Legal

Privacy Policy

We sell hosting, not data. This policy covers what we collect, where it lives, who we share it with, and when it is deleted.

1. The short version

We sell hosting, not data. We collect the minimum we need to run the service, keep it in Australia, share it with as few processors as possible, and delete it on a published schedule. Privacy is a large part of why customers choose managed open-source apps, and we treat that as a design constraint, not a slogan.

2. Two kinds of data, two roles

Your account data: name, email, billing records, support tickets. For this, we are the data controller and this policy describes exactly how it is handled.

Your instance data: everything inside the apps we host for you, your files, your users, your customers' records. For this, you are the controller and we are a processor: we store and back it up as ciphertext-at-rest infrastructure, and we access it only to operate the service: backups, updates, diagnostics you request, or abuse investigation with cause. Routine monitoring covers resource metrics, not content.

3. What we collect and why

Account data (from you, at signup): name and email address, used to create and secure your account and to contact you about your services.

Billing data: processed by Stripe. Card details never touch our servers; we hold invoices and transaction records.

Support data: the content of your tickets and, where you ask us to help with an app, relevant instance logs. Our AI support agent processes ticket content and app logs to diagnose problems. This is disclosed here deliberately, and its access is fenced to your own services.

Usage data (optional): website analytics run only after you accept analytics cookies, and are retained no longer than six months.

4. Where data lives

Our control plane (accounts, billing records, tickets) runs in AWS Sydney (ap-southeast-2). Instances and their backups live in the region you chose when deploying; for Australian-region apps, that means your instance data and its backups stay in Australia, full stop.

We voluntarily apply the Australian Privacy Principles to how we handle personal information, and this policy is written to those standards.

5. Who we share data with

Only the processors needed to run the service: Stripe (payments), Amazon Web Services (control plane and backup storage), Amazon Cognito (authentication), Amazon Bedrock (the AI support agent's language model), and our datacenter providers for the physical servers in each region. We do not sell or rent personal data to anyone, and we disclose it beyond this list only where the law requires or to defend legal claims.

6. Retention and deletion

Instance data: retained for 14 days after an app is terminated (a recovery safety net), then permanently deleted, backups included.

Account data: retained while your account exists and deleted within 30 days of account closure, except transaction records and basic contact details we must keep for legal and accounting purposes.

Analytics data: no more than six months.

7. Data breaches

If a data breach occurs that is likely to result in serious harm, we will notify affected customers and the Office of the Australian Information Commissioner in line with the Notifiable Data Breaches scheme: promptly, plainly, and with what we know and what we are doing about it.

8. Your rights

You can request a copy of the personal information we hold about you, correction of it, or deletion of your account and its data at any time. For instance data, you can help yourself: SFTP and app-level exports are always available.

9. Changes

When we update this policy we will publish the new version here and email registered users about material changes.

10. Contact

Privacy questions or requests: