Privacy policy
Last updated July 23, 2026
Heimdal is a face-recognition service for clocking in and out and, at correctional facilities, for visitor management. This page explains, in plain words, what personal data passes through it, what we do with that data, and when it is deleted. We process personal data in line with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and its implementing rules.
Each organization that uses Heimdal decides who to enroll and why. In Data Privacy Act terms, the organization is the personal information controller, and Heimdal processes data on its behalf.
What we collect, and from whom
- Administrators and managers: name and email address. They sign in with Google, so we never hold a password for them. These are the people who run an organization's account.
- Members (the people who clock in and out): name, group assignment, a roster photo, and a face template. The photo and template are captured once, at enrollment. Each clock event records only the time, direction (in or out), and the kiosk's approximate location. No photo is kept when clocking in or out: the camera image is sent to our servers to be recognized and discarded straight after.
- Watch link viewers: nothing. A watch link shows a member's clock events without asking the viewer to register, log in, or provide any personal details.
- Access requests: if you submit the request form on our website, we keep the name, email, organization, and details you send so we can respond.
How consent is recorded
At a workplace, a member enrolls themselves through an invite link on their own device, and the consent notice is shown and agreed to before any face capture.
Schools work differently. A child cannot consent for themselves under the Data Privacy Act, and no teacher or school official can consent on their behalf, so the only valid consent is a parent's or legal guardian's. The school encodes its class lists as names first, sends parents a separate consent link that never opens a camera, and captures faces at school on the school's own device. That means a student's face may be captured before their parent has answered. If a parent declines, on the link or on paper, that student's face photo and facial data are deleted, no new capture is allowed, and the school records their attendance another way. Parents can decline at any time, and can withdraw a consent they already gave.
Either way we store the time, who consented, the guardian's name where one applies, and the exact wording that was shown, so the record does not drift when this page changes. Heimdal supplies that wording, the same for every organization. Where a school collects signatures on paper, it keeps a photograph of the signed sheet as the record. If you were enrolled and have questions about why your organization collects this data, your organization's administrator is the right first contact.
How face recognition handles your face
Your face is photographed once, during enrollment. The camera image is converted into a face template. At the kiosk, the camera image is sent to our servers, converted into a template there, matched against enrolled templates, and then discarded. We do not store it, and it is not written to any log or file. Only the template is kept, and only the one made at enrollment. A template cannot be reversed into a photograph. The roster photo is an ordinary image kept for identification, not for any other purpose. Visitation kiosks at correctional facilities work differently and do store a photo with each visit; that flow is described in its own section below. We do not sell personal data, use it for advertising, or use it to train machine-learning models.
Visitation at correctional facilities
At correctional facilities, Heimdal records visitor entry and exit instead of attendance, and that flow handles data differently:
- Visitors: registering a visit collects each visitor's name, age, address, birth date, and relationship to the resident being visited. Entry and exit are verified by a face scan, and each visit stores a capture photo and face template as part of the facility's visitation record.
- Residents: the facility enrolls residents (name, photo, face template) under its own legal authority as their custodian; the consent-link flow described above does not apply.
- Incidents: the exit gate photographs anyone it cannot match to a visitor who entered, and the entry gate photographs a resident detected at the gate or a banned visitor attempting to enter. This means a photo may be taken of someone who never registered as a visitor. The facility keeps those photos as part of its security record.
- Retention: visit records and incident records, including their photos and face data, are kept by the facility as official records of who entered and left. They are not covered by the member deletion rules above. The facility is the personal information controller for this data, and requests about it should be directed to the facility.
- Recognition is assistive: when a returning visitor is recognized, the match only prefills their registration details for a guard to review. Admission is always decided by facility staff, never automatically.
When data is deleted
- Face templates and roster photos are permanently erased when a member is removed from the organization.
- Push subscriptions are removed when the viewer unsubscribes or the watch link is rotated.
- Account and attendance records are deleted on the organization's request when it stops using the service.
One qualification, because it would be misleading to leave it out: our database is backed up continuously so that it can be restored after a failure. Deleted data stays in those backups until they age out, up to thirty days, and is not restored into the live system except as part of recovering the whole database.
Payments
We never see or store card numbers or e-wallet credentials. Payments in the Philippines are processed by PayMongo (QR Ph); payments from elsewhere are processed by Lemon Squeezy, which acts as the merchant of record. Each processor handles payment data under its own privacy policy.
Service providers
Heimdal runs on a small set of infrastructure providers that process data on our instructions: Supabase (database and file storage), Vercel (hosting), Resend (email), PayMongo and Lemon Squeezy (payments).
Face recognition runs on our servers, hosted with Vercel in Singapore. Finding a face in the camera view still happens in your browser; only the small image around a detected face is sent, and only at the moment of a scan. The video stream itself is never transmitted or recorded.
Your rights
Under the Data Privacy Act you may ask for access to, correction of, or erasure of your personal data, and you may withdraw consent. Members should direct requests to their organization's administrator, who can act on them directly: removing a member erases their biometric data immediately. You can also reach us at heimdal@bearlog.app, and you have the right to lodge a complaint with the National Privacy Commission.
Changes
If this policy changes, the date above changes with it, and material changes are announced to organization administrators by email.