ox Privacy
Features Docs Log in

Privacy policy

Draft, last updated 2026-10-04

ox Cloud (getox.in) deploys your repositories onto servers that you own. This page says what ox keeps about you, what it does not keep, who else sees it, and how to use your rights. Questions about any of it: [email protected].

1. Who is responsible

2. What ox stores about you

What ox does not keep

3. Cookies and tracking

ox sets only the cookies it needs to work, so no consent banner is shown:

ox has no analytics, no advertising trackers, and no third-party scripts. The landing, docs and sign-in pages load their fonts and scripts from ox itself. The signed-in console loads two typefaces (Inter and JetBrains Mono) from Google Fonts, so Google receives your IP address and browser details when you open the console. TODO (owner): self-host these fonts, as the landing already does, to remove the last third-party request. ox does not store a theme preference.

4. Who else handles the data (sub-processors)

5. Where data goes, and international transfers

Customers are worldwide, so account data is processed on the plane, wherever its host is (see the sub-processors above). Where the law requires a transfer mechanism for data sent out of the UK, EU or EEA, ox relies on the standard contractual clauses (and the UK addendum) with its providers where they offer them. TODO (owner): confirm the plane's region and the transfer terms with each provider.

6. Legal bases (GDPR and UK GDPR)

ox does not use automated decisions that have legal effects on you.

7. Your rights, and how to use them

Two of them need no email. Get a copy: in the console, Settings, Your data, Download my data, or ox account export. You get one JSON file with your profile, servers, projects, runs, audit log, token names and settings; it holds no secret, and your apps' variables and data are on your own servers, so they are not in it. Three downloads an hour. Delete your account: Settings, Delete account, or ox account delete --confirm <your GitHub login> (section 8). For anything else, such as a correction or an objection, email [email protected] from the address on your account, or say which GitHub login is yours. ox answers within 30 days.

For data in your applications, which is on your server, make the request to the app's owner (your customer, if you are their user). ox cannot see it.

8. What happens when you delete things

9. Security

Secrets on the plane are encrypted, tokens are stored as hashes, each account sees only its own data, the agent on your server connects out to the plane (no open inbound port for ox), and every action is audited. No system is perfectly secure. If a breach affects your personal data, ox will tell you and the authorities as the law requires.

10. Children

ox is for developers and is not meant for anyone under 16. ox does not knowingly collect data from children.

11. Changes

If this policy changes in a way that matters, ox will say so on this page and, for material changes, tell account holders ahead of time. The date at the top is the last edit.

12. Contact

[email protected]