beta

steezr cloud privacy policy

Effective 29 September 2026 · Version 1.0

This policy explains what personal data steezr cloud processes, why, who else sees it, how long we keep it and what you can ask us to do with it.

It covers the website steezr.cloud, the dash web app at dash.steezr.cloud, the scloud command line tool and the steezr cloud iOS app, together "the service". Use of the service is governed by the steezr Terms and Conditions.

1. Who is responsible

The controller of your personal data is:

steezr s.r.o.
IČO 22354883, DIČ CZ22354883
K Rybníčkům 282/19, 100 00 Praha 10, Czech Republic
Registered at the Municipal Court in Prague, file C 415229

Privacy questions and requests: support@steezr.com

We haven't appointed a data protection officer. Write to the address above about anything in this policy.

2. Our two roles

Controller for your account

For the data we need to run your account and the service (section 3), steezr s.r.o. is the controller and this policy applies.

Processor for what runs on your clusters

Your apps, their databases, buckets, logs and metrics run on clusters in your own Hetzner Cloud project. Personal data in them belongs to you and your users. For that data you are the controller and steezr s.r.o. acts as your processor under the steezr Data Processing Terms, which apply automatically. Your own privacy policy tells your users how their data is handled. Hetzner provides those servers under your own contract with Hetzner.

dash reads logs and metrics from your clusters to show them to you, but doesn't store them. It does store a summary of each cluster (numbers of apps, healthy apps and alerts) and the notifications it sends you.

3. Data we process

Account

Sign-in with GitHub, Google or Apple

If you sign in with one of these, we store the provider's user ID for you and the email address it gives us, and on first sign-in we take your name from the provider. We only accept an email address the provider has verified. Apple may give us a private relay address instead of your real one; we store whichever address Apple sends.

Two-factor authentication

If you turn on TOTP two-factor, we store its secret and ten recovery codes. The recovery codes are stored only as Argon2id hashes.

Sessions and tokens

Organizations

Which organizations you belong to, your role in each and which apps you can reach. For an invite: the invitee's email address, role, apps, who sent it and when it expires.

Audit log

Every change made through dash, the CLI or the API is recorded with the time, the email address of the person who made it, whether it came from the web or the CLI and the token name, the action, the app and target, the outcome and details, and how long it took. The audit log doesn't record IP addresses.

Push notifications

If you allow notifications in the iOS app, we store your device's Expo push token, the device name, the platform (iOS), and when it was registered and last seen. We also store your notification rules, and the notifications we send you (title, text, link, cluster, app and whether you've read it).

Hetzner and GitHub connections

Security and server logs

dash logs each request with the route, status, duration and the email address of the signed-in user. Failed sign-in attempts are logged with the email address and IP address. To slow down password guessing we count failed attempts per account, keyed by a hash, and per IP address in memory.

The steezr.cloud website sets no cookies and runs no scripts. Its web server logs requests (IP address, browser and page). It loads fonts from Google Fonts, so your browser sends your IP address to Google when you open it. dash and the iOS app ship their own fonts.

Support

If you email us, we have your email address and whatever you put in the message.

What we don't do

No analytics, no advertising, no tracking across sites or apps, and no selling of data. dash, the iOS app and scloud contain no analytics or crash-reporting SDKs, and the CLI sends no telemetry. We don't make decisions about you by automated means.

4. Why we process it

PurposeLegal basis (GDPR)
Creating your account, signing you in and running the service you asked for: clusters, apps, deploys, notifications, supportArt. 6(1)(b), performance of a contract
Keeping the service secure: rate limits, security logs, the audit log, detecting abuseArt. 6(1)(f), our and our customers' legitimate interest in a secure service and a record of who changed what
Accounting and tax records, answering lawful requests from authoritiesArt. 6(1)(c), legal obligation

We don't use your data for marketing.

5. Who else receives data

We use these service providers. Each gets only what it needs for its job.

RecipientWhat forWhere
Hetzner Online GmbHServers, database and backups for dashGermany
Amazon Web Services EMEA SARL (Amazon SES)Sending email: address confirmation and notification emailsFrankfurt region, Germany
650 Industries, Inc. (Expo)Delivering push notifications to the iOS appUSA
Apple (Apple Push Notification service)Delivering push notifications to your iPhoneUSA and other locations
GitHub, Google, AppleSign-in, only if you choose that providerUSA
GitHub, Inc.Repo access and CI through our GitHub App, if your organization installs itUSA
Google (Google Fonts)Fonts on the steezr.cloud websiteUSA and other locations

Some of these recipients are in the USA. Where personal data leaves the EU or EEA, we rely on the safeguards the GDPR allows, such as the recipient's certification under the EU-US Data Privacy Framework or the European Commission's Standard Contractual Clauses.

Certificate authorities and DNS providers see your domain names but no personal data about you. We disclose data to authorities only when the law requires it.

6. Where data is stored

dash, its database and its backups run on Hetzner servers in Falkenstein, Germany.

Your clusters run in the Hetzner location you pick when you create them. Hetzner offers locations in the EU and outside it, including the USA and Singapore. If you pick a location outside the EU, the data on that cluster is stored there. That choice, and its legal consequences for your users' data, are yours.

7. How long we keep it

DataKept for
Account, sign-in identities, two-factor data, memberships, notification rulesUntil you delete your account
Unconfirmed sign-ups24 hours
Web sessionsUntil you sign out or stop using dash, at most 14 days
CLI sign-in requests10 minutes
CLI and app tokens, push devicesUntil you revoke them or delete your account. CLI tokens stop working after 90 days.
InvitesStop working after 7 days. The invite record stays with the organization.
Notifications in your inbox90 days. Delivery records: 7 days.
Failed sign-in counters24 hours
Audit logFor as long as the organization exists, and after it's deleted, as the security record of who changed what. Entries are not removed when a member deletes their account.
Server and security logs30 days
Database backups30 days. Data you delete leaves the backups within 30 days.
Support emailsAs long as we need them to handle your request
Accounting recordsAs long as Czech accounting and tax law requires

8. Your rights

Under the GDPR you have the right to:

Email support@steezr.com from the address on your account. We answer within one month.

Deleting your account

In the iOS app, go to Settings → Delete account. In dash, go to Account → Delete account. If you're the only owner of an organization, make someone else an owner or delete the organization first. Deleting your account removes your sign-in, linked identities, two-factor data, tokens, devices, memberships and notifications. Organizations, apps and clusters are not deleted, and audit log entries stay (section 7).

Complaints

You can complain to the Czech supervisory authority, Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Praha 7, www.uoou.gov.cz, or to the authority where you live or work. We'd like the chance to fix it first, so please write to us too.

9. Security

No system is completely secure. If we learn of a personal data breach that affects you, we'll handle it as the GDPR requires.

10. Children

The service is for businesses and developers. It isn't directed at children under 16, and we don't knowingly process their data.

11. Changes to this policy

When we change this policy we publish the new version here with a new effective date and version number. If a change affects how we use your data in a significant way, we'll tell account holders by email or in dash before it takes effect.

12. Governing law

This policy is governed by Czech law and the General Data Protection Regulation (EU) 2016/679.