Trust

Security

Heyy Studio uses account, access, payment and service controls designed to protect the platform while recognising that no online system is risk-free.

Last updated: 28 September 2026

Protecting accounts and data

Heyy Studio is designed to keep public browsing separate from private account, project, billing and production activity. Access to private data is checked against the signed-in account and relevant project context before it is returned or changed.

Authentication and access controls

  • Supabase provides the current authentication service.
  • Private API routes check authenticated sessions and ownership or authorised roles.
  • Administrative and Expert areas use additional role or invitation controls.
  • Service credentials and provider secrets are handled on the server rather than intentionally exposed in browser code.

Payments

Subscription, credit-pack and Expert Production payments use Stripe-hosted or Stripe-supported payment flows. Payment events are verified before related plan, credit or production records are updated, and important payment operations include duplicate-processing protections.

Storage and service providers

Heyy Studio uses established providers for authentication, database and file storage, hosting, email, payments and requested generation. Access and data are separated by account, project or operational role where the workflow requires it. Provider infrastructure may operate across locations and no provider can guarantee absolute security.

Operational reliability and error handling

Generation and payment workflows record status so incomplete or duplicate work can be identified and reconciled. Failed generation reservations are returned after a confirmed failure. Operational errors may be logged and reviewed to diagnose problems and maintain the service. This is not a claim of continuous security monitoring or uninterrupted availability.

Your security responsibilities

  • Use a strong, unique password where a password is used and protect the email account connected to Heyy Studio.
  • Do not share sign-in links, sessions or private production files with unauthorised people.
  • Sign out on shared devices and keep browsers and devices updated.
  • Check recipients and file contents before sharing or downloading.
  • Contact support promptly if you suspect unauthorised access or an incorrect account change.

Report a suspected security issue

Use Contact & support or email hello@heyystudio.com with a clear description, affected page, steps to reproduce and any non-sensitive evidence. Choose Technical Support in the form. Do not access, alter, download or retain data that is not yours, disrupt the service or publish sensitive details before Heyy Studio has had a reasonable opportunity to review them.

No absolute guarantee

No online service, transmission method or storage system can be guaranteed completely secure. Heyy Studio does not claim SOC 2, ISO 27001, penetration-testing status, encryption-at-rest coverage or another certification or control that has not been verified for publication.