Legal
Hestia privacy policy
Hestia receives your Google account ID and email address to sign you in. It uses nothing else from your Google account.
Last updated 5 October 2026
About this policy
Hestia is a website builder built and operated by tlsc (tlsc.io). tlsc hosts and runs a Hestia site for each of its customers, and the people the customer invites sign in with Google to edit it.
This policy explains what Google user data Hestia accesses, how it is used, shared, protected, kept, and deleted. It also covers the other information Hestia handles, including data about visitors to the sites it hosts. Questions go to [email protected].
Google user data Hestia accesses
When you sign in with Google, Hestia requests only the openid and email scopes. From Google it receives:
- Google account ID: the number Google uses to identify your account.
- Email address: the address on your Google account.
- Email verified: whether Google has confirmed you own that address.
- Workspace domain: the domain of your Google Workspace organisation, if you belong to one.
Hestia does not request or receive your name, profile picture, contacts, calendar, files, or mail. It does not request offline access, and it does not keep Google access tokens or refresh tokens.
How Hestia uses Google user data
Each item is used only to sign you in:
- Google account ID: ties your Hestia account to the Google account that first signed in with your invited email, so no other Google account can use it.
- Email address:matched against the people the site owner invited. It is also shown to the site’s owners in the list of people with access, and used to send you one email when you are added.
- Email verified: sign-in is refused if Google has not verified the address.
- Workspace domain: checked once, at sign-in, to recognise tlsc staff. It is not stored.
Hestia does not use Google user data for anything else. It never uses Google user data for:
- targeted or any other advertising
- selling to data brokers or anyone else
- training AI or machine learning models
- determining creditworthiness
- lending purposes
Hestia’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How Hestia shares Google user data
tlsc does not sell, rent, or trade Google user data. It is shared, transferred, or disclosed only as follows:
- The site’s owners see the email address and role of everyone with access to their site.
- tlsc staff can see the same list to run and support the site.
- Railway, tlsc’s hosting provider, stores the database that holds your email address and Google account ID.
- Resend, tlsc’s email provider, receives your email address to send the email telling you that you were added.
- When the law requires it, tlsc may disclose data to comply with a valid legal request.
Google user data is never shown to visitors of the public site and never given to advertisers or other third parties.
How Hestia protects Google user data
- Your email address and Google account ID are stored in a database that belongs to one customer’s site only, separate from every other site. It is hosted by Railway in Singapore.
- The only way in is Google sign-in. Hestia has no passwords to leak or guess, and only people the site owner invited, plus tlsc staff, can sign in.
- Sign-in checks Google’s signed response and refuses any address Google has not verified.
- The session cookie cannot be read by scripts on the page, is sent only over HTTPS, and expires after 8 hours, or 1 hour for tlsc staff. It cannot be extended.
- Every request checks the account again, so a removed person is locked out at once.
- No Google access or refresh tokens are kept anywhere.
How long Google user data is kept, and how to delete it
- Your email address and Google account ID are kept for as long as you have access to the site.
- When a site owner removes you, your account, including both, is deleted from Hestia at once, and you are signed out.
- When a customer stops using Hestia, tlsc hands the site over or gives the customer a full export, then deletes its own copies.
- Your email address can stay in Resend’s delivery records, and in server logs if an email failed to send, for as long as those providers keep them.
To have your Google user data deleted, ask the site’s owner to remove you, or email [email protected] from the address on your account. You can also remove Hestia’s access at any time in your Google account settings. After that you can no longer sign in to Hestia.
Other information Hestia handles
Site content. The pages, images, translations, settings, and earlier versions your team creates belong to the customer. tlsc keeps them only to run the site. Deleted images are permanently removed after 14 days.
Cookies. Signing in sets the session cookie described above. While you sign in, a second cookie holds the sign-in check for up to 10 minutes. Both are used only by the editor. Visitors to the public site get no cookies.
Site visitors. To show the customer how fast their site is, Hestia records the page address (without anything after a question mark), whether the screen is phone, tablet, or desktop size, and load and response times. No IP address or browser details are stored. An IP address is held in memory for a moment to stop anyone flooding the site with requests, then forgotten. Measurements are deleted after 30 days. Hestia has no third-party analytics or advertising trackers.
Changes to this policy
If this policy changes, the new version is posted here with a new date. If Hestia changes how it uses Google user data, people who use Hestia are notified before the change takes effect.
Contact
Hestia is operated by tlsc. Questions or requests about privacy go to [email protected].
