Privacy Policy
Last updated: July 16, 2026
This policy describes what personal data DeployYourCode collects, why we collect it, and how you can exercise control over it.
1. Data we collect
Account data (name, email, password hash or social-login identifier, optional avatar), organization data (name, members, projects, uploaded logos), billing data (subscription status and history — full payment details are held by Stripe, not us), security data (active sessions, two-factor and passkey enrollment, sign-in audit events), and basic server logs (IP address, user agent) for security and debugging.
2. How we use it
To provide and secure the Service: authenticating you, running your organizations, processing subscription payments, sending transactional email (invitations, password resets, receipts, billing alerts), preventing abuse, and complying with legal obligations. We do not sell personal data or use it for third-party advertising.
3. Processors we share data with
Stripe (payments), Resend (transactional email), Inngest (background job processing), Anthropic (the AI assistant and the automatic build-fix feature), GitHub (reading the repositories you connect), Fly.io (running your applications and databases), Cloudflare (domain registration, if you buy a domain through us), and our hosting and database providers. Each processor receives only the data required for its function and is bound by its own data-processing agreement.
4. Cookies and local storage
We use strictly necessary, first-party cookies only: a session cookie to keep you signed in, one additional session cookie per extra account you sign in to on the same device, a short-lived cookie during social sign-in, a cookie recording which sign-in method you last used, and — if you complete two-factor authentication — a cookie that remembers this browser for 30 days so you are not challenged every time. Your theme preference and some interface state are kept in your browser's local storage and are not sent to us. We use no advertising, analytics or cross-site tracking cookies of any kind, and load no third-party scripts.
5. Data retention
Account and organization data is retained while your account is active. Webhook delivery logs are kept for 30 days, in-app notifications for 90 days, uptime history for 30 days, AI assistant conversations for 180 days after their last message, and audit-log entries for 12 months, after which they are automatically pruned. Application runtime logs are not stored by us — they are read live from the hosting provider and are subject to its own retention window. Server logs are rotated on a short schedule by our hosting provider.
6. Your rights
You can update your avatar and your security settings (password, two-factor, passkeys, active sessions) from the account page, and permanently delete your account there — we email you a confirmation link, and organizations where you are the only member are deleted with it. An organization owner can export the organization's data as JSON from the settings page. To correct your name or email address, or to request a copy of your personal data, contact us at the address below and we will action it. Depending on your jurisdiction you may have additional rights (access, rectification, erasure, portability, objection).
7. The AI assistant
The in-app assistant and the automatic build-fix feature send data to Anthropic to generate a response: the messages you type, and — so it can answer them — details of your projects, environments, services, deployments, databases, domains and usage. Automatic build fixes additionally send the contents of the repository files being diagnosed. Conversations are stored so you can return to them, are visible only to you — other members of your organization cannot read them — and are deleted 180 days after their last message. The assistant has read-only tools: it cannot change anything without you approving a specific action first, and it is never given your environment variable values, your database credentials, or the output of your running application.
8. Security
Passwords are hashed, sessions can be revoked remotely, and optional two-factor authentication and passkeys are available on every account. Data is encrypted in transit. Tenant data is isolated per organization at both the application layer and the database layer (row-level security). Application secrets — environment variables, managed database passwords — are encrypted at rest with AES-256-GCM and are never displayed back to you anywhere in the product. Note that if your own application prints a secret to its logs, that output is visible to members of your organization in the log console; we cannot filter your application’s output. Our staff can access tenant data for support and can sign in as a user to reproduce a problem; every such action is recorded in the audit log. If you would rather keep a secret in your own vault (Azure Key Vault, AWS Secrets Manager, Google Secret Manager, HashiCorp Vault), we store only a pointer to it and read the value when your app is deployed, so we hold no copy.
9. International transfers
Our processors may store or process data outside your country. Where required, those transfers rely on standard contractual clauses or an equivalent safeguard offered by the processor.
10. Changes to this policy
We will notify you of material changes to this policy by email or an in-app notice before they take effect.
11. Contact
Privacy questions or data requests: privacy@deployyourcode.com.