Draft, pending legal review

This page describes how the product actually works and is written by the people who built it. It has not been reviewed by a lawyer and is not yet a binding agreement.

Privacy

The short version: we hold your backups as ciphertext we cannot read, the minimum account data needed to run the service, and analytics you can decline. We do not sell anything to anyone.

What we hold

DataWhyCan we read it?
Backup artifactsThe productNo. Encrypted on your machine with a key we never receive
Artifact metadata: size, checksum, timestamps, retentionListing, retention, billingYes
Account: name, email, workspace membershipSign-in and access controlYes
Source credentials, cloud backups onlyTo connect to the database you asked us toHeld in a secrets vault, read at run time. Local backups never send them
Audit trail: who changed what, and whenYour record, and oursYes. Never contains a secret
Usage countersBillingYes. Quantities only, never content

What we cannot do

Backup data is encrypted before it leaves the machine that produced it, with a public key you supply. We store the result and never receive the private half.

We cannot decrypt your backups. We cannot recover them if you lose your key, and we cannot produce their contents in response to a request from anyone, including a legal one. We can only produce the ciphertext and the metadata listed above.

Who else processes it

We use a small number of providers. Each is listed with what it actually receives.

ProviderPurposeWhat it receives
WorkOSSign-in and organisationsName, email, workspace membership
StripePayments and invoicingBilling details, usage quantities. We never see your card
Amazon S3Artifact storageEncrypted artifacts
Oracle CloudCompute for the serviceRuns the application; holds no plaintext backup data
Google AnalyticsTraffic on this marketing sitePage views and referrers, only if you accept. Nothing from the product itself
Grafana CloudInfrastructure metricsMachine metrics. No customer data

Analytics and cookies

This marketing site uses Google Analytics to count visits, and only if you accept it. Decline and it is never initialised. There is no advertising network, no cross-site tracking pixel, and no analytics of any kind inside the product dashboard today.

We also use Google Search Console to see which searches lead here. It reports from Google’s own index and receives nothing from us.

How long we keep things

  • Artifacts are kept for as long as the retention policy you set says, then deleted. If you set a protection lock, they cannot be deleted before it expires, including by us.
  • Run history is available for 30 days.
  • Audit entries are kept for the life of the workspace.
  • A closed or unpaid account keeps its data for a year before anything is deleted, and downloads keep working throughout.

Your data, on the way out

You can download every artifact you hold, at any time, in every account state. Artifacts are self-describing and open with standard tools, so leaving does not require our cooperation or our continued existence.

Requests

To see, correct or delete the account data we hold, email us from the address on the account. We will tell you what we hold and what we cannot produce, which for backup contents is everything.