Idun Blue
ProductWhy Idun?PricingArticlesToolsHelp
EN / SV Log in Waitlist
ProductWhy Idun?PricingArticlesToolsHelp Log in
EN / SV Waitlist

Privacy Policy

Last updated: October 2, 2026

1. Introduction

This policy describes how Idunblue AB ("Company", "we", "us", or "our"), which operates the Idun Blue platform, processes personal data. We comply with the General Data Protection Regulation (GDPR) and Swedish data protection law.

This policy is written to be checkable. Every sub-processor in section 6 actually receives data in the current production setup — we list no vendor we do not use, and we omit none that we do.

2. Data Controller

The controller for the data we process about you as our customer is:

Idunblue AB
Company registration no.: 559595-9791
VAT no.: SE559595979101
Överälve, 827 93 Ljusdal
Sweden
Email: [email protected]

When a creator uses Idun Blue to run their own business, the creator is the controller for their members' data and we act as their processor. The terms are in our Data Processing Agreement. If you are a member of a creator and want to exercise your rights, contact the creator first.

3. What Data We Collect

Account data

When an account is created we collect name, email address, and password (stored as a cryptographic hash, never in plain text). For a creator we also collect the workspace name and billing details.

Usage data

We record how the Service is used: pages visited, features used, course progress and the like. We do not sell that data and we do not use it to target advertising for third parties.

Payment data

Card details go straight to our payment provider Stripe and never pass through our servers. We store transaction references, amounts, currency, and the billing details required for accounting and VAT — not card numbers.

Content data

Content uploaded or created on the Platform (courses, video, community posts, email copy, pages) is stored on our own server, see section 7.

AI conversation data

Messages exchanged with Idun AI, the assistant in Studio, are stored per workspace so a conversation can continue where it left off. See section 7b for what leaves our server.

OAuth and integration data

When you connect a third-party service via OAuth 2.0 — for example ChatGPT, Instagram, TikTok or YouTube — we store the access and refresh tokens plus the minimum account metadata needed to keep the connection alive, encrypted at rest. TikTok draft upload uses user.info.basic and video.upload; YouTube upload uses youtube.upload and youtube.readonly. We request only the scopes you explicitly authorize, and we delete the tokens within 24 hours of you revoking or disconnecting access.

Communication data

If you email us we keep your message and our reply, so we can help you and so there is a record of what was said.

Technical data

Our infrastructure and error monitoring process IP addresses, browser information and error reports. That is needed to serve the pages, stop attacks, and fix what breaks.

4. How We Use Your Data

We use your personal data for the following purposes:

  • Providing the Service: To create and manage your account, process payments, and deliver the features you use.
  • Improving the Service: To analyze usage patterns, fix bugs, and develop new features.
  • Communication: To send you important service updates, security notices, and, with your consent, product announcements.
  • AI features: To power AI-assisted content creation, the Idun AI assistant, and MCP tool integrations.
  • Third-party integrations: To facilitate integrations you authorize via OAuth (e.g., ChatGPT, other connected applications).
  • Legal compliance: To comply with legal obligations, respond to lawful requests, and protect our rights.

5. Legal Basis for Processing

We process your personal data based on the following legal grounds under GDPR:

  • Contract performance (Art. 6(1)(b)): Processing necessary to provide the Service you have subscribed to.
  • Legitimate interest (Art. 6(1)(f)): Processing for service improvement, security, and fraud prevention.
  • Consent (Art. 6(1)(a)): For marketing communications, which you can withdraw at any time.
  • Legal obligation (Art. 6(1)(c)): Processing required to comply with applicable laws.

6. Sub-processors — who receives data

We never sell personal data. We do rely on a number of vendors to run the Service. Below is every one that can receive personal data in the current production setup. Rows marked optional are used only if the creator switches the feature on.

Sub-processor What they do Where
Contabo GmbH Server hosting — our database, queue and media files run on our own server with them EU
Cloudflare, Inc. Proxy, CDN and DDoS protection for all traffic; storage of podcast audio on ingest Global network and object storage
Stripe, Inc. Payments, subscriptions and payouts EU/US; see the transfers section
Resend Email delivery — both transactional mail and broadcasts US; processing may take place outside the EEA
Google LLC (Drive) Off-server storage of the daily database backup US; processing may take place outside the EEA
Google LLC (Gmail SMTP) Fallback path for email delivery when Resend is unavailable US; processing may take place outside the EEA
Requesty Ltd. Idun AI: routes AI assistance, content generation and member translation to the model, with zero retention of content; see the AI processing section EU region; the company is registered in the United Kingdom
Microsoft Ireland Operations Ltd. (Azure) Idun AI: runs the language model that Requesty routes to Sweden (Azure Sweden Central); the provider belongs to a US group
Anthropic PBC (Claude) (optional) Only when the creator connects their own Claude or their own Anthropic key US; processing may take place outside the EEA
Sentry (Functional Software, Inc.) Error monitoring — receives error reports and technical context when something breaks EU data region: Germany; US provider
Meta Platforms, Inc. (optional) Publishing to Instagram, and measurement via the pixel and Conversions API US; processing may take place outside the EEA
TikTok Technology Limited (optional) Receives videos the creator explicitly transfers as TikTok drafts or, after separate approval, publishes directly EU/US; see the transfers section
Google LLC (YouTube) (optional) Receives videos the creator explicitly uploads to their connected YouTube channel EU/US; see the transfers section
Google LLC (Analytics) (optional) Visitor measurement on the pages where you have switched it on US; processing may take place outside the EEA
OpenAI (optional) Only when the creator connects their own ChatGPT, Codex or their own OpenAI key US; processing may take place outside the EEA
Apple, Google, Mozilla (optional) Push notifications to phones and browsers US; processing may take place outside the EEA
EU-kommissionen (VIES) (optional) Validation of VAT registration numbers on business purchases EU

The list includes operational providers and services you can connect. Where a service processes personal data on our behalf, an applicable data processing agreement is required. Your own connections may also be covered by your direct agreement with that service. See the AI and international transfers sections.

OAuth and third-party integrations

When you authorize a third-party integration via OAuth 2.0 (such as ChatGPT, Instagram, TikTok or YouTube):

  • We request only the permissions (scopes) necessary for the integration to function.
  • Access tokens are stored encrypted on our servers.
  • You can revoke access at any time from your Idun Blue dashboard or from the third-party platform.
  • When you revoke access, we delete the associated tokens within 24 hours.
  • Data exchanged through integrations is subject to both this Privacy Policy and the third-party platform's privacy policy.
  • Social content is sent only to the platforms and accounts you explicitly select. TikTok draft uploads still require you to finish and publish inside TikTok; direct TikTok posting stays disabled unless TikTok separately approves it.

7. Where the data is stored

The application server, live database and queue are hosted by Contabo GmbH in the EU. Media is stored both on our server and in Cloudflare object storage, depending on the feature and file type.

Cloudflare sits in front of all our domains as proxy and protection, which means traffic passes through their network. Podcast audio and other selected media objects may also be staged or stored in Cloudflare object storage.

Sentry uses an EU region in Germany for event data. Other services and your own connections may process data outside the EEA. A provider’s jurisdiction and the location where data is processed are not always the same.

Security measures

  • All traffic is encrypted in transit (TLS)
  • Passwords are stored as cryptographic hashes; access tokens for connected services are stored encrypted
  • The database is backed up automatically every night — 14 days on the server, 30 days on Google Drive
  • Role-based access control and separation between workspaces
  • Automated error monitoring and alerting

Scheduled database backups are encrypted before off-server storage. They are configured for 14 days of local retention and 30 days off-server. Restoration requires Idun’s separately held key.

7b. AI processing

Idun's built-in AI assistant, Idun AI, runs through Requesty Ltd., which routes requests to a language model hosted on Microsoft Azure in Sweden (Sweden Central). Requesty is configured to use EU regions only and to keep no prompt or completion content (zero data retention), and your data is not used to train the model. Requesty keeps billing records that contain no content. The creator may instead choose to use their own Claude or Codex account or their own API key; that service then processes the data, see below.

Other AI features include content generation, workspace summaries and translation of community posts. For analysis of workspace metrics, compiled business statistics are sent to the AI service. To create a voice profile, writing samples from the workspace’s product descriptions, courses, broadcasts, blog posts and pages are sent to the AI service. When a member requests an uncached translation, the post text is sent to the AI service and the translation is stored with the post.

AI use may send instructions, relevant customer details, order information, messages, attachments and tool results to the provider. This supports content work, customer service, orders, broadcasts and access management within the user's permissions and instructions. Some structured fields are masked, but free text and attachments can contain personal data; we do not promise that everything is always anonymised.

Provider retention and any use for model training depend on the service, account type and settings. We therefore make no blanket no-training or zero-retention promise for all AI connections. See Claude Code data usage and Codex account settings.

When you connect your own Claude, Codex or another service through the macOS app, MCP or API, that service can receive information within the connection's permissions. Your account and agreement with that service govern its handling of those copies. Choose a service suitable for the data you ask it to process. Local agent software can use a cloud model; local operation does not mean all processing stays on your device.

AI history may contain instructions, extracted attachment text, replies, tool results, summaries and saved memories. A daily job removes Idun AI conversations after 90 days without activity, including their messages, extracted attachment text, tool results and conversation summaries. Conversations with an active or pending run are excluded. Saved memories and action audit records are retained separately and do not currently have a common automatic expiry period. Contact the creator or [email protected] for access to or erasure of personal data that may be in AI history. A connected service can hold separate copies with its own retention terms.

This description does not grant new access or authorise new uses of personal data. See also the platform privacy policy.

8. How long we keep data

We retain your personal data for as long as your account is active or as needed to provide the Service. After account termination:

  • Member deletion removes or de-identifies the records covered by the account deletion process. Personal data in other users’ free text or AI history may need review when handling a request.
  • Export and deletion when a creator terminates the service are governed by the agreement and DPA. Contact us to carry out termination and handle data outside the self-service export.
  • Financial records are retained for 7 years as required by Swedish accounting law
  • Aggregated, anonymized usage data may be retained indefinitely

9. Your Rights

Under GDPR, you have the following rights regarding your personal data:

  • Right of access: Request a copy of the personal data we hold about you.
  • Right to rectification: Request correction of inaccurate or incomplete data.
  • Right to erasure: Request deletion of your personal data ("right to be forgotten").
  • Right to restrict processing: Request that we limit the processing of your data.
  • Right to data portability: Receive your data in a structured, machine-readable format.
  • Right to object: Object to processing based on legitimate interest or for direct marketing.
  • Right to withdraw consent: Withdraw previously given consent at any time.

To exercise any of these rights, email [email protected]. We respond within 30 days.

10. Cookies

This website (idunblue.com). With your consent we load Google Analytics and the Meta pixel, which set cookies for visitor measurement. Say no and nothing is loaded. Your answer is stored locally in your browser.

The platform (studio.idun.blue and app.idun.blue). There we use strictly necessary cookies for login and session. They cannot be opted out of, because login does not work without them.

Creators' own pages. A creator can switch on the Meta pixel or Google Analytics for their sales pages and checkout. If they do, that vendor's cookies are set for the visitor, and the creator is responsible for obtaining consent and disclosing it.

11. International Transfers

The application server and live database are hosted with Contabo in the EU. External providers and connected services may process data outside the EEA. See the sections on recipients, storage and AI.

Processing outside the EEA requires an applicable transfer mechanism, such as an adequacy decision covering the recipient or Standard Contractual Clauses with any necessary supplementary safeguards. Contact us for information about the mechanism applicable to a particular service. An EU-hosted primary system does not mean all processing takes place within the EEA.

12. Children's Privacy

The Service is not directed at children under 16 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes at least 30 days in advance. The current version is always available on our website.

14. Supervisory Authority

If you believe that we have not handled your personal data correctly, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) or the supervisory authority in your country of residence.

15. Contact

For questions about this Privacy Policy or to exercise your data rights:

Idunblue AB
Company registration no.: 559595-9791
VAT no.: SE559595979101
Överälve, 827 93 Ljusdal, Sweden
Email: [email protected]
Website: idunblue.com

Idun Blue

A home for your work. A business to make a living from.

Internal beta. The first creators will be invited soon.

Product

Product demoFeaturesPricingCoursesSignup & follow-upPaymentsSwitch to IdunWaitlist

Resources

Courses on IdunHelp centreGuidesFree toolsAbout

Compare

vs Kajabivs Teachablevs Circlevs Skoolvs Simplerovs Mailchimp

Company

ContactTermsPrivacyDPA
Online course platformCoachesTherapistsYoga teachersBreathworkCourse creatorsMembership sites
AIWebsitesEmail & automationsPodcastCommunityAds & Analytics
© 2026 Idunblue AB
Language EN / SV Instagram LinkedIn

May we use optional cookies?

They help us understand what works and improve the site — for analytics and marketing. The site still works if you choose no.

What does this choice mean?

Necessary cookies:Always used for essential functions such as security and sign-in.

Analytics and marketing:Only enabled if you allow them. You can change your choice through Cookie settings in the footer.