steezr cloud privacy policy
This policy explains what personal data steezr cloud processes, why, who else sees it, how long we keep it and what you can ask us to do with it.
It covers the website steezr.cloud, the dash web app at dash.steezr.cloud, the scloud command line tool and the steezr cloud iOS app, together "the service". Use of the service is governed by the steezr Terms and Conditions.
1. Who is responsible
The controller of your personal data is:
steezr s.r.o.
IČO 22354883, DIČ CZ22354883
K Rybníčkům 282/19, 100 00 Praha 10, Czech Republic
Registered at the Municipal Court in Prague, file C 415229
Privacy questions and requests: support@steezr.com
We haven't appointed a data protection officer. Write to the address above about anything in this policy.
2. Our two roles
Controller for your account
For the data we need to run your account and the service (section 3), steezr s.r.o. is the controller and this policy applies.
Processor for what runs on your clusters
Your apps, their databases, buckets, logs and metrics run on clusters in your own Hetzner Cloud project. Personal data in them belongs to you and your users. For that data you are the controller and steezr s.r.o. acts as your processor under the steezr Data Processing Terms, which apply automatically. Your own privacy policy tells your users how their data is handled. Hetzner provides those servers under your own contract with Hetzner.
dash reads logs and metrics from your clusters to show them to you, but doesn't store them. It does store a summary of each cluster (numbers of apps, healthy apps and alerts) and the notifications it sends you.
3. Data we process
Account
- Email address and name.
- Your password, stored only as an Argon2id hash.
- When you confirmed your email, when the account was created and when you last signed in.
- Before you confirm your email, the sign-up (email, name, password hash) waits in a separate table for up to 24 hours.
Sign-in with GitHub, Google or Apple
If you sign in with one of these, we store the provider's user ID for you and the email address it gives us, and on first sign-in we take your name from the provider. We only accept an email address the provider has verified. Apple may give us a private relay address instead of your real one; we store whichever address Apple sends.
Two-factor authentication
If you turn on TOTP two-factor, we store its secret and ten recovery codes. The recovery codes are stored only as Argon2id hashes.
Sessions and tokens
- Cookies in dash. dash sets only cookies it needs to sign you in:
__Host-dash_session(your session, renewed as you use dash, at most 14 days), and__Host-dash_oauth,__Host-dash_mfaand__Host-dash_mobile_confirm, which last 5 to 10 minutes during a sign-in. All are HttpOnly and SameSite=Lax. There are no advertising or analytics cookies, so we don't ask for cookie consent. - CLI and app tokens. When you sign in from
scloudor the iOS app, we issue a token and store only its SHA-256 hash, with a name (your computer's hostname or your device's name), when it was created and last used, and when it expires (90 days for CLI tokens). While a CLI sign-in waits for your approval, we keep the requesting IP address and the one-time code for up to 10 minutes. - On your devices.
scloudkeeps its token in the macOS keychain, or in a file only your user can read on other systems. The iOS app keeps its token in the iOS keychain.
Organizations
Which organizations you belong to, your role in each and which apps you can reach. For an invite: the invitee's email address, role, apps, who sent it and when it expires.
Audit log
Every change made through dash, the CLI or the API is recorded with the time, the email address of the person who made it, whether it came from the web or the CLI and the token name, the action, the app and target, the outcome and details, and how long it took. The audit log doesn't record IP addresses.
Push notifications
If you allow notifications in the iOS app, we store your device's Expo push token, the device name, the platform (iOS), and when it was registered and last seen. We also store your notification rules, and the notifications we send you (title, text, link, cluster, app and whether you've read it).
Hetzner and GitHub connections
- Hetzner API token. Stored encrypted (section 9). dash also installs it on your cluster, because the cluster needs it to manage its own servers and volumes.
- GitHub App. If your organization installs our GitHub App, we store the installation ID and the name and type of the GitHub account it's installed on. dash uses it to read your repos and set up CI.
Security and server logs
dash logs each request with the route, status, duration and the email address of the signed-in user. Failed sign-in attempts are logged with the email address and IP address. To slow down password guessing we count failed attempts per account, keyed by a hash, and per IP address in memory.
The steezr.cloud website sets no cookies and runs no scripts. Its web server logs requests (IP address, browser and page). It loads fonts from Google Fonts, so your browser sends your IP address to Google when you open it. dash and the iOS app ship their own fonts.
Support
If you email us, we have your email address and whatever you put in the message.
What we don't do
No analytics, no advertising, no tracking across sites or apps, and no selling of data. dash, the iOS app and scloud contain no analytics or crash-reporting SDKs, and the CLI sends no telemetry. We don't make decisions about you by automated means.
4. Why we process it
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating your account, signing you in and running the service you asked for: clusters, apps, deploys, notifications, support | Art. 6(1)(b), performance of a contract |
| Keeping the service secure: rate limits, security logs, the audit log, detecting abuse | Art. 6(1)(f), our and our customers' legitimate interest in a secure service and a record of who changed what |
| Accounting and tax records, answering lawful requests from authorities | Art. 6(1)(c), legal obligation |
We don't use your data for marketing.
5. Who else receives data
We use these service providers. Each gets only what it needs for its job.
| Recipient | What for | Where |
|---|---|---|
| Hetzner Online GmbH | Servers, database and backups for dash | Germany |
| Amazon Web Services EMEA SARL (Amazon SES) | Sending email: address confirmation and notification emails | Frankfurt region, Germany |
| 650 Industries, Inc. (Expo) | Delivering push notifications to the iOS app | USA |
| Apple (Apple Push Notification service) | Delivering push notifications to your iPhone | USA and other locations |
| GitHub, Google, Apple | Sign-in, only if you choose that provider | USA |
| GitHub, Inc. | Repo access and CI through our GitHub App, if your organization installs it | USA |
| Google (Google Fonts) | Fonts on the steezr.cloud website | USA and other locations |
Some of these recipients are in the USA. Where personal data leaves the EU or EEA, we rely on the safeguards the GDPR allows, such as the recipient's certification under the EU-US Data Privacy Framework or the European Commission's Standard Contractual Clauses.
Certificate authorities and DNS providers see your domain names but no personal data about you. We disclose data to authorities only when the law requires it.
6. Where data is stored
dash, its database and its backups run on Hetzner servers in Falkenstein, Germany.
Your clusters run in the Hetzner location you pick when you create them. Hetzner offers locations in the EU and outside it, including the USA and Singapore. If you pick a location outside the EU, the data on that cluster is stored there. That choice, and its legal consequences for your users' data, are yours.
7. How long we keep it
| Data | Kept for |
|---|---|
| Account, sign-in identities, two-factor data, memberships, notification rules | Until you delete your account |
| Unconfirmed sign-ups | 24 hours |
| Web sessions | Until you sign out or stop using dash, at most 14 days |
| CLI sign-in requests | 10 minutes |
| CLI and app tokens, push devices | Until you revoke them or delete your account. CLI tokens stop working after 90 days. |
| Invites | Stop working after 7 days. The invite record stays with the organization. |
| Notifications in your inbox | 90 days. Delivery records: 7 days. |
| Failed sign-in counters | 24 hours |
| Audit log | For as long as the organization exists, and after it's deleted, as the security record of who changed what. Entries are not removed when a member deletes their account. |
| Server and security logs | 30 days |
| Database backups | 30 days. Data you delete leaves the backups within 30 days. |
| Support emails | As long as we need them to handle your request |
| Accounting records | As long as Czech accounting and tax law requires |
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and get a copy,
- have it corrected,
- have it erased,
- restrict how we process it,
- receive it in a portable format,
- object to processing based on our legitimate interests,
- withdraw consent where we rely on it (at present we don't).
Email support@steezr.com from the address on your account. We answer within one month.
Deleting your account
In the iOS app, go to Settings → Delete account. In dash, go to Account → Delete account. If you're the only owner of an organization, make someone else an owner or delete the organization first. Deleting your account removes your sign-in, linked identities, two-factor data, tokens, devices, memberships and notifications. Organizations, apps and clusters are not deleted, and audit log entries stay (section 7).
Complaints
You can complain to the Czech supervisory authority, Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Praha 7, www.uoou.gov.cz, or to the authority where you live or work. We'd like the chance to fix it first, so please write to us too.
9. Security
- All traffic to dash uses TLS, and dash sends HSTS.
- Passwords and recovery codes are hashed with Argon2id. CLI and app tokens are stored as SHA-256 hashes.
- Hetzner API tokens and GitHub App secrets are encrypted with AES-256-GCM, using a separate key per organization.
- Session cookies are HttpOnly, and sign-in attempts are rate-limited per IP address and per account.
- Two-factor authentication, which an organization can require for all its members, and a 15-minute step-up for sensitive actions.
- Roles limit what each member can see and change, and the audit log records every change.
No system is completely secure. If we learn of a personal data breach that affects you, we'll handle it as the GDPR requires.
10. Children
The service is for businesses and developers. It isn't directed at children under 16, and we don't knowingly process their data.
11. Changes to this policy
When we change this policy we publish the new version here with a new effective date and version number. If a change affects how we use your data in a significant way, we'll tell account holders by email or in dash before it takes effect.
12. Governing law
This policy is governed by Czech law and the General Data Protection Regulation (EU) 2016/679.