LeadHeron · Last updated September 10, 2026
Privacy Policy
LeadHeron is operated by Bimeo Digital Solutions, LLC ("Bimeo", "we"), Baltimore, Maryland, USA. This policy explains what we collect when you use the LeadHeron dashboard, the website assistant, and the attribution service, and what we do with it.
Who this covers
There are two kinds of people in our data. Customers are the businesses that sign up and connect their systems. End users are the visitors and contacts of those businesses, whose messages, form submissions, and emails our customers choose to process through LeadHeron. We act as a service provider to our customers for end-user data; our customers decide what to collect and are responsible for their own notices to their visitors.
What we collect
- Account data: your email address, workspace name, team members' emails, and billing details handled by Stripe. We never see full card numbers.
- Website assistant data: the documents and pages a customer uploads or lets us crawl, visitor questions and the assistant's answers, and lead forms a visitor submits (name, email, phone, message). The embed script stores a first-touch record in the visitor's browser (landing page, referrer, click and campaign identifiers) for 90 days so a later inquiry can be credited to the campaign that brought them.
- Attribution data: emails a customer forwards to their LeadHeron address, including attachments; form submissions sent to their webhook; and, when the customer connects them, reporting data from Google Ads and Google Analytics.
- Usage and logs: request logs, hashed IP addresses used for rate limiting, and usage counts used for billing.
Google user data
When a customer connects Google Ads or Google Analytics, we request read access to campaign, click, and analytics reports for the accounts they choose, and permission to upload offline conversions to their Google Ads account. We use this data only to attribute the customer's leads, quotes, and sales to campaigns and channels, to report those results back to the customer, and to send conversion events the customer has configured back to their own Google Ads account. We do not use Google user data for advertising of our own, do not sell it, and do not share it with third parties except the service providers listed below that host and process it on our behalf. Customers can disconnect Google at any time from their dashboard, which deletes the stored token; they can also revoke access at myaccount.google.com/permissions. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How we use data
- To run the service: answer visitor questions from the customer's documents, deliver leads, read forwarded emails into quotes and sales, match them to marketing channels, and produce reports.
- To bill for usage and prevent abuse.
- To support customers and improve reliability. We do not use customer or end-user content to train machine-learning models.
AI processing
Visitor questions, forwarded emails, and form submissions are processed by large language models operated by Anthropic (and, where a customer selects it, another model provider) to generate answers and extract structured records. These providers process the content to return a result and do not use it to train their models under the terms we hold with them.
Service providers
We use Supabase (database, authentication, file storage), Vercel (application hosting), DigitalOcean (background processing), Anthropic (language models), Stripe (payments), SendGrid (email delivery and inbound email processing), and Google (Ads and Analytics APIs, when connected). Each processes data only to provide its service to us.
Retention and deletion
Account and workspace data is kept while the account is active. Conversations, leads, forwarded emails, and attribution records are kept for as long as the customer keeps the workspace, so their reports remain accurate. A customer can delete a bot, disconnect a source, or ask us to delete a workspace; deletion removes the data within 30 days, except billing records we must retain by law. Raw forwarded emails can be deleted on request while keeping the extracted records.
Security
Data is encrypted in transit and at rest. Connection credentials such as Google refresh tokens are stored in an encrypted vault and are never exposed to the dashboard. Access within a workspace is limited to its members through database-level row security.
Your rights
Customers can export or delete their data by contacting us. End users should direct requests to the business they interacted with; we will assist that business in fulfilling them. If you are in a jurisdiction with data-protection rights (for example the EU, UK, or California), you may exercise them through the same channel.
Children
LeadHeron is a business tool and is not directed to children under 16. We do not knowingly collect their data.
Changes
We will post changes here and update the date above. Material changes will be announced to customers by email.
Contact
Bimeo Digital Solutions, LLC · privacy@bimeodigital.com