{
  "data": {
    "similar": [
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/statsig.json",
        "name": "Statsig",
        "score": 72.3,
        "shared": [
          "analytics.events"
        ],
        "slug": "statsig"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/growthbook.json",
        "name": "GrowthBook",
        "score": 70.1,
        "shared": [
          "analytics.events"
        ],
        "slug": "growthbook"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/posthog.json",
        "name": "PostHog",
        "score": 68.4,
        "shared": [
          "analytics.events"
        ],
        "slug": "posthog"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/amplitude.json",
        "name": "Amplitude",
        "score": 66.2,
        "shared": [
          "analytics.events"
        ],
        "slug": "amplitude"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/mixpanel.json",
        "name": "Mixpanel",
        "score": 62,
        "shared": [
          "analytics.events"
        ],
        "slug": "mixpanel"
      },
      {
        "grade": "D",
        "json": "https://www.anchorterminal.com/tools/pendo.json",
        "name": "Pendo",
        "score": 48.2,
        "shared": [
          "analytics.events"
        ],
        "slug": "pendo"
      }
    ],
    "tool": {
      "slug": "heap",
      "name": "Heap",
      "vendor": "Contentsquare (Content Square, Inc.)",
      "vendorUrl": "https://www.heap.io",
      "kind": "http-api",
      "category": "product-analytics",
      "summary": "Heap is Contentsquare's product analytics service, which captures web and mobile interactions automatically. Its server-side HTTP API accepts custom events, identities, user and account properties, and user deletion requests.",
      "url": "https://www.anchorterminal.com/tools/heap",
      "markdownUrl": "https://www.anchorterminal.com/tools/heap.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/heap.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/heap.json",
      "license": "Proprietary service under Contentsquare's master services agreement. The React Native bridge and the Node client on npm are MIT",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://heapanalytics.com",
      "packages": [
        {
          "registry": "npm",
          "name": "heap-api"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. Track, identify and property calls need only `app_id`, the environment ID shown on the Projects page and used in the web snippet, with no secret. User deletion needs an API key that an admin generates under Account, Manage, Privacy \u0026 Security, exchanged by HTTP Basic for a temporary Bearer token. No OAuth, scopes or partner approval were found in the developer docs.",
      "pricing": "freemium",
      "pricingNotes": "Free plan up to 10,000 sessions a month with six months of history, APIs included, so an agent's owner can start without a contract. Growth is priced by estimate after signup, and Pro and Premier by quote. Whether signup asks for a card was not established (https://www.heap.io/pricing, checked 2026-10-07).",
      "priceSummary": "Freemium",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs or on the pricing page (checked 2026-10-07).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 213,
        "pypiWeekly": null,
        "asOf": "2026-10-07"
      },
      "docsUrl": "https://developers.heap.io",
      "llmsTxt": "https://developers.heap.io/llms.txt",
      "capabilities": [
        "analytics.events"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "llms-txt",
        "free-tier",
        "no-oauth",
        "write-only",
        "eu-region",
        "status-page",
        "soc2",
        "sales-led"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 53,
        "grade": "D",
        "agentReady": false,
        "rank": 488,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 7,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 49,
          "maintenance": 63,
          "payments": 25,
          "reliability": 72,
          "schema": 57,
          "security": 41,
          "transparency": 64
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 72,
            "points": 14.4,
            "reason": "Graded on the server-side API with the hosted lines. Statuspage site at status.heap.io with component history (20). 15 incidents between 9 July and 7 October 2026, three marked major. Dashboards and charts failed to load from 12 to 13 July, US Connect ingestion was delayed on 20 July, and a Salesforce sync incident opened on 2 October was still open. Only one, a data latency notice on 27 July, names Data Collection, the component the API writes to (10). Rate limits published with numbers, 30 requests per 30 seconds per identity on track and 15,000 events a minute per environment on bulk track (15). No 429 or backoff guidance found, but track takes an `idempotency_key` (7). Contentsquare's support package states 99.5 per cent availability for Product Analytics Pro and Enterprise, measured on the user interface (10). The API carries no beta label (10). Total 72."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 57,
            "points": 9.26,
            "reason": "OpenAPI 3.1 fragments are embedded in the Markdown of the track and identify pages. No single spec file was found, the property pages we read had empty fragments and user deletion is prose only (15). llms.txt and a .md copy of every page (10). Descriptions state purpose, limits and reserved keys, with little on when not to use a call (12). Required fields are marked and lengths stated in prose, with string types throughout, no enums and a free-form `properties` object (8). Curl examples on every page. Track and identify document 200 and 400 with an empty object, and only user deletion describes its error body (7). SDK changelogs are dated, but no changelog or version policy for the server-side API was found. Paths mix unversioned, v1 and v0 (5). Total 57."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 49,
            "points": 7.96,
            "reason": "Responses are an empty object, so context cost is small, but there is nothing to read back (15). No pagination or filtering because the reference has no read endpoint. Bulk calls take 1,000 events or users (5). Errors on track and identify are a bare 400. User deletion returns `err.message` with 401 and 404 explained (6). `idempotency_key` on track and bulk track, and property writes overwrite, so retries are safe (15). Track needs three fields and timestamps default to now. No current official server SDK was found. heap-api on npm is 1.0.1 from 2016 (8). Total 49."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 41,
            "points": 7.18,
            "reason": "Track, identify and property calls carry no secret. The OpenAPI fragment declares an empty security requirement and the only identifier is the environment ID that the web snippet publishes. User deletion uses one admin-generated API key per account, exchanged for a temporary token. No scopes or rotation guidance found (8 of 30). Ingest is write-only by design. Deletion of up to 10,000 users has no confirmation step (5). The API returns no untrusted content (10). Audit logs are unchecked because help.heap.io answered with a bot check, so none are counted (0). Contentsquare publishes a signed security.txt valid to 31 January 2028 on contentsquare.com (not on heap.io), a disclosure policy, an invitation-only YesWeHack bounty, SOC 2 Type II and ISO 27001 (18). Total 41."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 25,
            "points": 3.13,
            "reason": "No x402, MPP or L402 (0). The Free plan and its 10,000-session limit are public. Growth needs an estimate after signup and Pro and Premier say Contact Us, so no paid price is published (5). Free plan with APIs included. No card is mentioned on the pricing page, and the signup form needs JavaScript we couldn't run (20). A person signs up in a browser and copies the environment ID (0). Total 25."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 63,
            "points": 5.51,
            "reason": "heap.js 5.3.17 shipped on 6 October 2026, but that is the browser SDK. The server-side track reference last changed on 3 June 2026 and has no changelog, so we scored this line between the two (20 of 30). heap.js 5.3.15, 5.3.16 and 5.3.17 and Android Core 0.9.5 fall inside 90 days (20). Dated public changelogs and a community at community.contentsquare.com, whose response times we didn't check (8). Client SDKs for web, Android, iOS, React Native and Flutter are current. The Node server client is from 2016 (10). CI not checked (5). Total 63."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 64,
            "points": 5.6,
            "note": "editorial 61, provenance 66",
            "reason": "Closed service with published terms, now Contentsquare's master services agreement (15). The DPA (June 2026) caps Product Analytics retention at 37 months from collection unless agreed otherwise and links the sub-processor list. heap.io still carries a 2019 website terms page from Heap Inc. beside the Contentsquare documents (22). No deprecation policy for the API was found. Contentsquare's docs carry migration guides from the Heap SDKs to the CSQ SDK without an end date that we found (4). Sub-processor list (June 2026) with locations, AWS in Ireland, Frankfurt and Virginia and OpenAI for Sense Chat (20). Total 61."
          }
        ],
        "assessment": {
          "date": "2026-10-07",
          "basis": "public evidence",
          "confidence": "low",
          "notes": {
            "ergonomics": "Responses are an empty object, so context cost is small, but there is nothing to read back (15). No pagination or filtering because the reference has no read endpoint. Bulk calls take 1,000 events or users (5). Errors on track and identify are a bare 400. User deletion returns `err.message` with 401 and 404 explained (6). `idempotency_key` on track and bulk track, and property writes overwrite, so retries are safe (15). Track needs three fields and timestamps default to now. No current official server SDK was found. heap-api on npm is 1.0.1 from 2016 (8). Total 49.",
            "maintenance": "heap.js 5.3.17 shipped on 6 October 2026, but that is the browser SDK. The server-side track reference last changed on 3 June 2026 and has no changelog, so we scored this line between the two (20 of 30). heap.js 5.3.15, 5.3.16 and 5.3.17 and Android Core 0.9.5 fall inside 90 days (20). Dated public changelogs and a community at community.contentsquare.com, whose response times we didn't check (8). Client SDKs for web, Android, iOS, React Native and Flutter are current. The Node server client is from 2016 (10). CI not checked (5). Total 63.",
            "payments": "No x402, MPP or L402 (0). The Free plan and its 10,000-session limit are public. Growth needs an estimate after signup and Pro and Premier say Contact Us, so no paid price is published (5). Free plan with APIs included. No card is mentioned on the pricing page, and the signup form needs JavaScript we couldn't run (20). A person signs up in a browser and copies the environment ID (0). Total 25.",
            "reliability": "Graded on the server-side API with the hosted lines. Statuspage site at status.heap.io with component history (20). 15 incidents between 9 July and 7 October 2026, three marked major. Dashboards and charts failed to load from 12 to 13 July, US Connect ingestion was delayed on 20 July, and a Salesforce sync incident opened on 2 October was still open. Only one, a data latency notice on 27 July, names Data Collection, the component the API writes to (10). Rate limits published with numbers, 30 requests per 30 seconds per identity on track and 15,000 events a minute per environment on bulk track (15). No 429 or backoff guidance found, but track takes an `idempotency_key` (7). Contentsquare's support package states 99.5 per cent availability for Product Analytics Pro and Enterprise, measured on the user interface (10). The API carries no beta label (10). Total 72.",
            "schema": "OpenAPI 3.1 fragments are embedded in the Markdown of the track and identify pages. No single spec file was found, the property pages we read had empty fragments and user deletion is prose only (15). llms.txt and a .md copy of every page (10). Descriptions state purpose, limits and reserved keys, with little on when not to use a call (12). Required fields are marked and lengths stated in prose, with string types throughout, no enums and a free-form `properties` object (8). Curl examples on every page. Track and identify document 200 and 400 with an empty object, and only user deletion describes its error body (7). SDK changelogs are dated, but no changelog or version policy for the server-side API was found. Paths mix unversioned, v1 and v0 (5). Total 57.",
            "security": "Track, identify and property calls carry no secret. The OpenAPI fragment declares an empty security requirement and the only identifier is the environment ID that the web snippet publishes. User deletion uses one admin-generated API key per account, exchanged for a temporary token. No scopes or rotation guidance found (8 of 30). Ingest is write-only by design. Deletion of up to 10,000 users has no confirmation step (5). The API returns no untrusted content (10). Audit logs are unchecked because help.heap.io answered with a bot check, so none are counted (0). Contentsquare publishes a signed security.txt valid to 31 January 2028 on contentsquare.com (not on heap.io), a disclosure policy, an invitation-only YesWeHack bounty, SOC 2 Type II and ISO 27001 (18). Total 41.",
            "transparency": "Closed service with published terms, now Contentsquare's master services agreement (15). The DPA (June 2026) caps Product Analytics retention at 37 months from collection unless agreed otherwise and links the sub-processor list. heap.io still carries a 2019 website terms page from Heap Inc. beside the Contentsquare documents (22). No deprecation policy for the API was found. Contentsquare's docs carry migration guides from the Heap SDKs to the CSQ SDK without an end date that we found (4). Sub-processor list (June 2026) with locations, AWS in Ireland, Frankfurt and Virginia and OpenAI for Sense Chat (20). Total 61."
          },
          "sources": [
            {
              "what": "developer docs index (llms.txt)",
              "url": "https://developers.heap.io/llms.txt",
              "seen": "2026-10-07"
            },
            {
              "what": "server-side API overview",
              "url": "https://developers.heap.io/reference/server-side-apis-overview.md",
              "seen": "2026-10-07"
            },
            {
              "what": "track reference and OpenAPI fragment",
              "url": "https://developers.heap.io/reference/track-1.md",
              "seen": "2026-10-07"
            },
            {
              "what": "bulk track reference",
              "url": "https://developers.heap.io/reference/bulk-track.md",
              "seen": "2026-10-07"
            },
            {
              "what": "identify reference",
              "url": "https://developers.heap.io/reference/identify-1.md",
              "seen": "2026-10-07"
            },
            {
              "what": "add user properties reference",
              "url": "https://developers.heap.io/reference/add-user-properties.md",
              "seen": "2026-10-07"
            },
            {
              "what": "user deletion reference",
              "url": "https://developers.heap.io/reference/user-deletion.md",
              "seen": "2026-10-07"
            },
            {
              "what": "web install snippet",
              "url": "https://developers.heap.io/docs/web.md",
              "seen": "2026-10-07"
            },
            {
              "what": "heap.js 5 changelog",
              "url": "https://developers.heap.io/docs/heapjs-5-changelog.md",
              "seen": "2026-10-07"
            },
            {
              "what": "Android changelog",
              "url": "https://developers.heap.io/docs/android-changelog.md",
              "seen": "2026-10-07"
            },
            {
              "what": "status incidents",
              "url": "https://status.heap.io/api/v2/incidents.json",
              "seen": "2026-10-07"
            },
            {
              "what": "pricing",
              "url": "https://www.heap.io/pricing",
              "seen": "2026-10-07"
            },
            {
              "what": "legal index",
              "url": "https://www.heap.io/legal",
              "seen": "2026-10-07"
            },
            {
              "what": "master services agreement (redirects to Contentsquare)",
              "url": "https://www.heap.io/legal/heap-master-services-agreement",
              "seen": "2026-10-07"
            },
            {
              "what": "contracting entities",
              "url": "https://contentsquare.com/legal/entity-schedule/",
              "seen": "2026-10-07"
            },
            {
              "what": "support package and SLA",
              "url": "https://contentsquare.com/legal/support-package-slc/",
              "seen": "2026-10-07"
            },
            {
              "what": "data processing agreement",
              "url": "https://contentsquare.com/privacy-center/data-processing-agreement/",
              "seen": "2026-10-07"
            },
            {
              "what": "sub-processors",
              "url": "https://contentsquare.com/privacy-center/subprocessors/",
              "seen": "2026-10-07"
            },
            {
              "what": "security.txt",
              "url": "https://contentsquare.com/.well-known/security.txt",
              "seen": "2026-10-07"
            },
            {
              "what": "disclosure policy",
              "url": "https://contentsquare.com/disclosure/",
              "seen": "2026-10-07"
            },
            {
              "what": "trust portal",
              "url": "https://trust.contentsquare.com/?product=heapio",
              "seen": "2026-10-07"
            },
            {
              "what": "npm heap-api",
              "url": "https://registry.npmjs.org/heap-api/latest",
              "seen": "2026-10-07"
            }
          ],
          "openQuestions": [
            "unchecked: the Heap MCP server. A help centre article titled Heap MCP overview exists at help.heap.io, which answered our reader with a Cloudflare bot check. Its URL, tools, auth, limits and plan availability are unread, so the MCP server is not graded and `analytics.query` is not listed.",
            "unchecked: everything else on help.heap.io, including audit logs, roles and permissions, SSO detail, Heap Connect setup and any export or query API documented only there.",
            "unchecked: whether free signup asks for a card. The signup page at heapanalytics.com/signup renders with JavaScript only.",
            "unchecked: the registration date of heap.io. No RDAP service answered for .io.",
            "No changelog, version policy or deprecation policy for the server-side API was found in the developer docs.",
            "No 429 response or backoff guidance was found for the server-side API."
          ]
        },
        "negative": 0,
        "verdict": "Heap's server-side API suits an agent that records events. Limits are published, bulk calls take 1,000 items and track accepts an idempotency key. The API returns no analytics, and ingest calls carry no secret beyond the environment ID. Heap's help centre lists a Heap MCP article, which a bot check stopped us reading, so the MCP server is ungraded.",
        "bestFor": "An agent that records backend events or enriches user and account properties in a company's existing Heap project, or that files privacy deletions.",
        "strengths": [
          "Rate limits are published. Track allows 30 requests per 30 seconds per identity, and bulk track 15,000 events a minute per environment",
          "Track and bulk track accept an `idempotency_key`, and bulk calls take up to 1,000 events or users per request",
          "llms.txt and a Markdown copy of every developer page, with an OpenAPI 3.1 fragment embedded in the reference pages we read",
          "Free plan with up to 10,000 sessions a month and six months of history, with APIs and the User Privacy API included",
          "Sub-processor list (June 2026) names AWS regions in Ireland, Frankfurt and Virginia, and the customer chooses Europe or the USA"
        ],
        "weaknesses": [
          "No query, export or definitions endpoint in the developer reference. Reading results needs the app, Heap Connect or the MCP server we couldn't read",
          "Track, identify and property calls carry no secret. The only identifier is the environment ID that the web snippet also publishes",
          "Three incidents marked major on status.heap.io in the 90 days to 7 October 2026, one of them still open",
          "Paid plans have no public price. Growth asks for an estimate after signup, and Pro and Premier say Contact Us",
          "Error responses for track and identify are documented as a 400 with an empty object, and no 429 guidance was found"
        ],
        "agentNotes": [
          "Send EU projects to https://c.eu.heap-api.com instead of https://heapanalytics.com. The path stays the same",
          "Pass one of `identity` or `user_id` on track, never both",
          "Set `idempotency_key` on every track event so a retry doesn't duplicate it",
          "Stay under 30 requests per 30 seconds per identity, or batch up to 1,000 events in one bulk call",
          "For deletion, exchange the app_id and API key of the Main Production environment for a token first. Any other environment ID returns Unauthorized"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "low",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 53
          }
        ],
        "editorialScores": {
          "ergonomics": 49,
          "maintenance": 63,
          "payments": 25,
          "reliability": 72,
          "schema": 57,
          "security": 41,
          "transparency": 61
        },
        "provenanceScore": 66
      },
      "connect": {
        "http": "curl -X POST \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"app_id\": \"11\",\n    \"identity\": \"alice@example.com\",\n    \"event\": \"Send Transactional Email\",\n    \"properties\": {\"subject\": \"Welcome to My App!\"}\n  }' \\\n  https://heapanalytics.com/api/track"
      },
      "letme": {
        "capability": "https://letme.dev/analytics.events",
        "tool": "https://letme.dev/heap"
      },
      "notable": [
        "Server-side reference covers track, bulk track, identify, add user properties, add account properties and user deletion, all POST calls plus one deletion status GET (https://developers.heap.io/llms.txt)",
        "Track is limited to 30 requests per 30 seconds per identity per app_id, and bulk track to 1,000 events a minute per identity and 15,000 a minute per app_id (https://developers.heap.io/reference/track-1.md, https://developers.heap.io/reference/bulk-track.md)",
        "The embedded OpenAPI fragment for track declares an empty security requirement, and the examples send only `app_id`, the environment ID used in the web snippet (https://developers.heap.io/reference/track-1.md, https://developers.heap.io/docs/web.md)",
        "User deletion takes up to 10,000 users per request, runs asynchronously and needs a token from an admin-generated API key (https://developers.heap.io/reference/user-deletion.md)",
        "status.heap.io lists 15 incidents between 9 July and 7 October 2026, three marked major, including dashboard and chart loading on 12 to 13 July (https://status.heap.io/history)",
        "A help centre article titled Heap MCP overview exists, but help.heap.io answered our reader with a bot check, so its contents are unread (https://help.heap.io/hc/en-us/articles/50560292050321-Heap-MCP-overview)",
        "Heap's legal pages now point to Contentsquare's master services agreement, DPA and sub-processor list (https://www.heap.io/legal)"
      ],
      "area": "business",
      "details": [
        {
          "label": "Surface graded",
          "value": "The server-side HTTP API at https://heapanalytics.com (EU projects at https://c.eu.heap-api.com). The Heap MCP server named in the help centre was not read"
        },
        {
          "label": "Endpoints",
          "value": "POST /api/track (single or bulk), POST /api/v1/identify, POST /api/add_user_properties, POST /api/add_account_properties, POST /api/public/v0/auth_token, POST /api/public/v0/user_deletion, GET /api/public/v0/deletion_status/:id"
        },
        {
          "label": "Credentials",
          "value": "Ingest calls send only `app_id` (the environment ID). User deletion uses HTTP Basic with app_id and an admin-generated API key to get a temporary Bearer token"
        },
        {
          "label": "Rate limits",
          "value": "Track and add user properties 30 requests per 30 seconds per identity per app_id. Bulk track 1,000 events a minute per identity and 15,000 a minute per app_id"
        },
        {
          "label": "Batch sizes",
          "value": "1,000 events per bulk track request, 1,000 users per bulk property request, 10,000 users per deletion request"
        },
        {
          "label": "Idempotency",
          "value": "`idempotency_key` on track and bulk track. Property calls overwrite the previous value"
        },
        {
          "label": "Docs for agents",
          "value": "https://developers.heap.io/llms.txt and a .md copy of each page, with OpenAPI 3.1 fragments embedded in the track and identify pages. No single spec file found"
        },
        {
          "label": "SDKs",
          "value": "Client capture SDKs for web (heap.js 5.3.17, 6 October 2026), Android, iOS, React Native and Flutter. The Node client heap-api on npm is 1.0.1 and dates from 2016"
        },
        {
          "label": "Plans",
          "value": "Free up to 10,000 sessions a month with six months of history. Growth by estimate after signup. Pro and Premier by quote. Heap Connect is an add-on for Pro and included in Premier"
        },
        {
          "label": "SLA",
          "value": "99.5 per cent availability of the user interface on Pro and Enterprise plans, with service credits, per Contentsquare's support package"
        },
        {
          "label": "Status",
          "value": "status.heap.io on Statuspage with components for Data Collection, App, Heap Connect, Session Replay, integrations and alerts"
        },
        {
          "label": "Certifications",
          "value": "SOC 2 Type II, ISO 27001, 27017, 27018 and 27701 per trust.contentsquare.com. Bug bounty on YesWeHack by invitation after a valid report"
        },
        {
          "label": "Data location",
          "value": "AWS, with the customer choosing Europe (Ireland, with Frankfurt at rest) or the USA (Virginia). OpenAI is the LLM sub-processor for Sense Chat"
        }
      ],
      "unitPrices": [
        {
          "item": "Free",
          "unit": "month",
          "usd": 0,
          "note": "up to 10,000 sessions a month"
        }
      ],
      "provenance": {
        "legalEntity": "Content Square, Inc.",
        "domain": "heap.io",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "https://www.heap.io/legal/heap-master-services-agreement",
        "privacy": "https://www.heap.io/privacy",
        "statusPage": "https://status.heap.io",
        "changelog": "https://developers.heap.io/docs/heapjs-5-changelog",
        "securityTxt": "none",
        "checked": "2026-10-07",
        "notes": [
          "The Heap master services agreement URL redirects to Contentsquare's terms at contentsquare.com/legal/terms-conditions. The entity schedule names Content Square, Inc., 60 Hudson St, New York, for customers in the Americas, and other Contentsquare entities elsewhere.",
          "heap.io/terms is a website terms of use from Heap Inc., a Delaware corporation, last updated 30 August 2019. heap.io/privacy says the Heap policy has been consolidated into Contentsquare's.",
          "API calls go to heapanalytics.com and, for EU projects, c.eu.heap-api.com. Both are Heap domains named in the vendor's docs, not heap.io itself.",
          "www.heap.io/.well-known/security.txt and heapanalytics.com/.well-known/security.txt return 404. contentsquare.com publishes a signed security.txt that expires on 31 January 2028.",
          "RDAP has no service for .io through rdap.org, so the registration date of heap.io was not established.",
          "The only changelogs found are for the SDKs (heap.js 5, Android, iOS, React Native, Flutter). No changelog for the server-side API was found."
        ],
        "score": 66,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Content Square, Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "heap.io, no registry record we could read",
            "points": 0,
            "max": 15,
            "state": "no"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "heapanalytics.com",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 5 of the 7 things a reader expects, and has 2 clauses that cost points",
            "points": 4.3,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "published, but our reader couldn't read it",
            "points": 7,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "status.heap.io",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://www.heap.io/legal/heap-master-services-agreement",
            "state": "read",
            "readAt": "2026-10-08",
            "words": 10573,
            "points": 4.3,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": false
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "This Agreement is governed by the applicable governing law as indicated above without regard to conflicts of laws provisions and without regard to the United Nations Convention on the International Sale of Goods."
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "…of Contentsquare (and its respective Affiliates) arising out of or related to the Trial Services will be limited to one thousand (US $1,000) dollars.",
                "says": "Capped at US $1,000"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "Contentsquare may suspend any use of the CS Service or remove or disable any Account or content that Contentsquare reasonably and in good faith believes violates the Agreement, including any usage restrictions, subject to Contentsquare delivering reasonable prior notice to Customer, unless: (a) it is prohibited from d…"
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": false
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "Customer shall not, and shall ensure that its Users or others under its control shall not: :"
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": true,
                "quote": "“Service Level Agreement” means Contentsquare service level agreements as may be in effect from time to time found at https://contentsquare.com/legal/support-package-slc/."
              }
            ],
            "toKnow": [
              {
                "key": "training",
                "label": "Says it may use customer content to train or improve models, and no opt-out was found",
                "found": true,
                "quote": "(ii) use Customer Data in an anonymous or aggregated form where no such information could directly identify or will reasonably be used to identify Customer, Customer’s Users or its Visitors, for benchmarking or machine learning purposes;",
                "costsPoints": true
              },
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "c. access or use the CS Service or Documentation for the purpose of: (i) developing or operating products or services intended to be offered to third parties in competition with the CS Service, or (ii) allowing access to the Account or the CS Service by a direct competitor of Contentsquare;",
                "costsPoints": true
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "The customer may not use output from the service to train, calibrate or validate other systems, or for benchmarking or software development.",
                "quote": "use the output generated from the CS Service to train, calibrate, or validate, in whole or in part, any other systems, programs or platforms, or for benchmarking, software-development, or other competitive purposes"
              },
              {
                "date": "2026-10-08",
                "text": "Each Order Form renews automatically for the same period unless either party gives written notice at least 90 days before the term ends.",
                "quote": "Order Form shall automatically renew for successive periods of the same duration as the paid Initial Term and with payment terms as provided under the Order Form (each a “Renewal Term”) unless either Party gives written notice to the other to terminate the Order Form not less than ninety (90) days"
              },
              {
                "date": "2026-10-08",
                "text": "On termination, other than the customer's termination for cause, the customer pays the amounts due for the remainder of the term of all Order Forms.",
                "quote": "(a) subject to section 7.2 (Termination for Cause by Customer), Customer will pay to Contentsquare any amounts due for the remainder of the Term of all Order Forms (to the extent permitted by law);"
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://www.heap.io/privacy",
            "state": "unreadable",
            "reason": "the page says the policy has moved and holds none of its text",
            "readAt": "2026-10-08",
            "points": 7,
            "max": 10
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/heap.json",
      "live": {
        "slug": "heap",
        "probe": {
          "target": "https://heapanalytics.com",
          "method": "get",
          "lastAt": "2026-10-08T18:20:31.332969816Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 321,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 333,
          "p95ms24h": 444,
          "samples24h": 33,
          "samples30d": 33,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 33,
              "ok": 33
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.heap.io",
          "indicator": "minor",
          "summary": "Minor Service Outage",
          "checkedAt": "2026-10-08T18:22:03.573634844Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "heap-api",
            "version": "1.0.1",
            "seenAt": "2026-10-08T16:15:35.796443098Z"
          }
        ],
        "npmWeekly": 213,
        "securityTxt": {
          "url": "https://heap.io/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:30.698501929Z"
        },
        "pages": [
          {
            "url": "https://developers.heap.io/docs/heapjs-5-changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:42.369829827Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "65fc0b011bef"
          }
        ],
        "updatedAt": "2026-10-08T18:22:03.573634844Z"
      }
    },
    "verify": {
      "accepts": "a page on heap.io or one of its subdomains",
      "badgeUrl": "https://www.anchorterminal.com/badges/heap.svg",
      "body": {
        "slug": "heap",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/heap",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/heap\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/heap.svg\" alt=\"Heap on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Heap on Anchor Terminal](https://www.anchorterminal.com/badges/heap.svg)](https://www.anchorterminal.com/tools/heap)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/heap\"\u003eHeap on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/heap",
    "json": "https://www.anchorterminal.com/tools/heap.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/heap.md",
    "slim": "https://www.anchorterminal.com/tools/heap.min.md"
  },
  "markdown": "## Overview\n\n**Grade D · 53/100 · rank #488 of 629 · #7 in Product analytics \u0026 experimentation · not agent-ready · confidence low**\n\n\n## Assessment\n\nHeap's server-side API suits an agent that records events. Limits are published, bulk calls take 1,000 items and track accepts an idempotency key. The API returns no analytics, and ingest calls carry no secret beyond the environment ID. Heap's help centre lists a Heap MCP article, which a bot check stopped us reading, so the MCP server is ungraded.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Contentsquare (Content Square, Inc.) (https://www.heap.io) |\n| Kind | HTTP API |\n| Category | Product analytics \u0026 experimentation (https://www.anchorterminal.com/categories/product-analytics) |\n| Transport | HTTP |\n| Endpoint | `https://heapanalytics.com` |\n| Auth | OAuth or key · Self-serve. Track, identify and property calls need only `app_id`, the environment ID shown on the Projects page and used in the web snippet, with no secret. User deletion needs an API key that an admin generates under Account, Manage, Privacy \u0026 Security, exchanged by HTTP Basic for a temporary Bearer token. No OAuth, scopes or partner approval were found in the developer docs. |\n| Pricing | Freemium (Freemium) · Free plan up to 10,000 sessions a month with six months of history, APIs included, so an agent's owner can start without a contract. Growth is priced by estimate after signup, and Pro and Premier by quote. Whether signup asks for a card was not established (https://www.heap.io/pricing, checked 2026-10-07). |\n| x402 | No · No x402, MPP or L402 in the developer docs or on the pricing page (checked 2026-10-07). |\n| Licence | Proprietary service under Contentsquare's master services agreement. The React Native bridge and the Node client on npm are MIT |\n| Packages | npm: `heap-api` |\n| Docs | https://developers.heap.io |\n| llms.txt | https://developers.heap.io/llms.txt |\n| Last release | 2026-10-06 |\n| npm downloads / week | 213 |\n| Surface graded | The server-side HTTP API at https://heapanalytics.com (EU projects at https://c.eu.heap-api.com). The Heap MCP server named in the help centre was not read |\n| Endpoints | POST /api/track (single or bulk), POST /api/v1/identify, POST /api/add_user_properties, POST /api/add_account_properties, POST /api/public/v0/auth_token, POST /api/public/v0/user_deletion, GET /api/public/v0/deletion_status/:id |\n| Credentials | Ingest calls send only `app_id` (the environment ID). User deletion uses HTTP Basic with app_id and an admin-generated API key to get a temporary Bearer token |\n| Rate limits | Track and add user properties 30 requests per 30 seconds per identity per app_id. Bulk track 1,000 events a minute per identity and 15,000 a minute per app_id |\n| Batch sizes | 1,000 events per bulk track request, 1,000 users per bulk property request, 10,000 users per deletion request |\n| Idempotency | `idempotency_key` on track and bulk track. Property calls overwrite the previous value |\n| Docs for agents | https://developers.heap.io/llms.txt and a .md copy of each page, with OpenAPI 3.1 fragments embedded in the track and identify pages. No single spec file found |\n| SDKs | Client capture SDKs for web (heap.js 5.3.17, 6 October 2026), Android, iOS, React Native and Flutter. The Node client heap-api on npm is 1.0.1 and dates from 2016 |\n| Plans | Free up to 10,000 sessions a month with six months of history. Growth by estimate after signup. Pro and Premier by quote. Heap Connect is an add-on for Pro and included in Premier |\n| SLA | 99.5 per cent availability of the user interface on Pro and Enterprise plans, with service credits, per Contentsquare's support package |\n| Status | status.heap.io on Statuspage with components for Data Collection, App, Heap Connect, Session Replay, integrations and alerts |\n| Certifications | SOC 2 Type II, ISO 27001, 27017, 27018 and 27701 per trust.contentsquare.com. Bug bounty on YesWeHack by invitation after a valid report |\n| Data location | AWS, with the customer choosing Europe (Ireland, with Frankfurt at rest) or the USA (Virginia). OpenAI is the LLM sub-processor for Sense Chat |\n| Capabilities | analytics.events |\n| Tags | hosted, closed-source, llms-txt, free-tier, no-oauth, write-only, eu-region, status-page, soc2, sales-led |\n| JSON | https://www.anchorterminal.com/api/v1/tools/heap.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-07 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: low. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 72 | 14.4 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 57 | 9.3 |\n| Agent ergonomics | 13% | 16.2 | 49 | 8.0 |\n| Security \u0026 auth | 14% | 17.5 | 41 | 7.2 |\n| Payments \u0026 pricing | 10% | 12.5 | 25 | 3.1 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 63 | 5.5 |\n| Transparency \u0026 trust (editorial 61, provenance 66) | 7% | 8.8 | 64 | 5.6 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **53 → D** |\n\n### Why each score\n\n- Reliability 72: Graded on the server-side API with the hosted lines. Statuspage site at status.heap.io with component history (20). 15 incidents between 9 July and 7 October 2026, three marked major. Dashboards and charts failed to load from 12 to 13 July, US Connect ingestion was delayed on 20 July, and a Salesforce sync incident opened on 2 October was still open. Only one, a data latency notice on 27 July, names Data Collection, the component the API writes to (10). Rate limits published with numbers, 30 requests per 30 seconds per identity on track and 15,000 events a minute per environment on bulk track (15). No 429 or backoff guidance found, but track takes an `idempotency_key` (7). Contentsquare's support package states 99.5 per cent availability for Product Analytics Pro and Enterprise, measured on the user interface (10). The API carries no beta label (10). Total 72.\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 57: OpenAPI 3.1 fragments are embedded in the Markdown of the track and identify pages. No single spec file was found, the property pages we read had empty fragments and user deletion is prose only (15). llms.txt and a .md copy of every page (10). Descriptions state purpose, limits and reserved keys, with little on when not to use a call (12). Required fields are marked and lengths stated in prose, with string types throughout, no enums and a free-form `properties` object (8). Curl examples on every page. Track and identify document 200 and 400 with an empty object, and only user deletion describes its error body (7). SDK changelogs are dated, but no changelog or version policy for the server-side API was found. Paths mix unversioned, v1 and v0 (5). Total 57.\n- Agent ergonomics 49: Responses are an empty object, so context cost is small, but there is nothing to read back (15). No pagination or filtering because the reference has no read endpoint. Bulk calls take 1,000 events or users (5). Errors on track and identify are a bare 400. User deletion returns `err.message` with 401 and 404 explained (6). `idempotency_key` on track and bulk track, and property writes overwrite, so retries are safe (15). Track needs three fields and timestamps default to now. No current official server SDK was found. heap-api on npm is 1.0.1 from 2016 (8). Total 49.\n- Security \u0026 auth 41: Track, identify and property calls carry no secret. The OpenAPI fragment declares an empty security requirement and the only identifier is the environment ID that the web snippet publishes. User deletion uses one admin-generated API key per account, exchanged for a temporary token. No scopes or rotation guidance found (8 of 30). Ingest is write-only by design. Deletion of up to 10,000 users has no confirmation step (5). The API returns no untrusted content (10). Audit logs are unchecked because help.heap.io answered with a bot check, so none are counted (0). Contentsquare publishes a signed security.txt valid to 31 January 2028 on contentsquare.com (not on heap.io), a disclosure policy, an invitation-only YesWeHack bounty, SOC 2 Type II and ISO 27001 (18). Total 41.\n- Payments \u0026 pricing 25: No x402, MPP or L402 (0). The Free plan and its 10,000-session limit are public. Growth needs an estimate after signup and Pro and Premier say Contact Us, so no paid price is published (5). Free plan with APIs included. No card is mentioned on the pricing page, and the signup form needs JavaScript we couldn't run (20). A person signs up in a browser and copies the environment ID (0). Total 25.\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 63: heap.js 5.3.17 shipped on 6 October 2026, but that is the browser SDK. The server-side track reference last changed on 3 June 2026 and has no changelog, so we scored this line between the two (20 of 30). heap.js 5.3.15, 5.3.16 and 5.3.17 and Android Core 0.9.5 fall inside 90 days (20). Dated public changelogs and a community at community.contentsquare.com, whose response times we didn't check (8). Client SDKs for web, Android, iOS, React Native and Flutter are current. The Node server client is from 2016 (10). CI not checked (5). Total 63.\n- Transparency \u0026 trust 64: Closed service with published terms, now Contentsquare's master services agreement (15). The DPA (June 2026) caps Product Analytics retention at 37 months from collection unless agreed otherwise and links the sub-processor list. heap.io still carries a 2019 website terms page from Heap Inc. beside the Contentsquare documents (22). No deprecation policy for the API was found. Contentsquare's docs carry migration guides from the Heap SDKs to the CSQ SDK without an end date that we found (4). Sub-processor list (June 2026) with locations, AWS in Ireland, Frankfurt and Virginia and OpenAI for Sense Chat (20). Total 61.\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (17 items): https://www.anchorterminal.com/fixes/heap.md (JSON https://www.anchorterminal.com/fixes/heap.json)\n\n### What we couldn't check\n\n- unchecked: the Heap MCP server. A help centre article titled Heap MCP overview exists at help.heap.io, which answered our reader with a Cloudflare bot check. Its URL, tools, auth, limits and plan availability are unread, so the MCP server is not graded and `analytics.query` is not listed.\n- unchecked: everything else on help.heap.io, including audit logs, roles and permissions, SSO detail, Heap Connect setup and any export or query API documented only there.\n- unchecked: whether free signup asks for a card. The signup page at heapanalytics.com/signup renders with JavaScript only.\n- unchecked: the registration date of heap.io. No RDAP service answered for .io.\n- No changelog, version policy or deprecation policy for the server-side API was found in the developer docs.\n- No 429 response or backoff guidance was found for the server-side API.\n\n### Sources\n\n- developer docs index (llms.txt): \u003chttps://developers.heap.io/llms.txt\u003e (seen 2026-10-07)\n- server-side API overview: \u003chttps://developers.heap.io/reference/server-side-apis-overview.md\u003e (seen 2026-10-07)\n- track reference and OpenAPI fragment: \u003chttps://developers.heap.io/reference/track-1.md\u003e (seen 2026-10-07)\n- bulk track reference: \u003chttps://developers.heap.io/reference/bulk-track.md\u003e (seen 2026-10-07)\n- identify reference: \u003chttps://developers.heap.io/reference/identify-1.md\u003e (seen 2026-10-07)\n- add user properties reference: \u003chttps://developers.heap.io/reference/add-user-properties.md\u003e (seen 2026-10-07)\n- user deletion reference: \u003chttps://developers.heap.io/reference/user-deletion.md\u003e (seen 2026-10-07)\n- web install snippet: \u003chttps://developers.heap.io/docs/web.md\u003e (seen 2026-10-07)\n- heap.js 5 changelog: \u003chttps://developers.heap.io/docs/heapjs-5-changelog.md\u003e (seen 2026-10-07)\n- Android changelog: \u003chttps://developers.heap.io/docs/android-changelog.md\u003e (seen 2026-10-07)\n- status incidents: \u003chttps://status.heap.io/api/v2/incidents.json\u003e (seen 2026-10-07)\n- pricing: \u003chttps://www.heap.io/pricing\u003e (seen 2026-10-07)\n- legal index: \u003chttps://www.heap.io/legal\u003e (seen 2026-10-07)\n- master services agreement (redirects to Contentsquare): \u003chttps://www.heap.io/legal/heap-master-services-agreement\u003e (seen 2026-10-07)\n- contracting entities: \u003chttps://contentsquare.com/legal/entity-schedule/\u003e (seen 2026-10-07)\n- support package and SLA: \u003chttps://contentsquare.com/legal/support-package-slc/\u003e (seen 2026-10-07)\n- data processing agreement: \u003chttps://contentsquare.com/privacy-center/data-processing-agreement/\u003e (seen 2026-10-07)\n- sub-processors: \u003chttps://contentsquare.com/privacy-center/subprocessors/\u003e (seen 2026-10-07)\n- security.txt: \u003chttps://contentsquare.com/.well-known/security.txt\u003e (seen 2026-10-07)\n- disclosure policy: \u003chttps://contentsquare.com/disclosure/\u003e (seen 2026-10-07)\n- trust portal: \u003chttps://trust.contentsquare.com/?product=heapio\u003e (seen 2026-10-07)\n- npm heap-api: \u003chttps://registry.npmjs.org/heap-api/latest\u003e (seen 2026-10-07)\n\n## Who's behind it (provenance 66/100, checked 2026-10-07)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Content Square, Inc. | 20/20 |\n| Domain age | heap.io, no registry record we could read | 0/15 |\n| Endpoint on the vendor's domain | heapanalytics.com | 15/15 |\n| Terms of service | read, states 5 of the 7 things a reader expects, and has 2 clauses that cost points | 4.3/10 |\n| Privacy policy | published, but our reader couldn't read it | 7/10 |\n| Status page | status.heap.io | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe Heap master services agreement URL redirects to Contentsquare's terms at contentsquare.com/legal/terms-conditions. The entity schedule names Content Square, Inc., 60 Hudson St, New York, for customers in the Americas, and other Contentsquare entities elsewhere.\n\nheap.io/terms is a website terms of use from Heap Inc., a Delaware corporation, last updated 30 August 2019. heap.io/privacy says the Heap policy has been consolidated into Contentsquare's.\n\nAPI calls go to heapanalytics.com and, for EU projects, c.eu.heap-api.com. Both are Heap domains named in the vendor's docs, not heap.io itself.\n\nwww.heap.io/.well-known/security.txt and heapanalytics.com/.well-known/security.txt return 404. contentsquare.com publishes a signed security.txt that expires on 31 January 2028.\n\nRDAP has no service for .io through rdap.org, so the registration date of heap.io was not established.\n\nThe only changelogs found are for the SDKs (heap.js 5, Android, iOS, React Native, Flutter). No changelog for the server-side API was found.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://www.heap.io/legal/heap-master-services-agreement), read 2026-10-08, gives no date, states 5 of the 7 things a reader expects.\n\n- To know. Says it may use customer content to train or improve models, and no opt-out was found (costs points). \"(ii) use Customer Data in an anonymous or aggregated form where no such information could directly identify or will reasonably be used to identify Customer, Customer’s Users or its Visitors, for benchmarking or machine learning purposes;\"\n- To know. Restricts benchmarking or competitive use (costs points). \"c. access or use the CS Service or Documentation for the purpose of: (i) developing or operating products or services intended to be offered to third parties in competition with the CS Service, or (ii) allowing access to the Account or the CS Service by a direct competitor of Contentsquare;\"\n- Not found in the text. Gives the date it was last updated.\n- States a limit on its liability. Capped at US $1,000.\n- Not found in the text. Says how changes to the terms are announced.\n- Also in the text (2026-10-08). The customer may not use output from the service to train, calibrate or validate other systems, or for benchmarking or software development. \"use the output generated from the CS Service to train, calibrate, or validate, in whole or in part, any other systems, programs or platforms, or for benchmarking, software-development, or other competitive purposes\"\n- Also in the text (2026-10-08). Each Order Form renews automatically for the same period unless either party gives written notice at least 90 days before the term ends. \"Order Form shall automatically renew for successive periods of the same duration as the paid Initial Term and with payment terms as provided under the Order Form (each a “Renewal Term”) unless either Party gives written notice to the other to terminate the Order Form not less than ninety (90) days\"\n- Also in the text (2026-10-08). On termination, other than the customer's termination for cause, the customer pays the amounts due for the remainder of the term of all Order Forms. \"(a) subject to section 7.2 (Termination for Cause by Customer), Customer will pay to Contentsquare any amounts due for the remainder of the Term of all Order Forms (to the extent permitted by law);\"\n\n**Privacy policy** (https://www.heap.io/privacy), read 2026-10-08. Our reader couldn't read it (the page says the policy has moved and holds none of its text).\n\n\n## Live (updated 2026-10-08 18:22 UTC)\n\n- Right now: up, HTTP 200, 321 ms, checked 2026-10-08 18:20 UTC (get on `https://heapanalytics.com`)\n- Uptime 24h 100.0% (33 probes) · 30 days 100.0% (33 probes) · p50 333 ms · p95 444 ms\n- Vendor status page: minor, Minor Service Outage\n- npm `heap-api` 1.0.1\n- security.txt: none\n- Watching changelog \u003chttps://developers.heap.io/docs/heapjs-5-changelog\u003e\n- Always current: https://www.anchorterminal.com/api/v1/live/heap.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Free | free | per month (plan) | up to 10,000 sessions a month |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- Rate limits are published. Track allows 30 requests per 30 seconds per identity, and bulk track 15,000 events a minute per environment\n- Track and bulk track accept an `idempotency_key`, and bulk calls take up to 1,000 events or users per request\n- llms.txt and a Markdown copy of every developer page, with an OpenAPI 3.1 fragment embedded in the reference pages we read\n- Free plan with up to 10,000 sessions a month and six months of history, with APIs and the User Privacy API included\n- Sub-processor list (June 2026) names AWS regions in Ireland, Frankfurt and Virginia, and the customer chooses Europe or the USA\n\n## Weaknesses\n\n- No query, export or definitions endpoint in the developer reference. Reading results needs the app, Heap Connect or the MCP server we couldn't read\n- Track, identify and property calls carry no secret. The only identifier is the environment ID that the web snippet also publishes\n- Three incidents marked major on status.heap.io in the 90 days to 7 October 2026, one of them still open\n- Paid plans have no public price. Growth asks for an estimate after signup, and Pro and Premier say Contact Us\n- Error responses for track and identify are documented as a 400 with an empty object, and no 429 guidance was found\n\n## Before you call it (notes for agents)\n\n1. Send EU projects to https://c.eu.heap-api.com instead of https://heapanalytics.com. The path stays the same\n2. Pass one of `identity` or `user_id` on track, never both\n3. Set `idempotency_key` on every track event so a retry doesn't duplicate it\n4. Stay under 30 requests per 30 seconds per identity, or batch up to 1,000 events in one bulk call\n5. For deletion, exchange the app_id and API key of the Main Production environment for a token first. Any other environment ID returns Unauthorized\n\n## Connect\n\nFirst request:\n\n```bash\ncurl -X POST \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"app_id\": \"11\",\n    \"identity\": \"alice@example.com\",\n    \"event\": \"Send Transactional Email\",\n    \"properties\": {\"subject\": \"Welcome to My App!\"}\n  }' \\\n  https://heapanalytics.com/api/track\n```\n\nThrough letme (picks today, calling later): https://letme.dev/heap. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Statsig | BB | 72.3 | 89 | analytics.events | no | https://www.anchorterminal.com/tools/statsig.md |\n| GrowthBook | BB | 70.1 | 135 | analytics.events | no | https://www.anchorterminal.com/tools/growthbook.md |\n| PostHog | B | 68.4 | 171 | analytics.events | no | https://www.anchorterminal.com/tools/posthog.md |\n| Amplitude | B | 66.2 | 223 | analytics.events | no | https://www.anchorterminal.com/tools/amplitude.md |\n| Mixpanel | B | 62 | 313 | analytics.events | no | https://www.anchorterminal.com/tools/mixpanel.md |\n| Pendo | D | 48.2 | 541 | analytics.events | no | https://www.anchorterminal.com/tools/pendo.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- Server-side reference covers track, bulk track, identify, add user properties, add account properties and user deletion, all POST calls plus one deletion status GET (source: \u003chttps://developers.heap.io/llms.txt\u003e)\n- Track is limited to 30 requests per 30 seconds per identity per app_id, and bulk track to 1,000 events a minute per identity and 15,000 a minute per app_id (source: \u003chttps://developers.heap.io/reference/track-1.md, https://developers.heap.io/reference/bulk-track.md\u003e)\n- The embedded OpenAPI fragment for track declares an empty security requirement, and the examples send only `app_id`, the environment ID used in the web snippet (source: \u003chttps://developers.heap.io/reference/track-1.md, https://developers.heap.io/docs/web.md\u003e)\n- User deletion takes up to 10,000 users per request, runs asynchronously and needs a token from an admin-generated API key (source: \u003chttps://developers.heap.io/reference/user-deletion.md\u003e)\n- status.heap.io lists 15 incidents between 9 July and 7 October 2026, three marked major, including dashboard and chart loading on 12 to 13 July (source: \u003chttps://status.heap.io/history\u003e)\n- A help centre article titled Heap MCP overview exists, but help.heap.io answered our reader with a bot check, so its contents are unread (source: \u003chttps://help.heap.io/hc/en-us/articles/50560292050321-Heap-MCP-overview\u003e)\n- Heap's legal pages now point to Contentsquare's master services agreement, DPA and sub-processor list (source: \u003chttps://www.heap.io/legal\u003e)\n\n## Compare\n\n- [Amplitude vs Heap](https://www.anchorterminal.com/compare/amplitude-vs-heap.md): B 66.2 vs D 53\n- [GrowthBook vs Heap](https://www.anchorterminal.com/compare/growthbook-vs-heap.md): BB 70.1 vs D 53\n- [Heap vs Mixpanel](https://www.anchorterminal.com/compare/heap-vs-mixpanel.md): D 53 vs B 62\n- [Heap vs Pendo](https://www.anchorterminal.com/compare/heap-vs-pendo.md): D 53 vs D 48.2\n- [Heap vs PostHog](https://www.anchorterminal.com/compare/heap-vs-posthog.md): D 53 vs B 68.4\n- [Heap vs Statsig](https://www.anchorterminal.com/compare/heap-vs-statsig.md): D 53 vs BB 72.3\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on heap.io or one of its subdomains. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"heap\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/heap\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/heap.svg\" alt=\"Heap on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Heap on Anchor Terminal](https://www.anchorterminal.com/badges/heap.svg)](https://www.anchorterminal.com/tools/heap)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/heap\"\u003eHeap on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Heap is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/heap-dark.png\n- Light: https://www.anchorterminal.com/assets/share/heap-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Product analytics \u0026 experimentation",
        "url": "https://www.anchorterminal.com/categories/product-analytics"
      },
      {
        "name": "Heap",
        "url": ""
      }
    ],
    "description": "Heap is Contentsquare's product analytics service, which captures web and mobile interactions automatically. Its server-side HTTP API accepts custom events, identities, user and account properties, and user deletion requests.",
    "facts": [
      "rank #488 of 629",
      "OAuth or key auth",
      "0 desk reviews"
    ],
    "h1": "Heap",
    "image": "https://www.anchorterminal.com/assets/og/tools-heap.png",
    "path": "/tools/heap",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Heap review for AI agents, grade D (53/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/heap"
  },
  "tokens": {
    "markdown": 6750,
    "slim": 1630
  },
  "version": 1
}
