Last updated: July 2026
Gateholm exists to give you the privacy of self-hosting without the work. This policy explains what we collect, what we can and cannot see, and the choices you have. We aim to say only what is literally true about encryption — no overclaiming.
The service is operated by Gateholm, a sole proprietorship based in Massachusetts, USA — the data controller for your account and billing records. Where the GDPR applies, we process your data to perform our contract with you (running the apps you subscribe to, billing, support) and on our legitimate interest in keeping the service secure (operational logs, abuse prevention). We don't do marketing profiling, so we never need consent-based processing beyond what's described here.
This is the part that matters, and we're precise about it:
Today your data is hosted on servers in the European Union. This doesn't put it above the law: a legitimate, properly justified legal order will still reach it, and we won't pretend otherwise. What EU hosting does is put a foreign court in the loop — an overreaching or unjustified demand has to clear European legal process first, and your data can't simply be seized with no notice the way it can when the servers sit on the requesting government's own soil. It's a real speed bump against abuse, not a force field against the law. Choosing the region your data lives in — including options outside the EU — is on the roadmap.
We keep third parties to a minimum. The ones we use:
We do not sell your data, and we do not run advertising or third-party trackers.
We measure basic, aggregate traffic — which pages are visited and roughly where visitors arrive from — using Matomo, which we self-host on our own EU servers. It is not a third-party service: nothing is sent to Google, Meta, or any ad network. It runs without cookies, anonymizes your IP address (we never store it in full), honors your browser's Do Not Track setting, and records only the page path — never the full link, so tokens that ride in URLs (like a password-reset link) never reach it. No profiles, no cross-site tracking, nothing sold or shared. This runs only on our website; it is never placed inside the apps you use.
While your subscription is active you can export your data at any time, since everything is open source and standards-based — and your synced apps (Vault, Notes, Drive) also keep a copy on your own devices. After cancellation there is a 30-day grace period: resubscribe any time in that window to regain access (we email a reminder before it ends). After it ends, your data is permanently deleted from the live service; our encrypted backups then age out on a rolling schedule over the following months, and disaster-recovery copies may retain it a while longer for integrity, as backups do — after which it is gone everywhere.
One exception, required by law: billing records (invoices, payment confirmations) are kept by our payment processor, Stripe, for the period tax and accounting rules require, even after you delete your account. We never hold your card number; this is the minimal transaction record every business must retain.
You can access, correct, export, or delete your data — deletion is self-serve from your account (Delete your account), or by email. If you're in the EU/UK, the GDPR gives you these rights explicitly. To exercise any of them, email privacy@gateholm.com.
We use only the cookies needed to keep you signed in and to remember a referral link. No advertising or analytics cookies — our analytics (above) runs entirely without cookies, which is why you won't see a cookie-consent banner.
Questions about privacy? Email privacy@gateholm.com — or support@gateholm.com for anything else.