Privacy policy
Effective
Data and purposes
We use account details such as email, authentication information, and workspace records to sign you in and run your account. Google OAuth, when used, supplies profile and email information for authentication. We store service configuration, deployment status, provider credentials you supply, wallet balances, payment references, and ledger records to provision hosting, match payments, manage billing, and resolve support requests.
Your hosted app processes the content you choose to put into it. Your model provider receives requests sent using your API key under that provider's own terms. Operational logs and error reports help troubleshoot failures and protect the service. Support messages are used to answer requests and investigate billing or service issues.
Service providers and storage
The Rails control plane stores account, billing, and deployment records in SQLite on the hosting infrastructure. Coolify manages application deployment; Cloudflare handles DNS and network services; Resend delivers transactional emails; Google supports OAuth sign-in; GoPay/QRIS payment services handle payment information needed for payment matching. These providers receive data necessary for their respective functions. Your selected AI/model provider processes app requests separately.
Sentry receives error reports when configured. The application disables automatic user/IP collection, cookies, headers, request and response bodies, query parameters, job arguments, breadcrumbs, and performance tracing. Error messages, stack traces, and URL paths can still contain information needed to diagnose failures. This error reporting is separate from optional marketing tracking.
External providers may process information in countries other than yours and apply their own storage and retention practices. No promise of local-only processing is made.
Cookies and optional tracking
Authentication and security use necessary session mechanisms. The homepage may offer optional Google Tag Manager and Meta Pixel measurement only when configured. Neither provider loads before you accept optional tracking. They measure homepage visits and signup-link clicks; a click is not a completed signup. Application events do not send your email, account ID, or form content, but the providers can receive network/device information and set cookies.
Accept or decline in the homepage consent controls. Reopen “Tracking settings” there to change or withdraw your choice. Consent choice is saved in browser local storage; unavailable storage defaults to no tracking on the next visit. Global Privacy Control prevents optional tracking. Withdrawal stops future page tracking after reload; existing provider cookies can be removed in browser settings. Optional GTM/Meta tracking is not installed on legal, account, or dashboard pages.
Retention and your requests
Records are kept for account and service operation, billing reconciliation, security, dispute handling, and applicable legal obligations. No fixed retention schedule is promised here. Deleting a deployment does not necessarily delete billing records, logs, backups, or records held by providers. Avoid placing secrets or personal information in public service names or URLs.
Use the configured support email below to request access, correction, deletion, or information about your data, and to exercise privacy rights available under applicable law. We may need to verify account ownership before acting. Some records may need to be retained for billing, disputes, security, or legal obligations; we will explain relevant limits when responding. No guaranteed response deadline is stated here. If support details are missing, the public contact channel is not yet available.
