Privacy Policy
Effective 7 September 2026
This policy explains what Hero Instruments, Inc. collects when you use BLE Hero Workbench, what we do with it, and what never leaves your machine. We have tried to write it so that a firmware engineer can verify each claim against what the product actually does.
Who we are
Hero Instruments, Inc., 5636 Saint Bernard Avenue, New Orleans, Louisiana 70122, is the data controller for the processing described here. For privacy questions or to exercise any of the rights below, contact info@heroinstruments.com.
This policy covers the BLE Hero Workbench extension for Visual Studio Code, this website (including the documentation), and the account service behind them.
Information you give us
Your account
You can sign in either with a one-time link sent to your email address or with a password, so we store that address and the sign-in timestamps that come with it. If you choose a password, our account platform keeps only a cryptographic hash of it, which cannot be turned back into the password you typed. We never see or store the password itself, and no one at our company can read it or tell you what it is.
Teams
If you invite someone to your team, you give us their email address so we can send the invitation and show them in your member list. We use it for that purpose only. If you invite a person who does not go on to create an account, tell us and we will remove the pending invitation.
Waitlist
If you ask to be notified about availability, we store your email address together with the page that referred you, your browser user agent, and the time you signed up. The referrer and user agent help us tell genuine sign-ups from automated ones. We use waitlist addresses only to tell you when the product is available, and every message includes a way to unsubscribe. The list is not readable by other users.
The sign-up form is protected by Cloudflare Turnstile, a bot check that runs in your browser. It receives your IP address and basic signals about the browser session in order to tell a person from a script. It does not track you across sites and it does not set advertising cookies.
Beta application
If you go on to apply for the beta, we store the answers you give: your name and job title, your company and its website, your technical background, and what you want to use Hero Workbench for. We use them to decide who joins a beta with a limited number of places, and for nothing else. We do not sell them and we do not use them for advertising.
Your shipping address is collected for one reason: so we can ship you a Bluetooth® LE adapter. It is not used to profile you, and if we never send you anything it is never used at all. It leaves us in only two places: the carrier that delivers the hardware, and the address check described next. When it ships we email you the carrier and the tracking number, and we keep that number so we can tell you where the parcel is if you ask.
If you ask us for hardware, your address is checked when you submit. The address you typed is sent once to Google’s address validation service, so we can offer you a corrected version to accept or ignore before the application goes through. It is skipped for countries the service does not cover, and if the check is unavailable your application submits anyway. We keep no result from it: if you accept a correction it goes into the form fields, and what we store is the address as you confirmed it. Google’s handling of that request is governed by its own privacy policy and Google Maps Platform terms. Decline the hardware and no address is collected, so none is sent.
We also record that you accepted the Beta Test Agreement: which document, which version of it, when, and a one-way hash of your IP address. That record exists so both sides can tell which text was agreed to, and it is kept for as long as the agreement is in force.
We also store a one-way hash of your IP address against the sign-up. Hashing means we keep a fingerprint that can be compared against another sign-up from the same network, but that cannot be turned back into the address itself. We never store the address. Its only use is to cap how many sign-ups one network can make in a day, which is what stops an automated script from using our sign-up form to send mail to people who never asked for it.
Billing
Payments run through Stripe. Card numbers and payment credentials go directly to Stripe and never reach our systems. What we store against your account is limited to the identifiers and status we need in order to know what you are entitled to:
- your Stripe customer and subscription identifiers,
- your subscription status and tier (Standard, Advanced, or Elite),
- the end of your current billing period, and whether a cancellation is pending,
- your Harald credit balance, and a record of what each request consumed, if you use Harald on our hosted service. See below.
Content you choose to sync
Account sync is optional. When you enable it, the items you have saved in Hero Workbench are stored in your account so they are available on your other machines: your settings, emulated peripheral definitions, parsers, workflows, and workflow scripts.
Sharing an item with a colleague today is a deliberate act on your part: you export the file and send it. We do not do it for you.
Harald
Harald is the Bluetooth LE agent built into Hero Workbench, operating your devices and diagnosing what happened, which means that when you send Harald a message we also send a snapshot of the current Bluetooth LE state so the answer is useful. That snapshot includes device addresses, device names, and signal strength for the devices you have discovered, along with a summary of your recent actions.
Harald reaches Anthropic's Claude models through our hosted service, on a plan that includes it.
Your message and the state snapshot pass through our servers on the way to Anthropic. We forward the request and stream the reply back. We do not store the contents of the request or the reply. We do record how much it consumed of your monthly credit allowance: the number of tokens in and out, the model that served it, the time, and the resulting credit cost. That record is what the credit balance in Hero Workbench is computed from, and it is what lets us answer you if a charge looks wrong; we keep it for the life of your account and you can ask us for it. Our hosting provider records ordinary operational metadata about the request, such as the time, the response status, and the duration, which we keep for no more than 30 days. Anthropic processes the request as our subprocessor and retains data according to its own terms.
Your conversations with Harald are stored locally by your editor, not by us. If you would rather none of this data leave your machine, do not use Harald. Every other part of Hero Workbench works without it.
Diagnostics you send us
Two features send a bundle of your own diagnostic data to us, and neither one does it on its own. Both show you the exact text that would be sent, and both wait for you to agree. What you see in that preview is byte for byte what is uploaded; there is no separate cleaned-up version.
- Feedback reports. When you report a problem from inside Hero Workbench you can attach a diagnostics bundle. It holds recent lines from your log channels along with your extension version, editor version, and operating system. Clear the checkbox and only your message is sent. You can also ask Harald to write and send the report for you. Harald composes it from the session and shows you the whole thing, report and attachment together, on a prompt you have to approve before any of it is sent.
- Expert analysis. When Harald escalates a hard diagnostic question, it gathers the recorded events for the one device in question, its link parameter history, and recent lines from your radio logs. We analyse that bundle on our servers and return the diagnosis. It runs only for the device and question at hand, only when you approve the prompt that shows you the contents, and never in the background.
Both bundles are masked before you see them and before they are sent. Device addresses and names are replaced with placeholders, and access tokens, home directory paths, and email addresses other than your own are removed. Masking is not perfect: a bundle is drawn from your logs, so treat the preview as the thing to check rather than as a guarantee. Characteristic payload bytes are kept by default, because they are usually the most useful part of a report; a setting turns them off.
We keep these bundles for 12 months and use them only to answer the report or the question they came with. Ask us and we will delete one without touching the rest of the report.
What stays on your machine
Hero Workbench does its Bluetooth LE work locally. Unless you enable sync, use Harald, or send us a diagnostics bundle as described above, the following are held on your computer and are never transmitted to us:
- the devices you discover, including their addresses, names, and advertising data,
- the services, characteristics, and values you read or write,
- your logs and HCI traces, except the excerpts in a bundle you choose to send,
- your workflows, parsers, scripts, and emulated peripheral definitions,
- your conversations with Harald.
No analytics or usage tracking in the product
BLE Hero Workbench contains no analytics and no crash reporting. We do not count which features you open, and we do not know which devices you connect to. This website sets no advertising cookies. The only cookie we set is one that lets our own team preview the site before launch; it lasts 30 days and carries nothing about you. If you sign in, your session is held in your browser’s local storage so that you stay signed in between visits. Signing out removes it.
The website itself is the one place we do count something. It uses Vercel Web Analytics to record page views, so we can see which pages people read and which ones they never find. It sets no cookies, it does not follow you to other sites, and it gives us counts rather than a profile: the page you opened, the page that sent you to it, and coarse details such as country, browser, and device type. It runs on this website only. It is not in BLE Hero Workbench, and it never sees what you do inside the product.
There are two exceptions. The first exists only because we are paying a third party on your behalf. Harald includes a monthly credit allowance on the Elite plan, so we record, per request: how much text went in and came out, measured in tokens; which model served it; the time; and the resulting credit cost. We do not read, store, or analyse the content of your conversations to do this, and we do not use any of it to build a profile of how you work. It is metering, in the same sense a utility meter is metering, and we keep it so we can show you an accurate balance and answer you if a charge looks wrong.
The second is about the software, not about your work, and there are two pieces of it. When you download a build, whether from this website or from the update prompt inside the editor, we record which version you took, which kind of machine it was for, and when. And when Hero Workbench refreshes your access, it tells us which version it is running, which kind of machine it is on, and which version of VS Code. That is the entire contents: three strings and a time. It carries nothing about which features you open, which devices you scan, what your projects are called, or what is in your logs.
We keep it for one reason. We send beta testers a build and an adapter, and until now a tester who downloaded it and never got it running was invisible to us, so the only way to find out was to email and ask. Knowing which version reached which account also means we can tell whether a bad build is still out there. It is not used to profile how you work, it is not sold, and it is not shared.
Requests Hero Workbench makes to others
Two features reach third parties directly from your machine, sending only what the request needs:
- Documentation lookups query
docs.nordicsemi.com,docs.zephyrproject.org, anddocs.mcuboot.comwith your search terms. - Update checks query
api.github.comto see whether a newer release exists.
During the beta the extension is downloaded from this website rather than from a marketplace. Asking for a download tells us that your account did so, and the file itself is served by GitHub, which sees the request from your machine under its own privacy policy. There are no install counts and no marketplace listing.
Who we share data with
We do not sell personal data and we do not share it for advertising. We use a small number of service providers to run the product, each processing data on our instructions only. They are listed, with what each one handles, on our subprocessors page. We update that page before adding a new provider.
We may disclose data if the law requires it, and we will tell you unless we are prohibited from doing so.
Where data is held
Our account database and functions run in the United States (us-east-1). Our providers may process data in other countries. Where that involves a transfer out of the UK or the European Economic Area, we rely on the standard contractual clauses or another lawful transfer mechanism with the provider concerned.
How long we keep it
- Account and synced content: for as long as your account is open. After you close it, we delete them within 30 days.
- Billing records: for as long as tax and accounting law requires us to keep them, which is longer than the life of your account.
- Waitlist entries: up to 24 months, or until you unsubscribe.
- Diagnostic bundles you send us: 12 months, or until you ask us to delete them.
- Operational server logs: no more than 30 days.
Your rights
Depending on where you live, you have some or all of the following rights over your personal data: to access it, to get a copy in a portable form, to correct it, to have it deleted, to restrict or object to how we use it, and to withdraw consent where we relied on it. You also have the right to complain to your data protection authority.
To exercise any of these, email info@heroinstruments.com. We will respond within one month. We do not charge for this and we will not treat you differently for asking.
Children
BLE Hero Workbench is a professional engineering tool and is not directed at children. We do not knowingly collect data from anyone under 16.
Changes to this policy
If we change how we handle your data we will update this page and move the effective date at the top. For changes that materially affect you, such as adding usage analytics or a new category of data, we will tell you in the product or by email before the change takes effect.
Contact
Hero Instruments, Inc.
5636 Saint Bernard Avenue, New Orleans, Louisiana 70122
info@heroinstruments.com
This policy is governed by the law of the State of Delaware, USA.