Mjolnir

Privacy policy

The whole point of Mjolnir is that your infrastructure stays on your machine. This page lists the little that does not, and why.

Last updated 20 September 2026.

What the app never sends

Cluster names, context names, namespaces, object names, labels, log lines, secrets, connection strings, file contents, messages, query results: anything read from your clusters, containers, stores, machines, databases or brokers stays in the app. The application refuses, in code, to open a connection to any host that is not your own infrastructure or under *.mjolnir.sh or *.mjolnir.co.in.

An account

Signing in stores your email address and, for each machine you sign in from, a name you can edit, the platform, the app version and when it was last seen. That is the whole record. It exists so that a licence can be tied to five machines and so that you can sign one out from the licence page.

Payment

Paddle.com Market Limited takes payment as the merchant of record. Your card number, billing address and tax details go to Paddle and are handled under Paddle's privacy policy. We receive the email address you paid with, the plan, and the status of the subscription.

Crash reports and usage counters

Both are on by default and both turn off in one tap in Settings, Privacy, which also shows the exact JSON queued for sending before any of it goes and empties the queue when a switch is turned off. The events are a fixed catalogue with no cluster name, namespace, resource name, label, log line or key in any of them, inputs are never captured, and none of it is joined to your account. A crash report carries the stack trace, the app version and the operating system version.

This website

The site sets no analytics and no advertising cookies. One item in browser storage remembers the theme you chose. Fonts, scripts and images are served from this domain. The checkout loads one script from Paddle. Request logs, with IP addresses, are kept for fourteen days for security and then deleted.

Email

You get transactional email: a sign-in code, a licence key, a receipt, and a notice before a price or these terms change. There is no marketing list. Every message carries a postal address and a way to reach a person.

Who processes it

Paddle (payment), our email provider (transactional mail), and the hosting provider this service runs on. Nobody is sold or given your data, and nothing is used to train anything.

Retention and your rights

An account and its machines are kept while the subscription exists and for one year after it ends, then deleted. Crash reports are kept for ninety days. You can ask at any time for a copy of what we hold about you or for all of it to be deleted, and the request is honoured within thirty days: write to [email protected] from the address on the account. Where you live may give you further rights, including under the GDPR and the UK GDPR; the same address handles those.

Contact

Aman Jain, [email protected]. Security reports go to the address in SECURITY.md.