Privacy Policy
Burg
Last updated: 11 September 2026
This policy explains what personal data Burg collects, why, who it is shared with, and what rights you have over it. Burg is operated by Get a Head Studio ("we", "us"), which is the data controller for the purposes of the UK and EU GDPR.
Contact: hello@getahead.studio
[TO FILL IN] Add a postal address. GDPR expects controller contact details to include one, and app stores and some enterprise users ask for it.
1. What we collect
Account data. Your email address, an encrypted password credential, and account timestamps (created, last sign-in). Because Burg is invite-only, your email usually comes to us from the person who asked us to create your account, rather than from you directly.
Content you create. Everything you put into your workspace: documents, data tables, bulletin boards, whiteboards, links and embeds, the structure of your city (neighbourhoods, buildings, roads), and files you upload. This content may itself contain personal data — about you or about other people — depending on what you write and upload. You decide what goes in.
Technical and log data. Our hosting and database providers record standard server information when you use the Service: IP address, browser user-agent, request paths and timestamps, and error traces. These logs exist for security, debugging, and abuse prevention.
Session cookies. We set cookies that keep you signed in and maintain your session. These are strictly necessary for the Service to work.
What we do not collect. We do not run third-party analytics, advertising, or tracking scripts. We do not sell personal data, and we do not share it for cross-context behavioural advertising. We do not use your content to train machine learning models.
[VERIFY] The "what we do not collect" paragraph is written to match the stack in the repo README. If you later add an analytics tool, error-reporting service (e.g. Sentry), or an AI feature that sends content to a model provider, this paragraph and section 4 both need updating before you ship it.
2. Why we use it, and on what legal basis
| What we do | Why | Legal basis (UK/EU GDPR) |
|---|---|---|
| Create and authenticate your account | So you can sign in and only you can reach your workspace | Performance of a contract |
| Store, render, index, and search your content | It is the core function of the Service | Performance of a contract |
| Keep server and database logs | Security, debugging, abuse prevention | Legitimate interests |
| Email you about the Service | Outage notices, policy changes, account issues | Legitimate interests / legal obligation |
| Respond to your support requests | To help you | Performance of a contract / legitimate interests |
| Comply with legal requests | Because we have to | Legal obligation |
We do not send marketing email. If that ever changes, it will be opt-in and separately consented to.
3. Where your data is processed
The application runs on Render in the Oregon (US West) region. The database, authentication system, and file storage run on Supabase. If you are outside the United States, your personal data is transferred to and processed in the US.
For transfers from the UK or EEA, we rely on the Standard Contractual Clauses incorporated into our providers' data processing agreements.
4. Who we share it with
We share personal data only with the infrastructure providers that make the Service run. They act as our processors and may only use the data to provide their services to us.
| Provider | What they handle | Where |
|---|---|---|
| Render | Application hosting, request logs | United States (Oregon) |
| Supabase | Database, authentication, file storage, backups | United States |
We do not sell or rent personal data. We may disclose data if required by law, court order, or valid legal process, or where necessary to protect our rights, our users, or the public — and we will tell you if we are permitted to.
If the Service is ever transferred to another operator, we will give you notice before your data moves, so you can export it or close your account first.
5. Security
Access to workspaces is enforced at the database level with row-level security, so one account's queries cannot reach another account's rows. Traffic is encrypted in transit with TLS. Data is encrypted at rest by our hosting providers. Public signup is disabled, so accounts exist only where we have created them.
No system is completely secure, and we cannot guarantee the security of data transmitted to or stored on the Service. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and affected users as required by law.
6. How long we keep it
- Your content: until you delete it, or until your account is deleted.
- Account data: for as long as your account is open.
- After account deletion: we delete your account and content within 30 days, except
where we must keep something to comply with a legal obligation.
- Backups: deleted content may persist in provider backups for a short period after
deletion, until those backups roll over.
- Server logs: retained according to our providers' default log retention, typically a
matter of days to weeks.
7. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you;
- correct data that is inaccurate;
- delete your data ("right to erasure");
- export your data in a portable format;
- object to or restrict certain processing;
- withdraw consent, where processing is based on consent;
- complain to a supervisory authority.
To exercise any of these, email hello@getahead.studio. We will respond within 30 days. We will not discriminate against you for exercising a privacy right.
UK/EU. You can complain to your local data protection authority — in the UK, the Information Commissioner's Office (ico.org.uk).
California. Under the CCPA/CPRA you have rights to know, delete, correct, and opt out of sale or sharing. We do not sell or share personal information as those terms are defined, and we do not process sensitive personal information for inferring characteristics. You may use an authorised agent to make a request.
Other US states. Residents of states with comprehensive privacy laws (including Colorado, Connecticut, Virginia, Oregon, Texas, and others) have broadly similar rights, and we handle those requests the same way.
8. Children
The Service is not intended for anyone under 16, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, email us and we will delete it.
9. Automated decision-making
We do not make decisions about you using solely automated processing that produce legal or similarly significant effects.
10. Changes to this policy
We may update this policy. We will change the "last updated" date at the top, and if the change materially affects how we handle your personal data, we will notify you by email or in the Service before it takes effect.
Contact
Get a Head Studio — hello@getahead.studio
If you have a concern about how we handle your data, contact us first and we will try to resolve it.