Penguin HQPenguin HQ
PricingSign inSign up

Privacy Policy

Last updated October 7, 2026

Penguin HQ is run by Webmatter Solutions LLC, a Texas limited liability company ("we", "us" or "our"). This policy explains what information we collect when you use Penguin HQ at penguinhq.dev, including your account, which signs you in to every Penguin app, and companies, invitations, plans, billing and the emails we send; why we collect it; who sees it; and the choices you have. Your use of Penguin HQ is also covered by our Terms of Service.

We also run Penguin Poker and Penguin Parade, and each has its own privacy policy for what you do in it: Penguin Poker's Privacy Policy and Penguin Parade's Privacy Policy.

Contents

  1. The short version
  2. What we collect
  3. How we use it
  4. Legal bases
  5. Who sees your information
  6. Cookies and browser storage
  7. How long we keep it
  8. Your choices and rights
  9. Security
  10. International transfers
  11. Children
  12. Changes to this policy
  13. Contact us

The short version

  • Your Penguin HQ account signs you in to every Penguin app, and Penguin HQ keeps your companies, their members, invitations and plans. We collect what that takes: your name, your email address, a hash of your password, and the like.
  • What you do in Penguin Poker or Penguin Parade, like playing in rooms or checking in, is covered by that app's own privacy policy.
  • Everyone in your companies sees your name, email address, penguin and role. Owners and admins can also see whether you've turned on two-step verification.
  • We don't sell your information, show ads, or track you across other websites. Any analytics we use count visits without cookies.
  • Stripe handles payments, so we never see card numbers.
  • Email cameron@webmatter.io for a copy of your information, or to have it deleted.

The rest of this policy has the details.

What we collect

This section covers what Penguin HQ itself collects. What Penguin Poker and Penguin Parade collect when you use them, like rooms and votes, or check-ins and goals, is in their own policies.

When you create an account

One account signs you in to Penguin HQ, Penguin Poker and Penguin Parade. We collect:

  • Your name, email address and password. We keep only a hash of your password, never the password itself.
  • Your time zone, which we take from your browser when you sign up and you can change, so each app's days and times follow your clock.
  • Your color theme, and the penguin you pick in either app, which follows you into both.
  • Whether you've verified your email address, and when. To verify it, we email you a link that works once, within 24 hours, which we keep only as a hash. Until you verify it, you can't invite anyone or accept invitations, and invitations to your address wait.
  • If you turn on two-step verification, where we offer it: the secret behind your authenticator app's codes, which we encrypt; when you turned it on; and your 10 recovery codes, each good for one use, which we keep only as hashes.

When you sign in

  • Signing in starts a session, which lasts 30 days and works in every Penguin app in that browser. We keep it as a hash of the token in your session cookie. Signing out, here or in either app, ends it in all of them.
  • With two-step verification on, signing in asks for a code after your password. For the 10 minutes you have to enter it, we keep a note of whose sign-in it is. Once a code from your app has been used, we remember it for a couple of minutes, so nobody can use it again. And when you set up two-step verification, we keep the new secret, encrypted, for the 30 minutes you have to confirm it.
  • If you ask to reset your password, where we offer it, we email you a link that works once, within an hour, and stops working if your password changes. We keep it only as a hash.

To stop people guessing passwords and codes, or using our forms to flood inboxes, we count attempts, and the counts delete themselves:

  • sign-in tries from each IP address, here and at our admin portal, and for each email address, until 15 minutes after the last one;
  • wrong two-step codes for each account, until 15 minutes after the last one, and for a day;
  • wrong passwords and codes when you change your password or two-step verification, until 15 minutes after the last one;
  • sign-ups from each IP address, and password reset links asked for each email address and from each IP address, for an hour;
  • verification links sent for each account, for an hour;
  • invitations sent by each person and for each company, and new companies made by each account, for a day.

We get your IP address from Cloudflare, which sits in front of our servers, or from our hosting provider's proxy.

When you're part of a company

  • The company's name and when it was created, who's a member, each member's role (owner, admin or member) and when they joined, whether the company requires two-step verification, and which features we've turned on for it before they're released to everyone.
  • Invitations: the email address invited, the role offered, who sent it, and when it runs out. If someone invites you, we get your email address from them, and use it to send you the invitation, which works for 14 days. Signing up through it and verifying your address accepts it; if you already have an account, you choose whether to accept.

Every Penguin app shares the company: its members, their roles and its plan hold in Penguin Poker and Penguin Parade alike. What each app keeps about a company, like Penguin Poker's rooms or Penguin Parade's check-ins, is covered by that app's policy.

When your company pays

Payments go through Stripe. Owners enter card details on Stripe's checkout page, and we never see or store card numbers. When a company first checks out, Stripe receives the company's name and the email address of the owner checking out. Billing details an owner gives Stripe, like an address or a tax ID, stay with Stripe. We keep Stripe's IDs for the company and its subscription, the plan, the subscription's status, how often it's billed, when it renews or ends, whether a card is on file, and, for an Enterprise contract, how many seats it covers.

When you visit the site

  • Your browser sends your IP address and details like its type and version with every request, as it does to any website. Cloudflare, which sits in front of our servers, and our hosting provider use them to deliver the site and protect it from attacks. Our own logs record what was requested, without any query string, whether it worked, how long it took, and which account made the request, along with details of any errors, such as an email address we couldn't deliver to. They don't record IP addresses, apart from sign-in attempts at our admin portal, which we log to stop break-ins.
  • We may count visits with Plausible Analytics. If we do, it sees the address of the page you visit, without any query string, the site that sent you, your browser, operating system and device type, and your country, region and city, worked out from your IP address. It never sees the pages our emails link to for verifying an address or resetting a password. It doesn't store your IP address or set cookies, and can't tell who you are.
  • The site's fonts come from Google Fonts, so your browser fetches them from Google, which receives your IP address and browser details. The emails we send use the same fonts.

When you contact us

If you email us, we keep your message and our reply.

How we use it

We use your information to:

  • run Penguin HQ: create your account, sign you in to it and to every Penguin app, and remember your settings;
  • keep your account secure: check your email address, reset forgotten passwords, run two-step verification, and limit tries at passwords and codes;
  • run companies: their members and roles, the invitations they send, and whether they require two-step verification;
  • email you links to verify your address or reset your password, and the invitations people send you;
  • tell Penguin Poker and Penguin Parade who you are, which companies you're in, your role in each, and each company's plan, so they can sign you in and give you what your role and your company's plan allow;
  • take payments, and give each company what its plan includes;
  • let some companies try features before they're released;
  • understand how Penguin HQ is used, in aggregate, so we can improve it;
  • answer you when you write to us, and send you messages about your account, your company or changes to these policies;
  • prevent abuse, and meet legal obligations such as keeping payment records.

We don't sell your information, rent it out, or use it for ads.

Legal bases

If you're in the European Economic Area, the United Kingdom or another place with similar law, we rely on these legal bases:

  • Contract: to provide Penguin HQ to you and your company, including your account, signing in to the Penguin apps, companies, invitations and payments.
  • Legitimate interests: to keep Penguin HQ secure, prevent abuse, understand how it's used, and send invitations for the companies that ask us to. We rely on these only where your rights don't outweigh them.
  • Legal obligation: to keep payment and tax records, and to answer lawful requests.
  • Consent: where we ask for it. You can withdraw it at any time.

Who sees your information

Your company

Everyone in a company sees its members' names, email addresses, penguins and roles, and when they joined. Its owners and admins also see its pending invitations, with the address and role each went to and when it runs out, and, where companies can require two-step verification, whether each member has it on. Everyone in a company can see its plan, its seats and when its subscription renews or ends; only owners can change them, or open the company's billing in Stripe.

Invitations

When someone invites you, the email we send shows their name and email address and the company's name, and your companies page shows who invited you. When you invite someone, they see yours.

Penguin Poker and Penguin Parade

Penguin Poker and Penguin Parade use your Penguin HQ account. When you use one, it reads your account: your name, email address, penguin, theme and time zone, and whether you've verified your address and turned on two-step verification. It also reads your companies, with their members, roles and plans. The apps never see your password's hash or your authenticator secret. Inside an app, the people you work with see what that app's policy describes.

Service providers

These companies help us run Penguin HQ, and handle your information to provide their services to us:

  • Render hosts Penguin HQ, its database and the short-lived records described above, in the United States (Oregon).
  • Cloudflare runs our domain's DNS and sits in front of our servers, so every request to Penguin HQ passes through it.
  • Stripe processes payments. It also uses payment information under its own privacy policy, for example to prevent fraud.
  • Mailgun sends our emails.
  • Plausible Analytics counts visits, if we use it, in the European Union, without cookies.
  • Google serves the site's fonts.

For legal reasons, and if Penguin HQ changes hands

We may disclose information when the law requires it, or when we believe in good faith that it's needed to protect the rights, property or safety of our users, the public or us. If Penguin HQ is sold or merged, or its assets are transferred, your information may be transferred with it, and this policy will continue to apply to it.

Cookies and browser storage

We use only the cookies Penguin HQ needs to work. There are no advertising or tracking cookies, and our analytics don't use cookies at all.

  • __Secure-penguin_session keeps you signed in. It's set for all of penguinhq.dev, so Penguin Poker and Penguin Parade can read it and sign you in too. It lasts 30 days.
  • __Secure-ph_sign_in holds your place while signing in waits for your two-step code. It lasts 10 minutes, and only goes with sign-in requests.
  • __Host-ph_admin is only for the site's administrator. It lasts 12 hours.

Their prefixes keep them to secure connections, and the site's scripts can't read any of them.

We don't keep anything in your browser's local storage. The script that picks light or dark mode reads only your account's saved theme and your device's setting. Stripe sets its own cookies on its checkout and billing pages. Penguin Poker and Penguin Parade set a few cookies of their own, like Penguin Poker's guest cookie for its rooms, which their policies describe.

How long we keep it

  • Your account: until you delete it.
  • Sign-in sessions: until you sign out, they're ended (for example when you change your password), or you delete your account. Each one stops working after 30 days.
  • Email verification links: 24 hours, or until used.
  • Password reset links: an hour, or until used.
  • Two-step verification in progress: 10 minutes for a sign-in waiting for its code, 30 minutes for a setup waiting to be confirmed, and a couple of minutes for a code that's been used.
  • Counts of attempts: from 15 minutes to a day, as described above.
  • Invitations: until they're accepted, declined or revoked, or the company is deleted. They stop working after 14 days.
  • Companies: until their owners ask us to delete them.
  • Billing records: as long as we need them for accounting and tax law, which can be longer than the company lasts. Stripe keeps payment records as long as financial laws require.
  • Logs: our hosting provider keeps them for a limited time.

To delete your account, email cameron@webmatter.io. That deletes it from every Penguin app: we delete your account details, sessions, two-step secret and recovery codes, and company memberships, and each app deletes or keeps what you did in it as its own policy describes. Deleted information can remain in backups for a limited time.

Your choices and rights

  • Change your name, time zone and color theme, change your password, and manage two-step verification, from your account. Pick your penguin in either app. Turning on two-step verification, or changing or resetting your password, signs you out everywhere else, and you can sign out everywhere else without changing anything.
  • Email cameron@webmatter.io to get a copy of your information, to correct it, or to delete it, account and all. We'll answer within 30 days, and may ask you to confirm who you are first, for example by writing from your account's email address. The same address works for requests about Penguin Poker and Penguin Parade.
  • Your company's owners and admins manage its membership, and can tell you more about how your company uses the Penguin apps. Where we offer it, you can leave a company from its page.

Depending on where you live, including the European Economic Area, the United Kingdom and US states such as California, the law may give you the right to access, correct, delete or get a copy of your information; to object to or restrict how we use it; and to withdraw consent you've given. We won't treat you differently for using these rights. If you're in the EEA or the UK, you can also complain to your local data protection authority.

We don't sell or share personal information as California law defines those terms. And because we don't track you across other websites, there's nothing for Do Not Track or Global Privacy Control signals to turn off.

Security

We protect your information with HTTPS. We keep passwords only as Argon2 hashes, and session tokens, recovery codes and the links we email for verifying addresses and resetting passwords only as SHA-256 hashes. We encrypt two-step secrets with AES-256-GCM. Those emailed links carry their code after a #, which browsers don't send to servers, so it stays out of our logs. Access to the systems that run Penguin HQ is limited, and our admin portal asks for a code from an authenticator app as well as a password. No system is perfectly secure, so we can't promise your information will never be exposed, but if a breach affects it, we'll tell you as the law requires. You can help by using a password you don't use anywhere else, and turning on two-step verification.

International transfers

We're based in the United States, and Penguin HQ runs there. If you use it from somewhere else, your information is transferred to the United States and stored and processed there, where data protection law may differ from yours. Cloudflare, which every request passes through, handles requests in data centers around the world, and Plausible processes its analytics in the European Union. Where the law requires safeguards for these transfers, we rely on those our providers offer, such as the European Commission's standard contractual clauses.

Children

Penguin HQ isn't meant for children under 13, or under the minimum age where they live, and we don't knowingly collect their information. If you believe a child has given us information, email cameron@webmatter.io and we'll delete it.

Changes to this policy

We'll post any changes to this policy here, with a new date at the top. If a change significantly affects how we handle your information, we'll tell you by email or in the app before it takes effect.

Contact us

Questions, requests or complaints about privacy: email cameron@webmatter.io. Penguin HQ is run by Webmatter Solutions LLC, in Texas, United States.

© 2026 Webmatter Solutions LLCPowered with ❤️ by Webmatter
PricingTermsPrivacy