Headroom
Effective April 13, 2026
Data controller: John Schmidt — john@headroom.pro
Account data: Your email address, collected when you request access or sign in.
Production data: Scenes, shots, images, diagrams, notes, briefs, flags, and other content you create inside Headroom. This is your data. We store it on your behalf.
Usage data: Product analytics collected via PostHog: which pages you open and which features you use. Autocapture is off and page text is masked, so the content of your scenes, shots, notes, and briefs is never sent. Events are tied to your account ID, not your email.
Technical data: Browser type, device type, and error logs, collected automatically when you use the Service.
We do not collect payment card details (handled directly by Stripe if paid tiers are introduced). We do not collect location data. We do not build advertising profiles. We do not sell your data to third parties. We do not use your data to train AI models.
If you are located in the EU/EEA, we process your personal data under the following legal bases as defined in the General Data Protection Regulation (GDPR):
Production data is stored in Supabase (PostgreSQL), hosted on AWS infrastructure in the United States. Images and files are stored in Supabase Storage (S3-compatible), also in the United States. The application is hosted on Vercel, also in the United States.
If you are located in the EU/EEA, your data is transferred to the United States. These transfers are made under appropriate safeguards. Supabase and Vercel maintain Standard Contractual Clauses (SCCs) as approved by the European Commission. You can request details of these safeguards by contacting us.
We use the following third-party services to operate Headroom:
Each of these services operates under its own privacy policy and, where applicable, maintains GDPR-compliant data processing agreements.
You have the right to:
To exercise any of these rights, email john@headroom.pro. We will respond within 30 days.
If you are located in the EU/EEA and believe we are processing your data unlawfully, you have the right to lodge a complaint with your local data protection authority. In Italy, this is the Garante per la protezione dei dati personali (garanteprivacy.it).
We would appreciate the opportunity to address your concerns directly before you contact a supervisory authority.
Your data is retained for as long as your account is active. If you request account deletion, your data will be permanently deleted within 30 days. Anonymised, aggregated analytics data (with no link back to your account) may be retained indefinitely.
Access to your data requires authentication via a one-time code sent to your email. Data in transit is encrypted via TLS. Data at rest is encrypted by Supabase. Row-level security policies ensure your production data is only accessible by your account.
No system is perfectly secure. If you discover a security issue, please report it to john@headroom.pro.
We may update this policy from time to time. We will notify you of material changes via the in-app notification bell or by email. The effective date at the top of this page reflects when the policy was last updated.
Questions about this policy or your data? john@headroom.pro