Legal

Privacy Policy

Last updated: August 2, 2026

This Privacy Policy explains what information GridRocket ("we", "us") collects when you use our website, dashboard, and managed agent servers (the "Service"), how we use it, and the choices you have.

INFORMATION YOU PROVIDE

Account information: your email address, and any name or profile details you choose to add. Authentication is handled by our identity provider; if you sign in with Google we receive your email address, basic profile, and a provider identifier — never your Google password.

Billing information: our payment processor collects and stores your card details. We never see or store full card numbers. We do receive and store subscription status, plan, amounts, invoice identifiers, and the last four digits and brand of your card.

Support communications: messages, screenshots, and logs you send us when requesting help.

INFORMATION WE GENERATE

Deployment records: which plan and agent you selected, machine identifiers, region, hostname and subdomain, IP address of the machine, lifecycle state, and timestamps.

Provisioning and audit logs: the steps taken to build, reconcile, restart, or terminate your machine, plus administrative actions taken on your account. We deliberately exclude secret values such as root passwords and gateway tokens from log output.

Machine credentials: root or administrator passwords and agent gateway tokens generated at launch, stored so we can display them to you and so the machine can be managed.

Usage and device data: pages viewed, approximate location derived from IP address, browser and device type, and error diagnostics.

WHAT WE DO NOT COLLECT

We do not read, index, or mine the workloads running inside your machine — your prompts, files, model outputs, and application data stay on your server. We may access a machine only when you ask us to for support, when required to investigate abuse or a security incident, or when required by law.

HOW WE USE INFORMATION

To create and secure your account; to provision, monitor, repair, and terminate your machines; to issue DNS records and TLS certificates for your machine's subdomain; to process payments and prevent fraud; to provide support; to detect and stop abuse of the Service; to improve reliability and performance; and to comply with legal obligations.

LEGAL BASES

Where the GDPR applies, we process personal data to perform our contract with you (providing the Service), for our legitimate interests (security, abuse prevention, product improvement), to meet legal obligations, and — where required — with your consent.

WHO WE SHARE WITH

Infrastructure providers who host the virtual machines we provision on your behalf; DNS and certificate authorities used to give your machine a secure hostname; our authentication, database, and hosting platform; our payment processor; and analytics and error-monitoring services. Each receives only what it needs to perform its function.

We may also disclose information when required by law or valid legal process, to enforce our Terms, to protect the rights and safety of users or the public, or in connection with a merger, acquisition, or sale of assets (with notice to you).

We do not sell your personal information and we do not share it for cross-context behavioral advertising.

COOKIES

We use strictly necessary cookies and local storage to keep you signed in and to remember interface preferences. We may use privacy-respecting analytics to understand aggregate usage. We do not run third-party advertising trackers.

SECURITY

We use TLS in transit, access controls and role separation in the dashboard, row-level security on our database, and least-privilege service credentials. Machine credentials are stored so they can be shown to you and used for management, which means they are not zero-knowledge — treat your dashboard account as sensitive and enable strong authentication. No system is perfectly secure, and we cannot guarantee absolute security.

RETENTION

Account and billing records are retained while your account is active and afterwards as needed for legal, tax, and accounting purposes. Deployment and audit records are retained for operational and security history. Machine credentials are retained for the life of the machine and deleted with its deployment record. When a machine is terminated, the underlying disk is destroyed by the infrastructure provider and its contents are not recoverable by us.

YOUR RIGHTS

Depending on where you live, you may have the right to access, correct, export, or delete your personal information, to object to or restrict certain processing, and to withdraw consent. You can update most account details in the dashboard, and you can request deletion of your account by contacting us. We will respond within the period required by applicable law. EU and UK residents may also lodge a complaint with their local data protection authority.

INTERNATIONAL TRANSFERS

We operate in the United States and our providers may process data in other countries. Where required, we rely on appropriate safeguards such as standard contractual clauses for international transfers.

CHILDREN

The Service is not directed to children under 18 and we do not knowingly collect their personal information. If you believe a child has provided us information, contact us and we will delete it.

CHANGES TO THIS POLICY

We may update this Policy. Material changes will be reflected in the "Last updated" date above and, where appropriate, announced in the dashboard.

CONTACT

Privacy questions and data requests can be sent to privacy@gridrocket.dev.