Heypocket
heypocket.comHeypocket (a product of Open Vision Engineering, Inc.) is a wearable hardware device ('Pocket') with an accompanying App and optional subscriptions, whose features include audio capture/recording. The only accessible policy documents were a Terms of Sale (governing hardware purchases, shipping, returns, and warranty) and an unrelated third-party Terms of Service belonging to 'Frill Group Pty Ltd' (a feedback tool), neither of which addresses AI data handling, model training, privacy, or security in any meaningful way. The core Privacy Policy and Terms of Use were inaccessible, leaving virtually all AI-governance and data-privacy questions unanswered — a significant risk signal for a device that records audio and processes potentially sensitive personal information. This tool is not recommended for professional, enterprise, or regulated-industry use without obtaining and reviewing the full Privacy Policy and Terms of Use and securing contractual protections.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
The accessible Terms of Sale do not address ownership of user-submitted data, prompts, or captured audio/content. The only ownership-adjacent language grants the Company a broad license to any feedback provided on beta/evaluation units, but general input data ownership is silent. The controlling Privacy Policy and Terms of Use were inaccessible.
Output Data Ownership
None of the accessible documents address who owns AI-generated outputs or transcriptions produced by the device or App. This topic is entirely governed by the inaccessible Terms of Use and Privacy Policy. The silence prevents any assurance of favorable output ownership terms.
Training Data Usage
No accessible document discloses whether user inputs, recordings, or content are used to train or improve models. For an audio-capture AI device, silence on model training is a high-risk signal because users cannot verify whether their sensitive recordings feed model improvement. The relevant policy was inaccessible.
Data Retention & Deletion
The Terms of Sale only reference user responsibility to delete data before returning a device and disclaim responsibility for data on returned units; no retention schedule, deletion SLA, or security-retention obligation (e.g., HIPAA, SOC 2 audit logs) is provided. There are no stated data-deletion mechanisms for cloud-stored recordings or account data. The controlling Privacy Policy was inaccessible.
Third-Party Data Sharing
The only disclosed third-party sharing in accessible documents is with payment processors for transaction fulfillment, which is expected and integral to purchasing. No broader disclosure exists regarding sharing of recordings or personal data with other third parties, advertisers, or data brokers. The absence of a complete Privacy Policy prevents assessing whether wider sharing occurs.
Opt-Out Rights
The accessible documents contain no opt-out mechanisms for data collection, model training, or third-party sharing (only Subscription cancellation and marketing-adjacent options are absent). The Privacy Policy that would normally contain such rights was inaccessible, so no opt-out provisions could be verified. Under the strict-reading rule, the absence of any stated opt-out warrants a RED rating.
Compliance & Certifications
No compliance frameworks or certifications (GDPR, CCPA, CPRA, SOC 2, HIPAA, ISO 27001, NIST, FedRAMP, etc.) are mentioned anywhere in the accessible documents. The only regulatory references relate to U.S. export controls (EAR/OFAC) and recording/wiretap consent laws, not data-privacy certifications. Absence of any privacy compliance framework is a high-risk signal.
Model Explainability & Auditability
There is no mention of model transparency, explainability, or enterprise auditing capabilities in any accessible document. This topic is completely absent, providing no assurance for enterprise users needing audit visibility into how the AI processes their data.
Security Practices & Breach History
No security controls (encryption at rest/in transit, access controls, penetration testing, bug bounty, incident response) are disclosed, and no trust center or security page is referenced in the accessible documents. There is no breach disclosure. For a device capturing audio, the absence of any security-practice disclosure is a serious gap.
Enterprise vs. Consumer Risk Delta
The Terms of Sale indicate the product is intended for personal/household use and restrict resale or commercial distribution, with no enterprise tier or differentiated data-handling terms described. Paid Subscriptions unlock additional features but no distinct data-handling protections are disclosed. There is no enterprise agreement or data-processing addendum referenced.
Human Review of User Inputs
No accessible document addresses whether staff may access, review, or listen to user recordings, prompts, or outputs. Given the device records audio, silence on human review is a notable risk. The relevant policy was inaccessible.
Regulatory & Litigation Exposure
The Terms of Sale incorporate a mandatory arbitration agreement and class-action waiver (contained in the inaccessible Terms of Use), which limits users' litigation rights. No disclosures about government data requests or law enforcement cooperation are present, and there are strong liability caps and damages exclusions favoring the vendor. The recording-law provisions place legal compliance burdens on the user.
PII & SPI Data Inventory
The accessible documents confirm collection of account, payment, and shipping information, and the product captures audio recordings (communications content — a category of SPI), but there is no data inventory or purpose-limitation disclosure because the Privacy Policy was inaccessible. Capturing audio of the user and potentially third parties without a visible privacy disclosure constitutes SPI collection without clear notice. The policy silence on the full scope of PII/SPI collected is itself a high-risk indicator.
You've read all 15 risk ratings for Heypocket. Create a free account to see the exact policy wording behind each rating.