vpsFocus
Русский Sign in Create account

Privacy Policy

Draft. The list of data is accurate — it is derived from what the server actually stores. The text has not been reviewed by a lawyer, and the operator's details are placeholders.

Version 2026. Operator: [OPERATOR NAME], [REGISTRATION DETAILS]. Contact: [CONTACT EMAIL].

1. The short version

We keep exactly what is needed to check your plan and to reach you: your email address, a password hash, your account id, the server ids the app generates, and the domains of the sites you have connected.

We keep nothing that could be used to log into your client's server: no server addresses, no usernames, no SSH keys, no passwords, no passphrases, no host key fingerprints, and none of the credentials generated during provisioning. All of that lives in your operating system's credential store. What we do not have cannot leak from us.

2. What we collect and why

DataWhyHow long
Email addressSigning in, password recovery, messages about the accountWhile the account exists
Password hash (argon2id)Checking the password at sign-inWhile the account exists
Interface languageThe language of our lettersWhile the account exists
Account id, plan, plan expiry, plan historyAccess to paid featuresWhile the account exists
Server ids generated by the appTying sites to the servers they run onUntil the server is removed
Domains of sites connected to paid featuresExternal uptime checks and blacklist lookupsUntil the site is removed
Sessions: token hashes, creation and last-use time, the browser or app stringSigning in and the device listUp to 90 days, or until the session ends
Failed sign-in counterProtection against password guessingUntil the next successful sign-in
Technical logs: request method, path and durationDiagnostics[PERIOD]
App error reports — only with your explicit consentFixing bugs[PERIOD]

Your email address reaches us only from you: the app sends it when you sign in or register. Everything else the app sends about servers and sites is exactly what is listed above.

3. What we do not collect

  • Addresses, ports and usernames of your servers.
  • SSH keys, passwords and passphrases.
  • Server host key fingerprints.
  • Credentials generated during provisioning: the Postgres password, the session signing key, the analytics admin password, the agent token.
  • Notification settings: mail server parameters and the Telegram bot token.
  • Your clients' visitor analytics — all of it stays on the client's server.
  • Server metrics and the contents of the agent's checks.
  • Database connections, queries and results from the site data cards — the query runs from the app to the client's server directly, and the answer is shown only on your own screen.
  • Your Cloudflare API key, and the mail addresses, destinations and rules from the Mail tab — the app calls Cloudflare's API directly with a key that stays in your operating system's credential store, and mail is forwarded by Cloudflare straight to the inbox you chose.

An app error report contains no server addresses, no client domains and no secrets: the set of fields is pinned by an automated test, so adding anything new there can only be done deliberately, by breaking it.

4. Server logs

Logs record the request method, path and duration. Request bodies and headers are not recorded: they contain passwords and tokens.

5. Cookies

The site sets two cookies — one for the short-lived and one for the long-lived session token. Both are strictly necessary: without them you cannot stay signed in. Both are marked HttpOnly, so no script on the page can read them, and SameSite=Lax, so they are not sent from other sites. There are no analytics or advertising cookies.

6. Who else sees the data

We do not sell data and do not share it with third parties for advertising. Data may be processed by the infrastructure providers the service runs on: [HOSTING], [EMAIL PROVIDER].

On the paid plan, the domains of connected sites are used for external availability checks from our infrastructure, and malware checks are performed through the Google Web Risk API.

7. Where the data is stored

Servers are located in [COUNTRY, REGION]. Connections to the service are protected by TLS.

8. Your rights

  • Find out what data we hold about you.
  • Correct it: the address and password can be changed in your account page and in the app.
  • Delete the account with all related records — write to [CONTACT EMAIL].
  • Withdraw consent for error reports: the toggle on the account screen in the app. A refusal is remembered; we do not ask again.
  • End sessions on every device — the button in your account page and in the app.

Deleting the account does not touch a stack already deployed on your servers: it keeps running. You can remove it from the app.

9. Children

The service is intended for professional use and is not directed at people under [AGE].

10. Changes

We may change this policy. Material changes are announced to the account's email address.