This policy explains what personal data is handled when you visit bagpipper.com or use the Bagpipper desktop app, why we handle it, how long we keep it and what rights you have. We have written it in plain language. If anything is unclear, please contact us at [email protected].
1. Who we are
Bagpipper, Viremail and Krodium are made by Svayam Incarnation Limited, a company registered in England and Wales (company number [to be confirmed], registered office [to be confirmed]). In this policy, “we”, “us” and “our” mean Svayam Incarnation Limited. We are the data controller for the personal data described here, except where section 12 explains otherwise. Our ICO registration number is [to be confirmed].
2. What this policy covers
Bagpipper (bagpipper.com) is a desktop suite for business, formerly the Viremail desktop app. It brings the Viremail apps into one native desktop app, includes Krodium, a private browser, built in, and gives access to the Krodium Store. This policy covers the Bagpipper desktop app and the bagpipper.com website.
It does not cover the following, which have their own documents:
- The Viremail service itself, including your account, mail, files, chat and the other Viremail apps. It is governed by the Viremail privacy policy and the Viremail terms.
- Store purchases and developer listings, which are governed by the terms at krodium.com, and the developer agreement at krodium.com/developers.
- Third-party websites you visit using Krodium, and apps made by third-party developers, which have their own privacy practices.
3. Data we collect and why
3.1 When you visit bagpipper.com
The website has no analytics, no advertising and no third-party trackers. It loads no third-party scripts, and its fonts are hosted by us. Like any website, our servers record technical information about each request: your IP address, your browser’s user agent, the time of the request and the page requested. We use these server logs to keep the site secure and running properly. We keep them for up to 30 days, unless we need to keep particular entries longer to investigate abuse or a security incident. We also apply rate limiting by IP address, held in memory only, to protect the site from overload and misuse.
3.2 When you sign in with Viremail on bagpipper.com
The Store pages on bagpipper.com use Sign in with Viremail, which works through OpenID Connect. When you sign in, Viremail tells us your Viremail account identifier, your name and your email address. We store:
- a user record, made up of your identifier, email address, name, the time it was created and the time you last signed in; and
- a session record, which holds only a SHA-256 hash of your session token (never the token itself), an expiry of at most 14 days, and is limited to at most ten sessions per person.
Temporary sign-in state records, used to protect the sign-in step, are deleted after use or within 15 minutes. If you would like your user record deleted, contact us at [email protected].
3.3 When you use the desktop app
The desktop app is designed to keep your information on your computer. In particular:
- The app sends no usage data and no telemetry. Its logs stay on your computer.
- When the app checks for updates, it sends its version number to viremail.com. As with any request over the internet, your IP address is visible to the server that receives it.
- Installers are downloaded from GitHub (github.com and its download host). GitHub sees the IP address of the person downloading and has its own privacy policy.
- On Windows and Linux, spelling dictionaries download from a Google content delivery network the first time they are needed. That network sees your IP address.
- The sign-in cookie that connects the app to your Viremail account is encrypted using your operating system’s key store.
3.4 Vault screen scanning
The Vault “scan screen” feature can find two-step verification links displayed on your screen. It captures your screens only after you agree in a system dialog. The capture is read on your computer, and the only thing kept is the two-step verification links found. Nothing is sent to us.
3.5 Clipboard history
Bagpipper can keep a history of up to 1,000 clipboard items. This history is stored only on your computer and is encrypted using your operating system’s key store. It skips anything copied from Vault or from a password manager, and it is wiped when you sign out.
3.6 Krodium
- Tabs in Krodium are sandboxed separately from your Viremail session, so websites you browse cannot reach your Viremail data.
- Krodium data is encrypted using your operating system’s key store.
- The optional blocker uses public filter lists, which are downloaded daily.
- If you import from another browser, Krodium brings in bookmarks, history and open tabs only. It never imports cookies.
- Bookmarks and history can sync between your devices. This sync is end-to-end encrypted, so we cannot read it.
3.7 When you contact us
If you email us, we receive your email address and whatever you choose to tell us. We use it to reply and to keep a record of the conversation.
4. Our lawful bases
Under UK data protection law we must have a lawful basis for each use of personal data. Ours are:
- Legitimate interests, for server logs, rate limiting and operating and securing the website and the update service. We have considered the impact on you and believe it is small, because we collect little and keep it briefly.
- Contract, for providing the app and for Sign in with Viremail, where you ask us for a service.
- Legal obligation, where we must keep or disclose information to comply with the law.
- Consent, where we ask for it, for example when you accept a system dialog. You can withdraw consent at any time.
5. Cookies and local storage
bagpipper.com uses only strictly necessary cookies and one preference stored in your browser. We do not use tracking cookies. The details are in our cookie policy.
6. Who we share data with
We do not sell personal data, and we do not share it for advertising. We share data only in these limited cases:
- Service providers. We use hosting and network providers acting as processors. They run the servers we operate and the content delivery and security network in front of them. They may only act on our instructions and are bound by contracts that protect your data.
- Viremail. When you sign in with Viremail, your Viremail account identifies you to us, as described in section 3.2.
- GitHub and Google. When you download an installer, or download dictionaries where that applies, those providers receive your IP address as described in section 3.3, and handle it under their own policies.
- Authorities and advisers. We may disclose data where the law requires it, to protect our rights or the safety of others, or to our professional advisers under a duty of confidentiality.
- Business changes. If our business is sold or reorganised, data may pass to the new owner, who must respect this policy.
7. International transfers
Where our providers process personal data outside the United Kingdom, we make sure appropriate safeguards are in place. These are either UK adequacy regulations covering the destination country, or the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses.
8. How long we keep data
| Data | How long |
|---|---|
| Server logs | Up to 30 days, unless needed longer to investigate abuse or a security incident |
| Rate limiting counters | In memory only, and cleared when the server restarts |
| Sign-in state records | Deleted after use, or within 15 minutes |
| Session records | Until expiry, at most 14 days, or until you sign out |
| User record | Until you ask us to delete it |
| Emails to us | For as long as needed to deal with your request and for a reasonable period afterwards |
| Data kept on your computer | Under your control: clipboard history is wiped at sign-out, and you can remove the rest by uninstalling the app |
9. Your rights
Under the UK GDPR and the Data Protection Act 2018 you have the right to:
- be told whether we hold your personal data and receive a copy of it (access);
- have inaccurate data corrected (rectification);
- have your data erased in certain circumstances (erasure);
- ask us to restrict how we use your data in certain circumstances (restriction);
- object to uses based on our legitimate interests (objection);
- receive your data in a portable format, where the processing is based on contract (portability); and
- withdraw consent at any time, where we rely on it.
To use any of these rights, email [email protected]. We will respond within one month. We may need to confirm your identity first. If a request is complex, we may extend the period as the law allows, and we will tell you why.
If you are unhappy with how we have handled your data, you have the right to complain to the Information Commissioner’s Office at ico.org.uk. We would appreciate the chance to put things right first, so please contact us.
10. Security
We take reasonable technical and organisational steps to protect personal data. They include:
- encrypted connections (HTTPS) for the website and for the app’s communication with our servers;
- storing session tokens only as hashes, and limiting how long sessions last;
- encrypting sensitive data on your computer with your operating system’s key store;
- end-to-end encryption for Krodium bookmark and history sync;
- keeping Krodium tabs sandboxed from your Viremail session;
- limiting access to our systems to the people who need it; and
- keeping logs for a short, fixed period.
No system is completely secure. If a breach affects your rights and freedoms, we will tell you and the Information Commissioner’s Office as the law requires.
11. Children
Bagpipper and bagpipper.com are not directed at children under 13, and we do not knowingly collect their personal data. Viremail’s own age rules apply to Viremail accounts. If you believe a child has given us personal data, please contact us and we will delete it.
12. Business accounts
Many people use Bagpipper through a business account provided by an employer or organisation. In that case:
- For personal data processed in Viremail Business, the employer or organisation may be the controller, and we act as its processor. Questions about that data should go to the employer first.
- Administrators can set Krodium policies, such as blocked sites and download rules. These apply on the devices and accounts they manage.
- An activity report is shared with the employer only after the employee accepts a notice explaining what it contains.
For the website, the update service and Sign in with Viremail, we remain the controller, as described in this policy.
13. Third-party apps and websites
The Krodium Store lists extensions, web apps and desktop apps from us and from third-party developers. Third-party developers decide what their apps do with your data and are responsible for it. Please read their privacy information before installing. Links to other websites are not covered by this policy.
14. Changes to this policy
We may update this policy from time to time, for example when we add features or when the law changes. We will change the date at the top of the page and, for significant changes, take reasonable steps to tell you, such as a notice in the app or on this site.
15. Contact us
For any question about this policy or your personal data, email [email protected], or write to Svayam Incarnation Limited at its registered office, [to be confirmed]. You can also read our terms of use and acceptable use policy.