Privacy Policy

What we collect, why we are allowed to, who else touches it, and how to get it back or have it erased.

Last updated 2 September 2026

The short version

  • We collect what the product needs: who you are, what you published, who you gave access to, and a record of what happened.
  • The reports our customers publish belong to them. If you were sent a link, ask them — not us — about the contents.
  • Data is stored in London; the code serving it runs in US East. Five subprocessors, all named.
  • No selling, no advertising, and your content never trains a model.
  • Analytics on these marketing pages only, and only if you accept.

A summary, not a substitute. The numbered sections below are the ones that bind us.

1.Who we are

Deliverd is a service for publishing AI-generated reports, dashboards and interactive HTML to an audience that signs in first. It is operated by Deliverd, operating from Ireland.

For anything in this policy, including a request to exercise your rights, write to support@deliverd.dev. We answer data protection requests within 30 days.

2.Two roles, and which one applies to you

This matters more than anything else in this document, because it decides who you ask when you want something changed or deleted.

When we are the controller

For the people who hold accounts with us — you signed up, you run an organisation, you publish reports — we decide what account data to collect and why. That is the data described in section 3, and this policy governs it.

When we are a processor

The reports our customers publish, and the audiences they publish to, belong to them. If you were sent a link and signed in to read something, the organisation that published it is the controller of that report and of the record that you opened it. We host and serve it on their instructions and do not decide what goes in it.

So if you want a report corrected, taken down, or your access to it removed, ask the organisation that published it — they can act immediately and we cannot act on their content without them. If you cannot reach them, write to us and we will pass the request on and tell you that we have.

3.What we collect

We collect what the product needs to work and to be auditable. There is no advertising network, no data broker, and nothing here is sold.

Account and profile

Your email address, your name if you or your identity provider supply one, the organisations and workspaces you belong to, and your role in each. Sign-in itself is handled by Supabase Auth; where your organisation uses single sign-on, we receive the identity assertion your provider sends.

Content you publish

The HTML, Markdown and files you publish, and every prior version. We do not read published content except as automated safety checks require: at publish time we scan uploads for path traversal, unsafe file types, embedded secrets such as API keys, and scripting patterns worth flagging. Those checks are automatic and their findings are stored on the version. Nobody at Deliverd reads your reports as a matter of course.

Access and audience data

Who you granted access to, the workspaces and groups involved, share links and their settings, and the email addresses of external guests together with the one-time codes used to verify them.

Activity and audit history

Who published, opened, shared, changed or was denied access to what, with a timestamp. Audit records include the IP address the action came from; records of a report being viewed include the browser user agent. This history is insert-only by design — see the Security page — because an audit trail an administrator can quietly edit is not an audit trail.

Billing

On paid plans, Stripe processes the payment. Card numbers go to Stripe directly and never reach our servers; we store the customer and subscription identifiers, your plan, and the invoice history Stripe reports back.

Email delivery

A log of the transactional email we sent you — recipient, template and whether it was delivered — so that a missing invitation can be diagnosed.

Marketing-site analytics

Only if you accept. Nothing is loaded from Google until you do, and it covers these public pages alone: never the product, never a published report. See the Cookie Policy.

4.Why we are allowed to hold it

Under the GDPR, each of the above rests on one of these bases.

Where we rely on legitimate interests we have weighed them against your rights, and you can object — see section 8.

5.Who else touches it

We use a small number of subprocessors to run the service. Each is bound by a data processing agreement and may use the data only to provide their service to us.

Beyond these, we disclose personal data only where the law requires it, and where we are permitted to tell you, we will. If the business is ever sold or merged, account data would transfer with it and you would be told before anything changed.

We do not sell personal data, and we do not use your published content to train machine-learning models — ours or anyone else’s.

6.Where your data is processed

Accounts, access grants, audit history and published files are stored in the United Kingdom (London). The application code that serves the product and streams reports currently runs in the United States (US East), which means your data is processed there while a request is being served.

Transfers out of the European Economic Area rely on the European Commission’s Standard Contractual Clauses with each provider, and on the UK adequacy decision for storage in the United Kingdom. If your organisation needs processing confined to a particular region, write to us before you commit — we would rather tell you what is true than have you discover it in a questionnaire.

7.How long we keep it

8.Your rights

If you are in the EEA or the UK you have the right to access a copy of your personal data, to have it corrected, to have it erased, to restrict or object to how we use it, and to receive it in a portable format. Where we rely on consent you can withdraw it at any time, and withdrawing is as easy as giving it.

Email support@deliverd.dev and we will respond within 30 days. We may need to confirm who you are first, and we will only ask for what is necessary to do that.

Remember section 2: if your request concerns a report someone published to you, the organisation that published it holds the decision. We will tell you who they are where we are able to.

You can also complain to a supervisory authority. Ours is the Data Protection Commission in Ireland (6 Pembroke Row, Dublin 2, D02 X963, Ireland), and you may instead complain in the country where you live or work.

9.How we protect it

Published content is treated as untrusted and served from a separate origin that never sees your product session. Access is re-evaluated on every single request rather than once at the door, credentials are stored as hashes, and the audit trail cannot be edited — including by us.

The Security page sets all of this out in detail, along with the things the product does not do yet.

10.Children

Deliverd is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, write to us and we will delete it.

11.Changes to this policy

When this policy changes in substance we update the date at the top of the page, and for changes that materially affect account holders we email the administrators of each organisation at least 14 days before the change takes effect. Continuing to use the service after that date means the new version applies.

Questions about any of this go to support@deliverd.dev.