Privacy
What is written below is what this website does, which is mechanical and checkable. What the service does with a customer's evidence is a legal document, and it is the owner's to write and a lawyer's to sign off.
What this website collects
Nothing is asked for and nothing is stored on this site. There is no form but the one below, no account, and no sign-in. The console is a separate service on a separate hostname, and this site sets no cookie that reaches it.
Cookies
This deployment sets no cookies at all. No analytics property is configured for it, so there is nothing to ask permission for and no banner is shown.
Analytics
This deployment measures nothing. No analytics property exists for this domain, so no request is made to any other host from any page on this site.
The service
Heliograph Cloud is not open to customers, so the service holds no customer data today and this says what it will hold when it does. Captured log bodies are stored in plaintext, because searching and alerting on them is what the service is for, and they are kept in Cloudflare R2 and D1 created in the EU jurisdiction. Station-side redaction masks credentials before delivery and is a safety net rather than a guarantee. We do not offer UK-only storage: Cloudflare's stores offer EU, US and FedRAMP jurisdictions and there is no UK one, which we would rather tell you now than be asked later. Processing is a separate question with a separate answer, because a Worker runs in the data centre nearest the request and constraining that is a paid add-on we have not bought. Retention, deletion, export and the full list of sub-processors are not settled yet, and the pages that will carry them are written before anybody is asked to rely on them.
This section has not been reviewed by a solicitor. It is written from the service's own design documents and says what is true today, which is that no customer data exists yet. The reviewed version replaces it before anybody is asked to rely on it.
Who to contact
Write to hello@heliograph.io, which reaches a person rather than a queue. For anything about a security weakness, dan@dbhq.uk is the address published in the source repositories and is the one to use.