← Back to sign in

Privacy Policy

Effective 24 September 2026 · Last updated 24 September 2026

What we collect

Account data: your email address and a sign-in credential managed by our authentication service (we never see or store your password in readable form), plus one-time-code and two-factor state. We record when you accepted these documents and which version you accepted.

Infrastructure data you connect: server hostnames and addresses, health-check results, metrics (CPU, memory, disk, network), incidents, deployment history, alert rules, and backup schedules.

Credentials you provide so Srvrsup can act for you: SSH keys, registry credentials and API tokens. These are stored encrypted and are used only to perform the actions you ask for or authorize.

Billing data: your plan, subscription status and payment-processor customer identifier. Card numbers are entered with our payment processor and never reach Srvrsup.

Operational data: request logs (including IP address and a request identifier), error reports, and security audit events.

How we use it

To run the service you asked for: monitor your servers, raise and explain alerts, run the repairs and deployments you approve, and bill your subscription. We do not sell personal information and we do not use it for advertising.

AI processing

Srvrsup uses artificial intelligence (large language models) to diagnose problems and suggest fixes. When a diagnosis is requested, relevant incident context, for example logs, error messages and service status from your servers, is sent to our model gateway, which routes to model providers. Diagnoses are suggestions produced by automated analysis and can be wrong; see the Disclaimer.

Who we share it with (sub-processors)

We share data only with the service providers needed to run Srvrsup: Hetzner (server hosting for the application and its database); Cloudflare (network routing and DNS); Vercel (hosting of the web dashboard); Stripe, through Agyeman Enterprises' central billing router (payment processing and subscription billing); Resend, for delivery of transactional email such as sign-in codes and alerts; and our AI model gateway (LiteLLM) with the model providers it routes to. Error reports go to our own self-hosted error-tracking service. We may also disclose information when required by law.

How long we keep it

Metrics are retained for 7 days on the Free plan and 90 days on the Pro plan, after which they are deleted. Other account and infrastructure data is kept while your account is open. When you delete your account, the data described above is deleted from our live systems immediately; copies in encrypted backups age out on our normal backup rotation. Billing records are retained for as long as tax and accounting law requires. Security audit events are retained for as long as needed to protect the service.

Your rights: access, export and deletion

You can export your data at any time: while signed in, request GET /admin/account/export and you receive a JSON file of the data your account owns (credential material is excluded). You can delete your account and its data at any time: while signed in, send DELETE /admin/account with confirmation, which removes your data and your sign-in identity. Depending on where you live you may also have rights to correct data, object to or restrict processing, and complain to a regulator; contact us to exercise them.

Cookies

Srvrsup sets a strictly necessary, HttpOnly session cookie to keep you signed in. We do not use advertising or cross-site tracking cookies.

Security

Credentials are encrypted at rest, transport is encrypted with TLS, access to production is restricted, and actions taken on your behalf are written to an audit log. No system is perfectly secure; we will notify affected customers of a breach as required by law.

Children

Srvrsup is not for anyone under 18 and we do not knowingly collect their data.

Changes

When we change this policy we update the effective date above and, for material changes, notify account holders.