Privacy Policy
This describes what Herald Signage actually collects and where it goes. It's deliberately specific — a policy that lists real systems is one you can hold us to, unlike boilerplate that reserves every right imaginable.
Who we are
Herald Signage (“Herald”) is a product of Accutek Solutions, operated by Jacob Neudorf, doing business as Accutek Solutions, based in Texas, United States. Mailing address: 1100 3rd St, Graham, TX 76450, United States. Privacy questions go to privacy@heraldsignage.com.
Herald Signage is currently offered only to customers in the United States.
What we collect
Account information. Your name, email address, and a cryptographic hash of your password. We store the hash, never the password itself.
Sign-in and security records. Session records including IP address and browser user-agent, and an audit log of significant actions in your account — who changed what, when, and from which IP. This is how you (and we) investigate if something looks wrong.
Content you upload. Images, video, slides, web page addresses, playlists, and schedules. If you put personal information into a slide, we hold that too — see section 10.
Device and playback data. Information your players report: device name, hardware model, software version, local network address, health and connection status, what is currently on screen, a record of what played and when, and periodic screenshots of the screen’s own output so you can check a display remotely.
Billing references. Your Paddle customer and subscription identifiers, plan, status, and renewal date.
What we deliberately don't collect
- Card numbers. Payment details go directly to Paddle. They never touch our servers.
- Congregant records. The Planning Center integration reads service and event information to build slides. It does not import your people database, and we don’t store congregant records.
- Advertising and analytics trackers. Herald runs no advertising or marketing-analytics scripts, and we don’t sell or share your data. The only third-party script in Herald is Sentry, which we use to find and fix bugs (see section 06).
Why we use it
To run the service: authenticate you, deliver content to your screens, enforce your plan limits, send operational alerts you have configured, and bill you. We also use aggregate technical information — error rates, device health patterns — to find and fix problems. We do not build advertising profiles.
Cookies
Herald uses essential cookies only. There is no advertising or analytics cookie, which is why you aren’t greeted by a consent banner. Specifically:
- hrd_sess — keeps you signed in. Set across our subdomains so one sign-in reaches your organization’s address.
- hrd_oauth_state, hrd_oauth_nonce, hrd_oauth_next — short-lived, used only during Google sign-in to prevent request forgery and return you to the right page.
Who else touches your data
We keep this list short on purpose. Today it is:
- Hostinger — the servers Herald runs on, located in the United States.
- Paddle — payments, invoicing, and sales tax, as merchant of record. They receive your billing contact and payment details directly.
- Google (Drive) — encrypted nightly backups are stored in Google Drive so a server failure can’t take your data with it. Backups are encrypted before they leave our server.
- Sentry — error and performance monitoring, hosted in the United States. When something breaks, Sentry receives the error, the page or request involved, and technical details such as browser type and timing. It also keeps short session replays (a record of clicks and page changes) for sessions where an error happened and for about 1 in 20 others. Replays mask all text and form fields and leave out images and video, so your content, names, and passwords are not recorded. If you send a report with “Report a problem”, Sentry receives what you write.
- Cloudflare — DNS for our domains. Your traffic is not proxied through them.
- Let’s Encrypt — TLS certificates for our domains.
We do not sell your personal information, and we have never disclosed it for advertising. If we’re ever legally compelled to hand over data, we’ll tell you unless we’re forbidden from doing so.
Integrations you switch on
Some features connect Herald to services you control, using credentials you provide. These are off until you enable them, and you can revoke them at any time:
- Google Drive sync — mirrors media between Drive and your library, using a service account you supply.
- Email alerts — sent through your own mail server. Your alert emails do not pass through a Herald mail provider.
- Google Chat alerts — posts to a webhook you provide.
- Planning Center — reads service and event information to generate slides.
Once data reaches one of those services, that provider’s own privacy policy governs it.
How long we keep things
- Deleted media sits in a recoverable trash for about 14 days, then is permanently removed.
- Audit logs and playback history are retained while your account is open, because their value is being able to look back.
- Backups rotate automatically; older ones are deleted on a rolling schedule.
- Closed accounts are recoverable for 30 days, then deleted. Backups containing that data age out shortly after.
How we protect it
- Passwords are hashed with Argon2 — we cannot read them, even deliberately.
- Traffic runs over TLS. Stored third-party credentials are encrypted at rest.
- Backups are encrypted before leaving our server.
- Each organization’s data is isolated, and requests carrying credentials for one organization are refused on another’s address.
- Software updates sent to your players are cryptographically signed, so a device only installs builds we actually published.
No system is perfectly secure. If a breach ever affects your data, we will tell you promptly and plainly, with what we know and what we’re doing about it.
Personal information in your content
Herald is a tool for putting content on screens, and what goes on those screens is your decision. If you display personal information — a photo of a volunteer, a name on a slide, a child in a video — you are responsible for having the appropriate consent, and for your own obligations to the people involved.
Herald is a business tool, not a service directed at children, and we don’t knowingly collect personal information from children.
Your choices
You can view and correct your account details in the dashboard, export your media at any time, and ask us to delete your account and its data. To request an export or deletion, email privacy@heraldsignage.com from an address on the account. We’ll act within 30 days and won’t charge you for it.
Changes to this policy
If we change what we collect or who we share it with, we’ll update this page and email account admins before it takes effect. The date at the top always reflects the current version.
Contact
Privacy questions, export requests, or complaints: privacy@heraldsignage.com.
