Privacy Policy
Last updated: 23 July 2026
1. What this policy covers
This policy explains what personal information Heimdall collects when you create an account and provision a platform, and how we handle it. It doesn't cover the data your platform's own members submit into your platform — as the platform owner, you control that, and you should have your own privacy notice for your platform's end users.
2. What we collect
- Account details you give us: name, email address, and your passkey's public key (WebAuthn — we never see or store a password);
- Platform configuration: your chosen subdomain, plan, and platform settings;
- Billing information, handled directly by Stripe — we don't store your card details ourselves;
- Standard technical logs (sign-in events, request logs) kept for security and abuse prevention.
3. How we use it
We use your information to create and run your account, provision and bill your platforms, respond to support requests, and protect the service from abuse. We don't use it for advertising, and we don't sell it.
4. Who we share it with
We share the minimum necessary with the subprocessors that make the service work:
- Stripe — payment processing and subscription billing;
- Resend — transactional email (invites, notifications);
- Cloudflare — DNS and network routing/tunnelling to your platform;
- AWS — for encrypted off-site backup and attachment storage.
Any additional subprocessor would need to meet the same review Stripe, Resend, Cloudflare, and AWS did before we'd use it, and we'd update this list if that changed.
5. Where your data is stored
We design and operate this service with the goal of keeping compute, storage, and database
resources within Australia, in line with the Australian Privacy Principles (APPs). Backups are
stored in Sydney (ap-southeast-2). If a platform is ever provisioned outside
Australia — for example during a temporary regional outage — we'll disclose that here rather
than let it stand as a silent assumption.
6. How we protect it
Traffic is encrypted in transit (TLS 1.3) and data is encrypted at rest. Platform servers have no open inbound ports — all traffic is routed through an encrypted Cloudflare tunnel. Every change to your platform's data is recorded as an auditable event, not silently overwritten. See our FAQ for more detail.
7. Access, correction, and deletion
You can view and update your account details, and export your platform's data, at any time from your account. You can request correction or deletion of your personal information by contacting us; we'll action this unless we're required to retain something by law (for example, billing records).
8. Retention
We keep account and platform data for as long as your account is active, plus a reasonable period after account deletion to allow for backup rotation and recovery from accidental deletion, after which it's permanently removed.
9. Changes to this policy
We may update this policy from time to time. We'll post the updated version here with a new "last updated" date, and for material changes we'll make a reasonable effort to notify you directly.
10. Contact
Questions about this policy, or requests about your personal information, can be raised from your account page.