Heard Privacy Policy
Document key: heard-privacy
Version: 1.0.0
Last updated: September 5, 2026
Effective date: September 5, 2026
Canonical URL: https://discoverheard.com/privacy
This Privacy Policy explains how Justin Lauinger, the current individual publisher of Heard ("Heard," "we," "us," or "our"), handles personal information when you use the Heard mobile application, websites, application programming interfaces, public audio service, account-deletion page, or related support and safety channels (collectively, the "Service").
This policy describes Heard's current data practices and the additional processing that occurs only when the relevant feature is available. Publication of this policy does not by itself enable creator uploads, public creator content, moderation operations, or another disabled feature.
1. Scope and important facts
Heard is an audio-first social service intended only for people age 18 or older in the United States.
- Supabase provides account authentication and database services. Passwords are sent directly to Supabase Auth rather than through Heard's application API.
- Creator audio is uploaded to private Cloudflare R2 storage for technical processing and review. It does not become public unless it passes the applicable review and publication controls.
- Heard uses OpenAI to transcribe eligible private creator audio and evaluate the resulting transient text for moderation. Heard does not store or display the raw moderation transcript. Creator publication remains disabled.
- Published audio and associated post and creator information are internet-public and may be copied, cached, recorded, or redistributed by others.
- Heard stores certain sessions, onboarding information, feed state, playback state, and creator drafts on your device.
- Heard does not currently include third-party advertising, cross-app tracking, behavioral-analytics, payment, or crash-reporting SDKs. Infrastructure, operating systems, app stores, and network providers may still process ordinary technical and security information.
- Account deletion removes identifying account information and public availability, but limited operational, security, rights, safety, or legal records may remain as described below. Those records are not necessarily anonymous.
2. Information we handle
Account and authentication information
When you register, sign in, recover an account, change a password, or delete an account, Supabase may process your email address, password, user identifier, session credentials, authentication status, and related timestamps. Heard's application API receives a signed session credential and the account information necessary to authorize a request, but not your raw password.
If Heard activates its public eligibility control, it will record that you confirmed you are at least 18, are located in the United States, can use the English-language release, accepted the current Terms and Community Guidelines, and acknowledged this Privacy Policy. The eligibility receipt is designed not to contain a birth date, raw IP address, device identifier, or copy of your password.
Profile and public identity
We process a stable profile identifier, handle, display name, optional biography, account status, onboarding status, and associated timestamps.
For a published post, the profile identifier, handle, display name, post information, and audio may be public. A biography may be visible through supported signed-in profile and search features. Heard does not intentionally publish your account email address or authentication identifier as profile information.
Preferences and safety choices
We process the categories you choose for feed personalization, preference versions, onboarding status, and creators you block or mute. Block and mute relationships are private. Blocking changes supported signed-in Heard surfaces; it cannot prevent signed-out access to information or audio that was already public or erase third-party copies.
Category choices such as Health & Wellness or Culture/Religion can suggest sensitive interests. Heard uses those choices to provide the feed you request and does not use them to infer a diagnosis, religion, or other sensitive trait or for advertising. Heard will provide any separate notice, consent, or rights process required by applicable law before beginning a covered sensitive-data use.
Device-local information
Depending on the feature you use, the app may store the following on your device:
- Supabase session credentials and authentication state;
- incomplete onboarding information;
- account and preference scope, opaque feed cursors, and limited error timing;
- public track metadata and stream URLs in the native playback queue;
- creator recording or imported-audio drafts; and
- pending-upload recovery state.
An incomplete onboarding draft currently has no automatic expiration and may remain after an ordinary sign-out. Creator drafts are account-scoped, are marked to expire seven days after their last update, and are removed when the app next performs its draft cleanup. Clearing app data or uninstalling the app may also remove device-local information.
Creator submissions
When you create or import audio for submission, Heard may process:
- the audio bytes and a Heard-generated storage name;
- title, category, duration, MIME type, size, and checksum information;
- content, asset, upload-session, and retry identifiers;
- recording method and a Human, AI-generated, or AI-assisted source choice;
- your confirmation that the source choice is accurate and that you own or have permission to use the audio and any identifiable person's voice; and
- upload, inspection, review, visibility, storage, and deletion status and timestamps.
The current creator form does not require an AI provider or model and does not collect a voiceprint or a copy of a voice-consent document. Free-form audio may reveal sensitive information about you or another person. Do not record or submit another person's private or sensitive information without every permission and lawful basis required for the recording and its intended use.
Technical processing and moderation
Heard performs technical inspection of creator audio and may create a private normalized playback copy. Technical records can include file size, checksum, container, codec, duration, channels, sample rate, bitrate, processing version, duplicate reference, status, bounded diagnostic code, and timestamp.
For eligible private creator submissions, Heard sends the audio needed for transcription to OpenAI and sends the resulting text to OpenAI for moderation. Heard retains bounded moderation results and integrity evidence but does not intentionally store or expose the raw transcript. OpenAI may retain or review data as permitted by the configuration and terms governing Heard's API use.
Automated moderation can make mistakes. A technical or automated result does not itself publish content. Uncertain, flagged, unsupported, or failed results remain private for human review.
Reports, appeals, rights requests, and support
If you submit a report, appeal, copyright notice, counter-notice, privacy request, accessibility request, or support message, we may process the contact information, account or content identifiers, message, evidence, legal statements, communications, status, and resolution information needed to handle the request.
Do not send a password, authentication code, token, suspected child sexual abuse material, or unrelated sensitive information through these channels. Rights notices and counter-notices may require disclosure to the affected party as described in the Copyright Policy and applicable law.
Network and service information
Cloudflare, Supabase, app stores, operating systems, and network providers may process IP addresses, request times, requested hosts or paths, response status, device or browser characteristics, and security signals when providing their services. Heard's application rate-limiting design uses short-lived pseudonymous keys and bounded counters instead of intentionally writing raw network addresses or bearer credentials to application logs. Providers may retain their own security and service logs under their configurations and terms.
The app requests microphone access only when you choose a recording feature. Existing audio is selected through the operating system's document picker. The current app does not request precise location, contacts, camera, photo-library, broad shared-storage, health-platform, or advertising-identifier permission.
3. How we use information
We use information to:
- create, authenticate, secure, recover, and delete accounts;
- create profiles and provide category-based discovery and playback;
- receive, inspect, process, review, publish, update, unpublish, and remove creator submissions;
- label supported AI-generated or AI-assisted content;
- operate blocking, muting, reporting, appeal, support, safety, and rights processes when those processes are active;
- prevent abuse, investigate incidents, enforce policies, and protect users and the Service;
- comply with law and valid legal process and preserve information when legally required; and
- communicate about accounts, security, requests, policies, and the Service.
Heard does not currently sell personal information, use it for cross-context behavioral advertising, create biometric voiceprints, identify people from their voices, clone voices, or train a generative model on Creator Content. Any materially different use requires a new product decision, applicable notice and consent, and an updated privacy review before it begins.
4. How information is disclosed
Public and other users
Published audio and the associated post and creator information are public. Signed-in users may also see supported profile and creator-search information. Heard does not intentionally make account email addresses, passwords, private preferences, or block and mute relationships public.
Service providers
Heard currently uses:
- Supabase for authentication, account email and password workflows, session issuance, PostgreSQL data storage, and account administration;
- Cloudflare for API delivery, restricted compute, private and public audio storage, technical processing, maintenance, and CDN delivery;
- OpenAI for transcription of eligible private creator audio and moderation of the transient transcript;
- Resend for identifier-limited operational safety alerts; and
- Namecheap Private Email for the support mailbox and authentication email delivery configured through Supabase.
These providers may use subprocessors and process information in locations permitted by their applicable terms. They may process information only for the services Heard directs them to perform, subject to their agreements and applicable law. Heard requires providers receiving user data to protect it consistently with this policy and applicable law.
Legal, safety, and rights protection
We may preserve or disclose information when reasonably necessary to comply with law or valid legal process; make a legally required child-safety report; investigate fraud, abuse, infringement, or a security incident; enforce our policies; or protect the rights, property, or safety of users, Heard, providers, or the public.
Business transition
If the Service or its assets transfer to a verified successor through formation, reorganization, financing, merger, acquisition, or sale, personal information may transfer subject to applicable notice, purpose-limitation, and privacy requirements. The current publisher is an individual; Heard does not currently identify a limited-liability company as the Service provider or controller.
At your direction
We may disclose information when you direct us to do so or give legally sufficient consent for the specific disclosure.
Tracking and opt-out signals
Heard does not currently track people over time across unaffiliated websites or apps for targeted advertising, so a browser Do Not Track signal does not change current Service behavior. Heard does not permit third parties to collect personal information through the Service for their own cross-context behavioral advertising. Where applicable law requires recognition of a Global Privacy Control or another universal opt-out signal for a covered sale, sharing, or targeted-advertising activity, Heard will honor it. Heard currently has no such activity to opt out of.
5. Retention
Heard retains personal information only while reasonably necessary for the disclosed purpose, security, dispute resolution, enforcement, or legal compliance. Current practices and criteria include:
| Information | Current approach |
|---|---|
| Account and profile | Retained while active. Account deletion removes the authentication account and identifying fields and minimizes or pseudonymizes limited remaining records. |
| Device-local onboarding | Removed after onboarding completion, account deletion, app-data clearing, or uninstall; currently may survive ordinary sign-out and has no automatic expiration. |
| Device-local creator draft | Marked to expire seven days after its last update and removed on the next app cleanup; also removed on submission, discard, account change, successful sign-out, or deletion. |
| Active private upload | Retained while upload, processing, or review remains active. Heard does not currently apply a fixed maximum to every inactive or pending-review upload; creator publication remains disabled while that cleanup boundary is completed. |
| Raw moderation transcript | Not intentionally stored by Heard after the moderation request. OpenAI may retain or review request data as permitted by the configuration and terms governing Heard's API use. |
| Terminal private audio | Inaccessible and eligible for scheduled deletion after the applicable retention cutoff, ordinarily 30 days. A valid restricted legal or safety hold can delay deletion. Eligibility for deletion does not guarantee that every provider log, replica, or backup is erased on the same day. |
| Removed public audio | Removed from current Heard feeds and queued for origin and CDN deletion. Heard's internal target is denial of ordinary and byte-range access within five minutes after an authorized removal decision, but this is not a guarantee that third-party copies disappear. |
| Operational, moderation, safety, rights, and deletion records | May remain in minimized or pseudonymized form while reasonably necessary for integrity, security, enforcement, legal compliance, dispute resolution, or proof. Some record classes do not currently have a fixed destruction period. |
| Provider logs, replicas, caches, and backups | Governed by provider configurations and terms. Retention can continue for security, continuity, legal, or backup-cycle purposes after data is removed from Heard's active systems. |
A valid legal, safety, litigation, fraud-prevention, or preservation obligation may require longer restricted retention. Child-safety material included in a completed CyberTipline report must be preserved in accordance with applicable law, including the current statutory preservation period. Access to preserved information must be restricted to what is necessary for that purpose.
6. Account and content deletion
You can permanently delete your account in the app through Settings → Account Actions → Delete account or through Heard's public account-deletion page. An API-hosted form is also available at https://api.discoverheard.com/delete-account.
After a valid request, Heard is designed to:
- remove the account and identifying profile fields;
- remove posts from current Heard feeds, profile responses, and playback eligibility;
- stop active upload and processing work;
- clear Heard app sessions, queues, local storage, cache, and document files after successful mobile completion;
- queue public audio for origin and CDN removal; and
- make private terminal audio eligible for deletion under the applicable retention and legal-hold rules.
Limited stable identifiers, one-way hashes, status records, and minimized or pseudonymized operational, security, moderation, rights, safety, legal-hold, or deletion evidence may remain. Some identifiers may remain linkable to information that was previously public and are not necessarily anonymous. Account deletion cannot erase copies made independently while content was public.
Deletion timing, provider propagation, backup treatment, and lawful-retention exceptions are described here and on the public account-deletion page. They may vary by record type and legal obligation.
7. Your choices and privacy rights
You can use available product controls to update supported profile fields and preferences, manage microphone permission, discard a local draft, edit or remove supported posts, block or mute creators, sign out, and permanently delete your account.
Depending on applicable law, you may also have rights to request access, correction, deletion, or a portable copy; withdraw consent; limit certain sensitive-data uses; use an authorized agent; or appeal a privacy-request decision. Heard does not currently sell personal information or use it for targeted advertising.
To exercise an applicable privacy right, email support@discoverheard.com with Privacy request in the subject. Heard may request information reasonably necessary to verify the request, may use a manual process where no self-service control exists, and will not discriminate unlawfully against you for exercising an applicable privacy right. An authorized agent may submit a request, subject to reasonable verification of authority and identity. If Heard denies a request that applicable law allows you to appeal, reply to the decision and state that you are appealing it.
8. Security
Heard uses administrative, technical, and organizational safeguards designed to protect information, including access controls, encrypted transport, private storage for unpublished audio, short-lived capabilities, restricted service roles, bounded logging, and separation between review and publication. No service can guarantee perfect security.
Do not send credentials through support, use a unique password, and tell us promptly if you believe an account or information is at risk.
9. Children and teenagers
Heard is intended only for adults age 18 or older and is not directed to children or teenagers. People under 18 may not create or use an account or submit content. Heard does not currently collect a date of birth or identity document for age verification.
If Heard learns that a person under 18 is using an account or that personal information was collected from them, Heard may restrict the account and delete the information, subject to safety preservation and other legal duties. Report child-safety concerns through the Child Safety Standards. Do not copy or forward suspected child sexual abuse material to Heard.
10. Processing location
Heard is intended for U.S. users. Information may be processed in the United States and other locations where Heard's providers and their subprocessors operate. Heard will conduct a new regional compliance review before intentionally offering the Service outside the United States.
11. Changes to this policy
We may update this policy when the Service, providers, law, or data practices change. The version and effective date will appear at the top. We will provide notice and obtain any new consent required by applicable law before a material change takes effect.
We will not use previously collected information for a materially incompatible new purpose without the notice, choice, or consent required by law.
12. Contact
Privacy questions and requests may be directed to:
Justin Lauinger, current individual publisher of Heard
Email: support@discoverheard.com
Website: https://discoverheard.com/support
The support address is active and operated by Heard's individual publisher but is not staffed 24 hours a day. Do not send passwords or authentication codes by email.