Draft — not yet in force. This document contains unfilled placeholders
and has not been reviewed by counsel. Complete src/lib/legal.ts and have these pages reviewed before launch.
Privacy Policy
Effective [EFFECTIVE DATE] · [LEGAL ENTITY NAME]
This policy explains what [LEGAL ENTITY NAME] collects when you use Ratna, why, and what you can do about it. It covers your data as our customer. Data that your application collects from its visitors is yours to govern — there, you are the controller and we act as your processor.
What we collect
- Account data — name, email address, and (if you sign in with GitHub) your GitHub username and account ID. If you use a password, we store only a bcrypt hash of it, never the password itself.
- Repository data — the source of repositories you explicitly authorise us to build, plus the build artefacts and VM snapshots we produce from them.
- Operational logs — build logs, application logs you emit, and deployment history.
- Request and usage metrics — request counts, response times, bandwidth, compute time and build minutes, used for metering, billing and capacity planning. These include visitor IP addresses in short-lived request records and in abuse-prevention systems.
- Billing data — plan, invoices and payment status. Card details are handled by our payment provider and never reach our servers.
- Support correspondence — what you send us when you ask for help.
Why we use it
- To run the service: build, deploy, route traffic to, and scale your applications.
- To bill you accurately and enforce plan limits and spend caps.
- To keep the platform secure and available — detecting abuse, diagnosing incidents, and preventing attacks.
- To communicate with you about your account: deployments, quota warnings, billing, security notices and service changes.
We do not sell your data, and we do not use your code or content to train machine-learning models.
Legal bases
Where data-protection law such as the GDPR applies, we rely on: contract (to provide the service you signed up for), legitimate interests (security, abuse prevention, and improving the platform), legal obligation (tax and accounting records), and consent where we ask for it specifically.
Who we share it with
We use a small number of sub-processors to run the service. Each receives only what it needs:
| Provider | Purpose | Data involved |
|---|---|---|
| Hetzner | Hosting / compute infrastructure | All service data at rest and in transit |
| Polar | Payments and subscription billing | Name, email, billing details, transaction records |
| GitHub | Sign-in and source-repository access | Account identity, repository contents you authorize |
| Bunny.net | CDN / edge delivery | Request metadata and cached response content |
| Backblaze B2 | Encrypted offsite backups | Encrypted database backups |
| [MAIL PROVIDER] | Transactional email | Email address, message contents |
We may also disclose data where legally required, or where necessary to protect our rights, our users, or the public. If we are compelled to disclose your data, we will try to notify you unless legally prohibited.
Where data is stored
The platform runs on servers in Europe. Content may be cached at edge locations worldwide to serve your visitors quickly, and encrypted backups are stored with a third-party provider. This means data may be transferred outside your country; where required we rely on standard contractual clauses or equivalent safeguards.
How long we keep it
- Account data — while your account is open, then deleted or anonymised within 90 days of closure.
- Applications, artefacts and snapshots — until you delete them or close your account.
- Logs and request metrics — rolled up into aggregate usage figures and pruned on a rolling basis; raw records with IP addresses are short-lived.
- Billing records — retained as long as tax and accounting law requires, typically several years, even after account closure.
- Backups — encrypted, on a rotating retention window; deleted data disappears from backups as they age out.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to complain to your data-protection authority. You can change most account data in the dashboard directly, and delete your account at any time. For anything else, write to [PRIVACY@YOURDOMAIN] and we will respond within the period required by applicable law (and in any case promptly).
Security
Applications run in hardware-isolated microVMs with per-tenant network isolation and syscall filtering. Traffic is encrypted in transit with TLS, passwords are stored as bcrypt hashes, and backups are encrypted. No system is perfectly secure; if we become aware of a breach affecting your personal data, we will notify you and any relevant authority as required by law.
Cookies
We use a single essential cookie to keep you signed in. We do not use advertising or cross-site tracking cookies in the dashboard. Cookies set by your deployed application are your responsibility to disclose to your visitors.
Children
The service is not directed at children, and we do not knowingly collect data from anyone under the age required to consent in their jurisdiction.
Changes
We will update this policy as the service evolves. Material changes will be announced by email or in-product before they take effect, and the effective date above will change.
Contact
[LEGAL ENTITY NAME], [REGISTERED ADDRESS]. Privacy questions and data requests: [PRIVACY@YOURDOMAIN].