Headroom
PRV
UK GDPR

Privacy policy

Updated 18 August 2026 · See also Security and Terms

This policy covers getheadroom.co and the hosted console at app.getheadroom.co. If you run the binary yourself, you are the controller of your deployment — this policy does not apply to data that never reaches us.

Who we are

Headroom is operated from the United Kingdom by Kyle Redelinghuys. Contact: hello@getheadroom.co.

For hosted customers we are the controller of account and billing data, and the processor of telemetry your team sends us.

What we collect

On this website

  • Sign-in. Happens on the hosted console, not this site. We collect the email you use to request a magic link.
  • Analytics. Page views via Plausible. No cookies, no fingerprinting, no personal profiles. We see aggregate counts (page, referrer, country, device class), not who you are.

This marketing site does not set cookies.

On the hosted service

  • Account. Email address, display name if a sign-in provider supplies one, team membership and role.
  • Session. An HttpOnly, Secure cookie that identifies a signed-in session. Signing out everywhere ends every session.
  • Telemetry. Metrics only — token counts, models, costs, session timings, repo and branch names, a channel label, and the seat the ingest key points at. The complete field list, and the fields we refuse, is on the security page.
  • Billing. If you pay, Stripe holds card details. We store the Stripe customer and subscription identifiers, plan, seat count and period dates — not the card number.
  • Mail. Magic-link and transactional mail (alerts you asked for) go through SendGrid. Click tracking is off, because scanners that prefetch links would spend a one-time sign-in token.

What we never collect

Prompts, completions, source code, file contents, or file paths. We do not build productivity leaderboards or compare developers to each other.

Why we use it

PurposeLawful basis (UK GDPR)
Provide the hosted product you asked forContract
Attribute spend to a seat and keep the service secureLegitimate interests — running a metering product that cannot work without a seat identity
Take payment and keep accountsContract, and legal obligation for tax records
Understand which pages on this site are readLegitimate interests — a cookie-free count of traffic

Who else sees it

  • DigitalOcean — the hosted service and this site run on a droplet in London, United Kingdom.
  • Plausible — privacy-friendly analytics for this marketing site only.
  • SendGrid — transactional email.
  • Stripe — payment, if you subscribe. Their terms apply to the card data they hold.
  • Google or Microsoft — only if you choose to sign in through them, and only after we have configured that provider.

We do not sell data. We do not use it for advertising.

How long we keep it

  • Earlier waitlist addresses. Held until you ask us to delete them, or they become an account.
  • Hosted telemetry. Raw records 90 days; daily rollups about 25 months. Free teams can see 30 days and one seat; the rest is retained but gated, not deleted, until they upgrade or the team is removed.
  • Accounts and billing identifiers. For the life of the team, then as long as tax law requires for invoices.
  • Team deletion. Ingest keys stop at once. Everything held for that team is purged within 24 hours.

Your rights

Under UK GDPR you can ask for a copy of what we hold, a correction, erasure, a restriction, or a portable export, and you can object to processing that rests on legitimate interests. Email hello@getheadroom.co. You can also complain to the Information Commissioner’s Office.

There is no newsletter. To delete an account or an older waitlist address, email the same address you used.

Self-hosted

A self-hosted deployment never sends us telemetry, accounts or licence check-ins. Licences are verified offline. If you turn on Slack, SMTP or OIDC, that traffic goes where you pointed it, not to us.

Children

Headroom is a workplace tool. We do not knowingly collect data from anyone under 16.

Changes

If this policy changes in a way that affects you, we will update the date on this page and, for hosted customers, note it in the product. The security page is the field-level list; this page is the legal one.