SECURITY & PRIVACY
HummingDeck runs on Google Cloud and encrypts your content in transit and at rest. Here is how we keep your decks, rooms, and customer data safe.
AT A GLANCE
Every connection uses TLS 1.2 or higher, and your files are encrypted at rest with AES-256.
Hosted entirely on Google Cloud, with managed databases, automated backups, and point-in-time recovery.
Files are served through expiring signed links. You decide who can open a document, and you can revoke access anytime.
You own your data. We never sell it, and we process it under a GDPR-ready Data Processing Agreement.
ENCRYPTION
All traffic between you, your viewers, and HummingDeck is protected with TLS 1.2 or higher. Shared documents are delivered over HTTPS through signed, time-limited links, never from a public location.
Uploaded files and database records are encrypted at rest with AES-256 on Google Cloud's managed storage and database services.
INFRASTRUCTURE
Compute, storage, and databases run on Google Cloud, inheriting its physical, network, and platform security.
Databases are backed up automatically every day, with point-in-time recovery to keep data loss to a minimum.
Documents are stored privately and served only through expiring signed URLs, so links cannot be guessed or shared indefinitely.
ACCESS CONTROL
Sharing a document does not mean losing control of it. Decide who gets in, for how long, and what they can do.
Require a verified email before anyone can open a document, so you always know who is viewing.
Set links to expire automatically, so access ends when the deal window closes.
Allow or block downloads per link, keeping sensitive content view-only when you need it.
Cut off access the moment you need to, for everyone on a link or a single recipient.
Every open and download is logged with a timestamp, giving you a complete record of who accessed what.
Automated link scanners and bots are detected and filtered out, so your view data reflects real people.
DATA & PRIVACY
We process customer data on your behalf, under clear, GDPR-ready terms.
We operate from the EU and offer a Data Processing Agreement with Standard Contractual Clauses for international transfers.
We publish the full list of subprocessors we rely on, and give advance notice before that list changes.
You can export your data, and we delete it on request and after account closure, subject to standard retention windows.
Billing runs through FastSpring, a PCI-compliant payment provider. We never see or store your card details.
Read the details
RESPONSIBLE DISCLOSURE
We take security reports seriously. If you believe you have found a vulnerability, please email us and we will respond quickly.
Email hello@hummingdeck.comStart sharing documents on infrastructure built to keep them safe.