Privacy Policy
Last updated: 2026-08-26
Idun Blue is a creator platform operated by Idunblue AB ("we", "us", "our"), a company registered in Sweden under company registration number 559595-9791. This Privacy Policy explains how we collect, use, and protect personal data when you use our platform at idun.blue and related services.
We are committed to protecting your privacy in accordance with the EU General Data Protection Regulation (GDPR) and Swedish data protection law.
1. Data Controller
The data controller for the Idun Blue platform is:
When a creator ("operator") uses Idun Blue to run their business, the operator is the data controller for their members' data, and Idunblue AB acts as the data processor.
2. What Data We Collect
2.1 Account Information
- Name and email address — provided when you create an account or sign up for a creator's offering.
- Password — stored as a secure hash (never in plain text).
- Profile information — optional details such as bio and profile picture.
2.2 Payment Information
- Payment processing is handled entirely by Stripe. We do not store credit card numbers or bank details on our servers.
- We store transaction references (Stripe customer ID, payment intent ID) to manage subscriptions and orders.
2.3 Usage Data
- Course progress — which lessons you have completed and when.
- Page views and interactions — aggregated analytics to help creators improve their content.
- Community activity — posts, comments, and messages you create.
- Email engagement — open and click tracking for emails sent through the platform.
2.4 Social Media Data
- If you connect a Meta (Instagram) professional account, we store an encrypted access token and basic account information such as account ID, username, account type and profile picture.
- When you enable the corresponding social tools, we retrieve media identifiers and metadata, account and post insights, comments and replies, and Instagram direct-message conversations and message events for that connected professional account.
- We use this data only to provide the features you choose: connecting the account, planning and publishing content, displaying analytics, moderating comments, replying to messages, and running reply rules that an authorized workspace user explicitly configures.
- For Instagram Login, we request only the permissions needed for those features:
instagram_business_basic, instagram_business_content_publish, instagram_business_manage_insights, instagram_business_manage_comments, and instagram_business_manage_messages.
- We do not access contacts or personal media unrelated to the connected professional account, send unsolicited messages, or publish without an authorized user's action or saved schedule.
2.5 Technical Data
- IP address — used for rate limiting and security; not stored long-term.
- Browser and device type — from standard HTTP headers, used for compatibility.
- Cookies — see section 7 below.
3. How We Use Your Data
We process personal data for the following purposes:
- Providing the service — account management, course delivery, community features, email delivery.
- Payment processing — managing transactions, subscriptions, invoices, and refunds via Stripe.
- Connected social tools — connecting an Instagram professional account and, when you choose the corresponding feature, publishing or scheduling content, displaying insights, moderating comments and handling permitted message replies.
- Platform security — rate limiting, fraud prevention, and abuse detection.
- Service improvement — aggregated, anonymized analytics to improve the platform.
- Communication — transactional emails (receipts, password resets, magic links) and, where you opt in, marketing emails from creators you follow.
Legal Basis (GDPR Art. 6)
- Contract performance (Art. 6(1)(b)) — processing necessary to provide the services you signed up for.
- Legitimate interests (Art. 6(1)(f)) — security, fraud prevention, service improvement, first-party sales analytics.
- Consent (Art. 6(1)(a)) — marketing emails, social media account connection, and advertising/analytics tracking (cookies, pixels, and server-side conversion events — see section 7).
4. Third-Party Services (Sub-Processors)
We share data with the following third-party services, only as necessary to operate the platform:
- HostUp AB (hosting) — provides the VPS infrastructure in Sweden on which the application, database and queues run. See HostUp's Privacy Policy.
- Cloudflare, Inc. (CDN, security and object storage) — proxies web traffic for performance and DDoS protection and stores selected media objects. See Cloudflare's Privacy Policy.
- Functional Software, Inc. (Sentry) (error monitoring) — may process error details and technical request metadata when the platform reports a fault. Idun Blue uses Sentry's EU data region in Germany. See Sentry's Privacy Policy.
- Stripe (payments) — processes and stores payment information. See Stripe's Privacy Policy.
- OpenAI and Anthropic (optional AI features) — depending on the operator's selected provider, text, files and non-Meta tool results that the operator deliberately asks the AI assistant to analyze may be processed by OpenAI or Anthropic. Member records are pseudonymised before any AI processing: email addresses, phone numbers and payment references are removed and names are shortened. The data is not used to train AI models. Meta Platform Data retrieved by Idun Blue — including connected-account and post metadata, insights, comments and messages — is not exposed to Papi or MCP AI tools. See OpenAI's Privacy Policy and Anthropic's Privacy Policy.
- Meta Platforms (Instagram, Facebook) — receives content you choose to publish via the social tools, and — only where a creator has configured Meta advertising tools and the visitor has the required consent — conversion data as described in section 7. See Meta's Privacy Policy.
- Google — sends transactional and marketing emails on behalf of creators (SMTP), stores client-side-encrypted disaster-recovery backups that Google cannot decrypt without Idun Blue's separately held key, and — where a creator has configured Google Analytics and the visitor has the required consent — receives analytics events as described in section 7. See Google's Privacy Policy.
Our application server and live database are hosted in Sweden. We do not sell personal data to third parties.
5. Data Retention
- Account data is retained as long as your account is active.
- Meta Platform Data — access tokens, connected-account identifiers, insights, comments, message data and raw Meta payloads are removed from active systems when the creator disconnects the account, removes authorization in Meta, or submits a Meta data-deletion request. Creator-authored Idun Blue drafts may remain, but are detached from the account and stripped of Meta-returned links and errors.
- Payment records are retained for the period required by Swedish bookkeeping regulations (7 years).
- Email tracking data and technical identifiers (IP addresses, browser user-agent strings attached to tracking events) are retained for 12 months, then automatically anonymized by a scheduled job.
- Consent records (when, where, and from which address a marketing opt-in was given) are retained while the consent is relied upon, as required by GDPR Art. 7(1).
- When you delete your account, personal data is removed from active systems immediately, except where legal retention requirements apply (e.g. payment records). Client-side-encrypted disaster-recovery backups are isolated from normal processing and expire within 30 days.
6. Your Rights (GDPR)
As a data subject under GDPR, you have the following rights:
- Access — request a copy of your personal data.
- Rectification — correct inaccurate data.
- Erasure — request deletion of your data ("right to be forgotten"). See Data Deletion Instructions.
- Data portability — receive your data in a machine-readable format.
- Restriction — request that we limit processing of your data.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY).
7. Cookies, Tracking & Advertising Measurement
7.1 On the platform itself (idun.blue, app.idun.blue, studio.idun.blue)
- Essential storage — authentication tokens (JWT) stored in
localStorage, necessary to keep you logged in. These are not cookies in the traditional sense but function similarly.
- Cloudflare cookies — security and performance cookies set by Cloudflare's CDN.
The platform's own surfaces do not run third-party advertising trackers.
7.2 On creator pages (sales pages, checkouts, course quizzes)
Creators can connect their own analytics and advertising tools to the pages they publish through Idun Blue. When configured by the creator, those pages may use:
- Google Analytics 4 — page-view and event analytics (cookies set by Google).
- Meta Pixel — advertising measurement (cookies such as
_fbp/_fbc set by Meta).
- Server-side conversion events — when a purchase or sign-up completes, the platform can send a conversion event to Meta (Conversions API) and/or Google (Measurement Protocol) containing a hashed email address, IP address, browser user-agent, and Meta click identifiers, so the creator can measure their advertising.
Consent controls all of the above. By default, for visitors in the EU/EEA, the United Kingdom, and Switzerland, these tools only activate after an affirmative choice in the cookie banner — declining (or simply not answering) means no advertising cookies are set and no conversion data is shared. An explicit decline is always respected. Your choice is stored locally and applies across the creator's pages and checkout. The creator is the data controller for this processing and responsible for its lawful basis; Idun Blue acts as their processor and provides the consent tooling.
8. Data Security
We implement appropriate technical and organizational measures to protect your data:
- All data is transmitted over HTTPS/TLS.
- Passwords are hashed using strong cryptographic algorithms.
- API endpoints are protected by rate limiting and input validation.
- Access to production systems is restricted and monitored.
- Database backups are encrypted and stored securely.
9. International Transfers
Our application server and live database are located in Sweden, and Sentry event data is stored in Germany. Some third-party services (including Cloudflare, Stripe, Meta, Google, OpenAI and Anthropic) may process data outside the EU/EEA. Where this occurs, we rely on the provider's applicable transfer mechanism, such as an adequacy decision or Standard Contractual Clauses.
10. Children
Idun Blue is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at [email protected].
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or a notice on the platform. The "Last updated" date at the top indicates the most recent revision.
12. Contact
For privacy-related questions or requests:
Idunblue AB
Company registration no.: 559595-9791
VAT no.: SE559595979101
Överälve, 827 93 Ljusdal, Sweden
Email: [email protected]