Headroom

Privacy Policy

Effective April 13, 2026

Data controller: John Schmidt — john@headroom.pro

1. What We Collect

Account data: Your email address, collected when you request access or sign in.

Production data: Scenes, shots, images, diagrams, notes, briefs, flags, and other content you create inside Headroom. This is your data. We store it on your behalf.

Usage data: Product analytics collected via PostHog: which pages you open and which features you use. Autocapture is off and page text is masked, so the content of your scenes, shots, notes, and briefs is never sent. Events are tied to your account ID, not your email.

Technical data: Browser type, device type, and error logs, collected automatically when you use the Service.

2. What We Don't Collect

We do not collect payment card details (handled directly by Stripe if paid tiers are introduced). We do not collect location data. We do not build advertising profiles. We do not sell your data to third parties. We do not use your data to train AI models.

3. Legal Basis for Processing (GDPR)

If you are located in the EU/EEA, we process your personal data under the following legal bases as defined in the General Data Protection Regulation (GDPR):

  • Contract performance (Art. 6(1)(b)). Processing your email address and account data to provide the Service you requested.
  • Legitimate interests (Art. 6(1)(f)). Anonymous usage analytics to improve the product. These do not override your rights and freedoms.
  • Legal obligation (Art. 6(1)(c)). Where processing is required to comply with applicable law.

4. How We Use Your Data

  • To provide and operate the Service
  • To send authentication codes and account-related emails
  • To notify you of new features or important Service changes
  • To improve the product based on anonymous usage patterns
  • To respond to support requests

5. Where Your Data Is Stored

Production data is stored in Supabase (PostgreSQL), hosted on AWS infrastructure in the United States. Images and files are stored in Supabase Storage (S3-compatible), also in the United States. The application is hosted on Vercel, also in the United States.

If you are located in the EU/EEA, your data is transferred to the United States. These transfers are made under appropriate safeguards. Supabase and Vercel maintain Standard Contractual Clauses (SCCs) as approved by the European Commission. You can request details of these safeguards by contacting us.

6. Third-Party Services

We use the following third-party services to operate Headroom:

  • Supabase: database, authentication, and file storage (US)
  • Vercel: application hosting (US)
  • PostHog: anonymous product analytics
  • Resend: transactional email delivery
  • Sentry: application error monitoring (EU)

Each of these services operates under its own privacy policy and, where applicable, maintains GDPR-compliant data processing agreements.

7. Your Rights

You have the right to:

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Correct inaccurate personal data
  • Erasure: Request deletion of your account and all associated data
  • Portability: Export your production data as JSON via Settings → Your Data
  • Restriction: Request that we limit processing of your data in certain circumstances
  • Objection: Object to processing based on legitimate interests

To exercise any of these rights, email john@headroom.pro. We will respond within 30 days.

8. Right to Lodge a Complaint

If you are located in the EU/EEA and believe we are processing your data unlawfully, you have the right to lodge a complaint with your local data protection authority. In Italy, this is the Garante per la protezione dei dati personali (garanteprivacy.it).

We would appreciate the opportunity to address your concerns directly before you contact a supervisory authority.

9. Data Retention

Your data is retained for as long as your account is active. If you request account deletion, your data will be permanently deleted within 30 days. Anonymised, aggregated analytics data (with no link back to your account) may be retained indefinitely.

10. Security

Access to your data requires authentication via a one-time code sent to your email. Data in transit is encrypted via TLS. Data at rest is encrypted by Supabase. Row-level security policies ensure your production data is only accessible by your account.

No system is perfectly secure. If you discover a security issue, please report it to john@headroom.pro.

11. Changes to This Policy

We may update this policy from time to time. We will notify you of material changes via the in-app notification bell or by email. The effective date at the top of this page reflects when the policy was last updated.

12. Contact

Questions about this policy or your data? john@headroom.pro

Terms of Service →