SECURITY & PRIVACY
HummingDeck runs on Google Cloud and encrypts your content in transit and at rest. Here is how we keep your decks, rooms, and customer data safe.
AT A GLANCE
Every connection uses TLS 1.2 or higher, and your files are encrypted at rest with AES-256.
Hosted entirely on Google Cloud, with managed databases, automated backups, and point-in-time recovery.
Files are served through expiring signed links. You decide who can open a document, and you can revoke access anytime.
You own your data. We never sell it, and we process it under a GDPR-ready Data Processing Agreement.
ENCRYPTION
All traffic between you, your viewers, and HummingDeck is protected with TLS 1.2 or higher. Shared documents are delivered over HTTPS through signed, time-limited links, never from a public location.
Uploaded files and database records are encrypted at rest with AES-256 on Google Cloud's managed storage and database services.
INFRASTRUCTURE
Compute, storage, and databases run on Google Cloud, inheriting its physical, network, and platform security.
Databases are backed up automatically every day, with point-in-time recovery to keep data loss to a minimum.
Documents are stored privately and served only through expiring signed URLs, so file addresses can't be guessed and stop working after they expire.
ACCESS CONTROL
Sharing a document does not mean losing control of it. Decide who gets in, for how long, and what they can do.
On Pro and Business, require recipients to verify their email before they can open a document. Verification confirms inbox access, not legal identity.
Set links to expire automatically, so access ends when the deal window closes.
Allow or block downloads per link, keeping sensitive content view-only when you need it.
Cut off access the moment you need to, for everyone on a link or a single recipient.
Every recorded view and download is logged with a timestamp, so you can review activity on each link.
Known bots and likely email-security scanners are flagged and kept out of normal view counts. Flagged sessions stay reviewable, and no filter can prove every remaining view is human.
DATA & PRIVACY
We process customer data on your behalf, under clear, GDPR-ready terms.
We operate from the EU and offer a Data Processing Agreement with Standard Contractual Clauses for international transfers.
We publish the full list of subprocessors we rely on, and give advance notice before that list changes.
You can export your data, and we delete it on request and after account closure, subject to standard retention windows.
Billing runs through FastSpring, a PCI-compliant payment provider. We never see or store your card details.
Read the details
RESPONSIBLE DISCLOSURE
We take security reports seriously. If you believe you have found a vulnerability, please email us and we will respond quickly.
Email hello@hummingdeck.comStart sharing documents on infrastructure built to keep them safe.