-party AI models, and we do not serve advertising.


3. Legal basis for processing

Depending on your location, we rely on:

Sensitive data. Journal entries can reveal information about your emotional and mental well-being. We treat this as sensitive/special-category data and process it only to provide the Service to you, based on your consent. The safety classification described in Section 1.1a is derived from that same text and is treated identically — it is stored with the entry, under the same consent, and is never disclosed to anyone.


4. How your data is shared

We never sell your personal data, and we do not share it for advertising.

To run the Service, we rely on third-party service providers that process your data on our behalf and under contract ("processors"), strictly to provide the Service to you. This includes processing the text and voice of your entries so the Service can transcribe, summarize, and reply to them — the Service cannot function without this. By using the Service, you acknowledge that your data, including the content of your entries, is transferred to such processors for these purposes.

We use processors in the following categories:

We may add or change the specific providers within these categories as the Service evolves. We require every processor to safeguard your data and to use it only to provide services to us — never for their own purposes. A current list of the specific providers we use is available on request at privacy@heyiro.com.


5. International data transfers

We are based in Brazil, and some subprocessors are located in the United States or the European Union. When we transfer your data across borders, we rely on appropriate safeguards — such as Standard Contractual Clauses (GDPR) and the international-transfer provisions of the LGPD (Arts. 33–36) — to protect it.


6. How long we keep your data

We keep your personal data for as long as your account is active. When you delete your account (see Section 7), we permanently erase your personal data from our production systems. Residual copies may persist in encrypted backups for up to 30 days before being overwritten. Aggregated, anonymized usage records that no longer identify you may be retained for accounting and capacity planning.


7. Your rights

Subject to applicable law (GDPR for the EU/EEA, LGPD for Brazil, and similar laws), you have the right to:

To exercise any right, use the in-app controls or email privacy@heyiro.com. We respond within the timeframes required by law.


8. Security

We protect your data with encryption in transit (HTTPS/TLS) and at rest, row-level access controls that isolate each user's data, hashed passwords, and an optional app lock (PIN / biometrics) on your device. No system is perfectly secure, but we work to protect your information and will notify you and the relevant authorities of a data breach as required by law.


9. Children

The Service is intended for adults (18+) and is not directed to children. We do not knowingly collect data from anyone under 18. If you believe a minor has provided us data, contact privacy@heyiro.com and we will delete it.


10. Changes to this policy

We may update this Policy. If we make material changes, we will notify you in the app or by email before they take effect. The "Last updated" date above reflects the current version.


11. Contact

Questions or requests about your privacy: Kirill Shumilov LTDA — privacy@heyiro.com