Privacy Policy
Draft — pending legal review. Last updated 20 July 2026.
1. What this covers
This policy covers the Nexploy marketing site, the account you create for a managed instance, and the dashboard. It does not cover data inside your own self-hosted instance, which never reaches us.
2. What we collect, and why
Account details you provide (email, name, authentication method) to create and secure your account; billing information handled by Stripe to process payment; technical logs (IP address, timestamps, request metadata) to operate and secure the service and investigate abuse.
3. Legal basis
We process account and billing data to perform the contract with you (running your subscription). We process technical/security logs under our legitimate interest in keeping the service secure and reliable. Where we send optional product updates by email, we rely on your consent, which you can withdraw at any time.
4. What we don’t collect
We don’t read or store your source code, environment variables or container logs beyond what a managed instance needs to run — and we never proxy or store prompts sent to the AI assistant on our own servers.
5. Subprocessors
Third parties that process data on our behalf, and what for:
| Subprocessor | Purpose | Data |
|---|---|---|
| Stripe | Payment processing and billing | Billing details, transaction history |
| Resend | Transactional email delivery | Email address, message content of the email sent |
| GitHub / GitLab / Gitea / Bitbucket / Azure Repos | OAuth repository access and webhook registration | Account identifier, email, repository/webhook access granted. A repository added by custom URL uses no OAuth and shares no account data. |
| Hetzner Online GmbH | Hosting infrastructure for managed instances | Server and application data for the instance you provision |
Retention periods by data type:
- Account data
- Duration of the account, plus 3 years after closure for legal/accounting purposes
- Billing records
- 10 years, as required by accounting law
- Technical/security logs
- 12 months, then anonymized or deleted
- Support communications
- 3 years after the last exchange
6. International transfers
Managed instances run on Hetzner, primarily in its EU data centers (Germany, Finland); some regions it offers are outside the EU/EEA (e.g. the US). Where a transfer outside the EU/EEA happens — on Hetzner or another subprocessor above — it relies on their published safeguards (such as EU Standard Contractual Clauses). Details are available on request.
7. Your rights
You can request a copy of your data, ask us to correct or delete it, restrict or object to certain processing, or ask for portability — subject to what we are legally required to keep. You can also lodge a complaint with your local data protection authority (in France, the CNIL). Contact us to exercise any of these.
8. Cookies
The dashboard uses a single cookie to keep you signed in and to remember your theme preference. We don’t use third-party tracking or advertising cookies.
9. AI assistant and automated processing
The AI assistant is an optional feature that acts on tools you explicitly grant it, and asks for confirmation before any change to a running service — it does not make unattended decisions about your account or billing. Where automated interaction features fall under AI transparency regulation (such as the EU AI Act), the product interface will clearly disclose when you are interacting with an AI system, in addition to this policy.
10. Changes
We may update this policy as the product changes. Material changes will be announced with reasonable notice before they take effect.
11. Contact
Questions about this policy, or requests about your data, can be sent to [email protected]. Publisher identity and address are on the Legal Notice page.