Data storage
The desktop app stores data in a local database for offline use. When cloud sync is enabled, data is also stored on Heptabase’s cloud infrastructure, including Amazon Web Services (AWS). Using only one device does not by itself mean your data stays only on that device: cloud sync, AI features, and connected services can involve server-side processing.
Encryption
For the AWS cloud storage described here, data is encrypted in transit and at rest. AWS manages server-side encryption using AES-256, and transfers between Heptabase and its database use SSL/TLS. This AWS data storage is in us-west-1, with VPC network controls restricting database exposure. These statements describe that infrastructure; they are not a statement that every AI or connected service processes data in the same region.
Encryption in transit and server-side encryption at rest are different from end-to-end encryption. Cloud features such as search and AI need to process readable content on servers; the encryption described above should not be interpreted as meaning that only your device can decrypt that content.
Search services
Search uses different services for different features. Elastic Cloud is used for search, and Turbopuffer is used for AI semantic/hybrid search. The AI search index includes content chunks and metadata such as titles and object identifiers, as well as vector representations used for semantic matching. It is not limited to anonymous identifiers. See Elastic Cloud security for that service’s security information.
Using AI features
When you use Heptabase AI, the request sent to the selected model service can include your prompt, relevant conversation history, attached or referenced content, and content retrieved by the agent’s tools. Depending on the feature, it may also include current-view information and supported images or extracted document text.
This does not mean every request sends your entire Space, but the agent can retrieve additional content as it works.
Using your own API key changes which provider account is used for model access and billing; it does not make the workflow local-only or bypass all Heptabase server processing.
Connecting external AI services
If you authorize an external app through Heptabase MCP, that app can request content through the tools available to its connection. Read/write authorization affects which tools it can use. Content returned to the external app is then handled under that app’s and its model provider’s policies.
Data retention, model-training use, and processing locations depend on the service and applicable terms. This article does not make a blanket promise of zero retention, no training, or one processing region across all providers. If you need to confirm a specific requirement before using a feature, contact Heptabase support.
