Privacy Policy

Last updated: 23 July 2026

Draft — pending legal review. This page describes how we intend to handle personal information under the Australian Privacy Principles (APPs), but has not yet been reviewed by a lawyer and is not final. The data-residency section in particular is marked below as needing a fact-check against current infrastructure before this policy is published for real.

1. What this policy covers

This policy explains what personal information Heimdall collects when you create an account and provision a platform, and how we handle it. It doesn't cover the data your platform's own members submit into your platform — as the platform owner, you control that, and you should have your own privacy notice for your platform's end users.

2. What we collect

  • Account details you give us: name, email address, and your passkey's public key (WebAuthn — we never see or store a password);
  • Platform configuration: your chosen subdomain, plan, and platform settings;
  • Billing information, handled directly by Stripe — we don't store your card details ourselves;
  • Standard technical logs (sign-in events, request logs) kept for security and abuse prevention.

3. How we use it

We use your information to create and run your account, provision and bill your platforms, respond to support requests, and protect the service from abuse. We don't use it for advertising, and we don't sell it.

4. Who we share it with

We share the minimum necessary with the subprocessors that make the service work:

  • Stripe — payment processing and subscription billing;
  • Resend — transactional email (invites, notifications);
  • Cloudflare — DNS and network routing/tunnelling to your platform;
  • AWS — for encrypted off-site backup and attachment storage.

Any additional subprocessor would need to meet the same review Stripe, Resend, Cloudflare, and AWS did before we'd use it, and we'd update this list if that changed.

5. Where your data is stored

Needs a fact-check before publishing: confirm current hosting region against live infrastructure, not just the design target below.

We design and operate this service with the goal of keeping compute, storage, and database resources within Australia, in line with the Australian Privacy Principles (APPs). Backups are stored in Sydney (ap-southeast-2). If a platform is ever provisioned outside Australia — for example during a temporary regional outage — we'll disclose that here rather than let it stand as a silent assumption.

6. How we protect it

Traffic is encrypted in transit (TLS 1.3) and data is encrypted at rest. Platform servers have no open inbound ports — all traffic is routed through an encrypted Cloudflare tunnel. Every change to your platform's data is recorded as an auditable event, not silently overwritten. See our FAQ for more detail.

7. Access, correction, and deletion

You can view and update your account details, and export your platform's data, at any time from your account. You can request correction or deletion of your personal information by contacting us; we'll action this unless we're required to retain something by law (for example, billing records).

8. Retention

We keep account and platform data for as long as your account is active, plus a reasonable period after account deletion to allow for backup rotation and recovery from accidental deletion, after which it's permanently removed.

9. Changes to this policy

We may update this policy from time to time. We'll post the updated version here with a new "last updated" date, and for material changes we'll make a reasonable effort to notify you directly.

10. Contact

Questions about this policy, or requests about your personal information, can be raised from your account page.