Effective date: July 4, 2026 Last updated: July 22, 2026
This Privacy Policy describes how Idlehour LLC ("Bastion," "we," "us," or "our") collects, uses, shares, and protects information when you use the Bastion software, the getbastion.app website, and related services (together, the "Service"). For the purposes of the EU/UK General Data Protection Regulation ("GDPR"), Idlehour LLC is the data controller for the personal data described here.
| Data | Purpose |
|---|---|
| Email address and password (hashed) | Account creation, login, and account notices |
| Subscription plan and billing interval | Determining which features to unlock (Free / Plus / Pro) |
| Support messages | Answering your questions at chad@getbastion.app |
| Bug reports and reviews you choose to submit | Improving the product |
| Data | Purpose |
|---|---|
| Subscription status, trial dates, and license checks | Enforcing plan features and renewals |
| Payment records from our processors (last 4 digits, brand, billing country — never full card numbers) | Billing, taxes, fraud prevention, refunds |
| Basic technical logs from our servers (IP address, timestamps, request status) | Security, abuse prevention, and diagnostics; retained briefly |
If you connect a third-party service (Todoist, Apple, Google, Microsoft, Asana, TickTick, Etsy, Shopify, Gumroad, Lemon Squeezy, or a social media platform), we store the OAuth access tokens needed to keep that connection alive, encrypted at rest. For social and commerce analytics, we fetch and store the aggregate metrics those platforms return (follower counts, reach, sales figures) so your dashboards can display them. You can disconnect any platform at any time, which deletes its tokens.
When you use an AI feature (asking a question, summarizing a note, generating text), Bastion sends only the text needed for that request — your prompt plus the relevant note excerpts — directly to the AI provider:
AI requests happen only when you invoke them — nothing in your vault is sent in the background. We do not store your prompts or the AI's responses on our servers; conversation history is kept locally in your vault.
We use the information above to:
Legal bases (GDPR): performance of our contract with you (accounts, billing, features); our legitimate interests (security, service improvement, minimal diagnostics); your consent (optional integrations you connect, marketing emails if we ever send them — currently we don't); and compliance with legal obligations (tax, accounting).
We do not use your personal data for automated decision-making that produces legal or similarly significant effects.
We share personal data only with the service providers ("subprocessors") that make Bastion work, under contracts limiting their use of it:
| Provider | Role | Data involved |
|---|---|---|
| Supabase | Authentication and database hosting | Email, hashed credentials, subscription records, encrypted OAuth tokens |
| Stripe, Inc. | Payment processing | Email, billing details they collect directly |
| Paddle.com Market Ltd | Payment processing (where used) | Email, billing details they collect directly |
| Vercel, Inc. | Website hosting | Standard web server logs |
| Anthropic, PBC | Default AI provider | Text you submit in AI requests, in transit only |
| Connected platforms (Todoist, Google, Apple, Microsoft, Asana, TickTick, Etsy, Shopify, Gumroad, Lemon Squeezy, social networks) | Integrations you enable | OAuth tokens; data flows you initiate |
We may also disclose information if required by law, to protect our rights or users' safety, or as part of a merger, acquisition, or sale of assets (in which case this policy continues to apply to data collected under it).
We do not sell personal information, and we do not share it for cross-context behavioral advertising (as those terms are defined by the California Consumer Privacy Act).
getbastion.app uses only strictly necessary cookies and browser storage: keeping you signed in and remembering preferences. We do not use advertising or third-party analytics cookies, so there is no cookie-consent wall to click through.
We protect your data with industry-standard measures: TLS encryption in transit, encryption at rest, row-level security on our database, hashed passwords, and least-privilege access controls. No system is perfectly secure; if we learn of a breach affecting your personal data, we will notify you and the relevant authorities as required by law.
We are based in the United States, and the providers above process data in the US and other countries. Where GDPR applies, transfers rely on appropriate safeguards such as the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework certifications of our subprocessors.
Depending on where you live, you may have the right to:
To exercise any of these, email chad@getbastion.app. We verify requests via your account email and respond within 30 days (45 for complex CCPA requests, with notice). EU/UK residents may also lodge a complaint with their local supervisory authority; California residents may contact the California Privacy Protection Agency.
Because your notes never leave your device, the most important "data portability" is already yours: your vault is plain Markdown on your own disk.
The Service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has created an account, contact us and we will delete it.
We do not track you across other sites, so we treat all traffic as if Do Not Track were enabled.
We review this policy at least annually and update it when our practices change. For material changes we will notify you by email or a prominent notice on getbastion.app before they take effect. The "Last updated" date above always reflects the current version.
Privacy questions or requests: chad@getbastion.app
Idlehour LLC getbastion.app