Privacy Policy

Effective date: July 4, 2026 Last updated: July 22, 2026

This Privacy Policy describes how Idlehour LLC ("Bastion," "we," "us," or "our") collects, uses, shares, and protects information when you use the Bastion software, the getbastion.app website, and related services (together, the "Service"). For the purposes of the EU/UK General Data Protection Regulation ("GDPR"), Idlehour LLC is the data controller for the personal data described here.


The Short Version

  • Your notes never leave your device. Bastion is a local-first app. Your vault content is processed on your machine, not on our servers.
  • We collect the minimum we need to run accounts and subscriptions — and nothing about the contents of your vault.
  • AI features only send text when you ask them to, directly to the AI provider you've chosen.
  • We never sell your personal information, and we never share it for cross-context behavioral advertising.

1. Information We Collect

1.1 Information you provide

DataPurpose
Email address and password (hashed)Account creation, login, and account notices
Subscription plan and billing intervalDetermining which features to unlock (Free / Plus / Pro)
Support messagesAnswering your questions at chad@getbastion.app
Bug reports and reviews you choose to submitImproving the product

1.2 Information collected automatically

DataPurpose
Subscription status, trial dates, and license checksEnforcing plan features and renewals
Payment records from our processors (last 4 digits, brand, billing country — never full card numbers)Billing, taxes, fraud prevention, refunds
Basic technical logs from our servers (IP address, timestamps, request status)Security, abuse prevention, and diagnostics; retained briefly

1.3 Integration data you authorize

If you connect a third-party service (Todoist, Apple, Google, Microsoft, Asana, TickTick, Etsy, Shopify, Gumroad, Lemon Squeezy, or a social media platform), we store the OAuth access tokens needed to keep that connection alive, encrypted at rest. For social and commerce analytics, we fetch and store the aggregate metrics those platforms return (follower counts, reach, sales figures) so your dashboards can display them. You can disconnect any platform at any time, which deletes its tokens.

1.4 What we explicitly do NOT collect

  • Vault content. Your notes, tasks, headings, file names, and everything else inside your vault are never transmitted to or stored on our servers.
  • Behavioral tracking. No advertising trackers, no cross-site tracking, no selling of data.
  • Full payment card details. Stripe and Paddle handle those; we never see them.

2. AI Features and Your Data

When you use an AI feature (asking a question, summarizing a note, generating text), Bastion sends only the text needed for that request — your prompt plus the relevant note excerpts — directly to the AI provider:

  • Default: Anthropic (Claude). Anthropic's API terms state that API data is not used to train their models.
  • Bring your own key: if you configure OpenAI, Google, xAI, OpenRouter, or another provider, requests go to that provider under your own account and their terms.

AI requests happen only when you invoke them — nothing in your vault is sent in the background. We do not store your prompts or the AI's responses on our servers; conversation history is kept locally in your vault.


3. How We Use Information

We use the information above to:

  • Provide, maintain, and improve the Service
  • Create and manage your account and subscription
  • Process payments, trials, refunds, and taxes
  • Operate the integrations you have connected
  • Respond to support requests
  • Send transactional emails (receipts, renewal and trial notices, security alerts, material policy changes)
  • Protect the Service against fraud and abuse, and comply with legal obligations

Legal bases (GDPR): performance of our contract with you (accounts, billing, features); our legitimate interests (security, service improvement, minimal diagnostics); your consent (optional integrations you connect, marketing emails if we ever send them — currently we don't); and compliance with legal obligations (tax, accounting).

We do not use your personal data for automated decision-making that produces legal or similarly significant effects.


4. How We Share Information

We share personal data only with the service providers ("subprocessors") that make Bastion work, under contracts limiting their use of it:

ProviderRoleData involved
SupabaseAuthentication and database hostingEmail, hashed credentials, subscription records, encrypted OAuth tokens
Stripe, Inc.Payment processingEmail, billing details they collect directly
Paddle.com Market LtdPayment processing (where used)Email, billing details they collect directly
Vercel, Inc.Website hostingStandard web server logs
Anthropic, PBCDefault AI providerText you submit in AI requests, in transit only
Connected platforms (Todoist, Google, Apple, Microsoft, Asana, TickTick, Etsy, Shopify, Gumroad, Lemon Squeezy, social networks)Integrations you enableOAuth tokens; data flows you initiate

We may also disclose information if required by law, to protect our rights or users' safety, or as part of a merger, acquisition, or sale of assets (in which case this policy continues to apply to data collected under it).

We do not sell personal information, and we do not share it for cross-context behavioral advertising (as those terms are defined by the California Consumer Privacy Act).


5. Cookies and Local Storage

getbastion.app uses only strictly necessary cookies and browser storage: keeping you signed in and remembering preferences. We do not use advertising or third-party analytics cookies, so there is no cookie-consent wall to click through.


6. Data Retention

  • Account data — kept while your account is active, deleted within 30 days of a verified deletion request.
  • Subscription and payment records — kept as long as required for tax and accounting law (typically 7 years).
  • OAuth tokens — deleted immediately when you disconnect a platform or delete your account.
  • Server logs — retained for a short rolling window (no more than 90 days) for security and diagnostics.

7. Security

We protect your data with industry-standard measures: TLS encryption in transit, encryption at rest, row-level security on our database, hashed passwords, and least-privilege access controls. No system is perfectly secure; if we learn of a breach affecting your personal data, we will notify you and the relevant authorities as required by law.


8. International Transfers

We are based in the United States, and the providers above process data in the US and other countries. Where GDPR applies, transfers rely on appropriate safeguards such as the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework certifications of our subprocessors.


9. Your Rights

Depending on where you live, you may have the right to:

  • Access a copy of the personal data we hold about you
  • Correct inaccurate data
  • Delete your data ("right to be forgotten")
  • Export your data in a portable format
  • Object to or restrict certain processing
  • Withdraw consent where processing is based on consent
  • Not be discriminated against for exercising any of these rights (CCPA)

To exercise any of these, email chad@getbastion.app. We verify requests via your account email and respond within 30 days (45 for complex CCPA requests, with notice). EU/UK residents may also lodge a complaint with their local supervisory authority; California residents may contact the California Privacy Protection Agency.

Because your notes never leave your device, the most important "data portability" is already yours: your vault is plain Markdown on your own disk.


10. Children

The Service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has created an account, contact us and we will delete it.


11. Do Not Track

We do not track you across other sites, so we treat all traffic as if Do Not Track were enabled.


12. Changes to This Policy

We review this policy at least annually and update it when our practices change. For material changes we will notify you by email or a prominent notice on getbastion.app before they take effect. The "Last updated" date above always reflects the current version.


13. Contact

Privacy questions or requests: chad@getbastion.app

Idlehour LLC getbastion.app