Privacy Policy
What Heimdall collects, how it is used, and your choices.
Who we are
- [COMPANY LEGAL NAME], [COMPANY ADDRESS]. Send questions and requests to [PRIVACY CONTACT EMAIL].
What we collect when you create an account
- We collect your name and email. Your password is stored only as a salted scrypt hash. Passkeys store a public key and credential id, never your biometric data.
- A sign-in session expires after 2 hours idle or 7 days at most. We record the Terms and Privacy versions you accepted and when.
Security and abuse prevention
- At self-serve sign-up, when configured, Cloudflare Turnstile checks you are not automated. We record the signup’s IP address, network subnet and network (ASN) to stop abuse.
- Sign-in, sign-up and password-reset attempts are logged with IP address and browser user agent for security, scheduled for deletion after 90 days by default. Emails are not stored in that log in readable form; we use a keyed hash (HMAC).
Your content
- Files you upload, including video, audio and images, are stored in S3-compatible object storage (Cloudflare R2). Notes are stored in the database. Media files are processed to make them searchable and editable through transcription (speech-to-text), scene detection, visual captions and visual search embeddings.
- These run on Heimdall’s own processing services hosted with Railway and, when configured for GPU work, RunPod. Some transcription can run in your browser on your device. [CONTENT SALE POLICY].
AI generation
- When you use AI video generation, the image and prompt you choose are sent to a third-party AI generation provider.
Importing from social links
- When you import a public post by URL, the link is sent to third-party retrieval services (SocialKit, ScrapeCreators, HikerAPI) or fetched directly, to download the public media.
Connected social accounts
- If you connect X, Facebook, Instagram or TikTok, we store the access tokens encrypted with AES-256-GCM and use them to manage connections and publish and check posts you request. Deleting the workspace removes them.
Payments
- Stripe processes payments. It collects card details and, where tax applies, your billing address. Heimdall stores Stripe references and purchase amounts, not card numbers.
- Account and workspace emails, including verification, password reset and invitations, are sent through [EMAIL DELIVERY PROVIDER].
Diagnostics
- The service records operational logs, traces and metrics through OpenTelemetry, sent to Grafana Cloud, to run and debug it. A filter strips emails, passwords, tokens, cookies, file names, prompts, captions and transcripts from that telemetry before export.
- The marketing site and app use no advertising or third-party analytics trackers. Cookies include a sign-in session cookie and a referral cookie/local storage entry holding a referral code and landing path, capture time and an optional share reference for 90 days.
Share links and referrals
- Anyone with a share link can view what you published. Referral attribution records the referring workspace, referred user and workspace, referral code, source, optional share link, landing path and time.
Who processes data for us
- Railway: hosting, [HOSTING REGION]. Cloudflare: R2 storage, Turnstile and marketing site hosting. RunPod: GPU processing. Stripe: payments. Grafana Labs: diagnostics.
- A third-party AI generation provider: only when you use AI generation. SocialKit, ScrapeCreators and HikerAPI: only for social link imports. [EMAIL DELIVERY PROVIDER]: account and workspace emails. X, Meta and TikTok: connected-account features.
How long we keep it
- Deleted items stay in trash for the workspace’s trash retention period, 30 days by default and adjustable, before they are purged.
- Deleting your account removes your access immediately and schedules anonymization of your name and email after 7 days. A deleted-user placeholder stays on comments and assets your workspaces keep.
- Deleting a workspace blocks access for a 7-day recovery window. Media is kept for [MEDIA RETENTION AFTER WORKSPACE DELETION]. Account records: [ACCOUNT RECORDS RETENTION]. Billing records: [BILLING RECORDS RETENTION]. Security logs: scheduled for deletion after 90 days by default.
Your choices
- You can export your profile and delete your account from account settings. Account deletion requires leaving or deleting workspaces you belong to first.
- Send other requests to [PRIVACY CONTACT EMAIL]. Depending on where you live you may have further rights, and we will respond to requests at that address.
Changes to this policy
- Nothing here limits any right you have under the law that applies to you, and nothing here is a substitute for advice about your own situation.