Privacy policy
Who is responsible
Stephan Gomer, a sole proprietor registered in Poland (NIP 1133096755), who runs Pethost, decides what happens with the data described here. For anything about your data, write to support@pethost.dev.
What we keep, and why
- Your account. Your email address and your name, when your sign-in or the checkout gave them to us; the public part of your passkeys; the id of your Google or GitHub account, if you sign in with one. We need these to sign you in and to write to you about your machine.
- Sessions and agents. A sign-in cookie, and for each AI agent you approved its name and a token, which we store only as a hash.
- Your subscription. Your plan, its state, and the ids Stripe gives your customer record and your subscription. Your card's details go to Stripe and never reach us.
- Your GitHub repositories. If you connect GitHub: which repositories you let Pethost read, so that your machine can download the commits you deploy.
- What you write to us. Your messages to support, and our answers.
We keep all of this to give you the service you pay for, which is the contract between us; we keep what the law on taxes and accounts requires for as long as it requires.
We send you email about your machine only: that it is ready, or that its backups have stopped. We send no advertising.
Visits to this site and the panel
The front page of pethost.dev and the pages of the panel count their visits with Google Analytics. Its script reaches your browser from our own domain. It sets cookies that tell one browser from another, for up to two years, and sends Google the page you opened, the page you came from, your browser and device, and your approximate location, which Google works out from your IP address without storing the address. Of the panel it is told which kind of screen is open (the list of projects, a project's logs), never the names of your projects or anything on those screens.
When you make an account, begin a checkout or pay, the panel's server tells Google Analytics that it happened, with the plan and the amount, under the id those cookies gave your browser, or under a number made from your account's id where your browser has none. This is how we learn what brings people to Pethost.
What is on your machine
Your projects, their files and settings, and their logs are on your machine. So are the request logs of your sites, which hold your visitors' IP addresses and browsers' names for 30 days, and the output of your containers, for 7 days. Backups are encrypted on the machine before they leave it, and kept for as many days as your plan states.
This data is yours, and we handle it only on your behalf, to run the service. For your sites' visitors, you are the one who answers for their data, and we are your processor.
Your domain under pethost.app is public: it is in the DNS, and certificate authorities publish every certificate they issue in public logs. The names under it are not published there, but anyone can guess one. After you pay we suggest one made from your GitHub login or the part of your email before the @; it becomes your domain only if you keep it. Your own domains are public in the same way.
What we do not do
- No advertising, and no selling of data.
- Besides the cookies of Google Analytics, the panel sets two, both needed to sign in: one for your session, and one that lives a few minutes while you sign in.
- The panel keeps no log of the addresses its visitors come from.
Who else handles it
- Hosting providers: the machines are on their servers, in the region of your plan (today Europe, in data centres in the European Union). The storage of the backups and the server of the panel, where the account data is, are in the European Union. We name them when you ask.
- Cloudflare (United States): the network in front of this site and of the panel. It sees the addresses of those who visit them, to deliver the pages and to keep attacks away.
- Stripe and its service Link (Ireland and United States): the payments. Link sells the subscription to you as the merchant of record, and answers for the payment data itself.
- Resend (United States): sends our emails.
- Google Analytics (Ireland and United States): the count of visits to this site's front page and to the panel, and of the accounts and payments that follow them.
- Google and GitHub (United States): signing in, if you choose them, and your repositories, if you connect them.
- Google Trust Services and Let's Encrypt (United States): the certificates of your sites. They learn your domain under pethost.app and your own domains, and nothing about you.
Where one of them handles data in the United States, it does so under the safeguards European law requires: the EU–US Data Privacy Framework or the standard contractual clauses.
How long we keep it
- Your account: for as long as you have it. Ask us, and we delete it.
- Your machine and its backups: erased and deleted within 30 days after your subscription ends, or sooner if you ask.
- Messages to support: for a year after the last one.
- Visits to this site and the panel: Google keeps what it holds about a single visitor for two months; the totals stay.
- Records of payments: Stripe keeps them, for as long as the law requires.
Your rights
You can ask us for a copy of your data, to correct it, to delete it, to limit what we do with it, or to hand it to you in a form another service can read, and you can object to a use of it. Write to support@pethost.dev: we answer within a month.
You can also complain to your country's data protection authority. In Poland that is the President of the Personal Data Protection Office (UODO).
Changes
When this policy changes in a way that matters to you, we tell you by email before the change applies.