Privacy policy
Draft, last updated 2026-10-04
ox Cloud (getox.in) deploys your repositories onto servers that you own. This page says what ox keeps about you, what it does not keep, who else sees it, and how to use your rights. Questions about any of it: [email protected].
1. Who is responsible
- For your account data, ox is the controller. That is what ox collects to run your account: who you are (from GitHub), your servers, your projects, your settings, and the audit log.
- For your applications' data, ox is at most a processor, and mostly not involved at all. Your app, its database, its uploads, its variables, its backups and its logs live on your own server. ox runs an agent there that carries out the actions you ask for. ox does not copy your application data to the plane, and does not read it for its own purposes. The one thing that passes through is what you ask to see: when you use Explore on a service, the rows, keys, or results you open are read on your server, pass through the plane to your browser, and are not stored. You are the controller of the personal data your own users give your apps.
- ox Cloud is operated by Saurav Sharma in India. The contact for all privacy matters is [email protected].
2. What ox stores about you
| Data | Why | Where and how long |
|---|---|---|
| Sign-in identity from GitHub: numeric GitHub user id, login, display name, avatar address, email address, and when the account was created | Your account is your GitHub user id. The login, name and avatar are shown in the console. The email is shown, and used to reach you. | The plane's database, until your account is deleted (section 7). |
| GitHub tokens from sign-in (a user token and a refresh token) | To read the repositories you choose, read-only, on your behalf. | The plane's database, encrypted (AES-256-GCM) under a key kept in a separate root-only file. |
| Sessions: a random token, and when it was made | To keep you signed in. | The plane's database. A session ends after 30 days or when you log out. |
| Personal tokens for the CLI and scripts | To let the CLI act as you. | Only a one-way hash, a name and when it was last used. A token lasts 90 days. Revoke it in Settings. |
Sign-in codes for ox login, with the address that asked and when | To approve the CLI on your screen. | The plane's database, short-lived. |
| Your servers: the name, hostname, IP address, memory, disk and Ubuntu version the agent reports, and a hash of the agent's credential | To show and reach your servers. | The plane's database, until you forget the server. |
| Your projects: name, repository address, GitHub App installation, and a record of each run (what was asked, the commit, the result, the times) | To deploy and to show your history. | The plane's database, until the project is deleted. |
| Settings you save: your S3 backup target (endpoint, bucket, region, access key, and the secret key) and a Hugging Face token | To copy your backups to your bucket and to download your models. | The plane's database. The secret key and the token are encrypted (AES-256-GCM). |
| Audit log: your account, who acted (you, or the token's name), what was done (deploy, rollback, variables save, restore, delete, token create or revoke, server add or forget, showing values, a change made from Explore), what it was done to, the time, and the IP address the request came from | Security, and so you can see what happened on your account. | The plane's database. You see it in Settings. TODO (owner): the code has no expiry for audit rows, so today they stay until the account is deleted. Decide a period. |
| Repository push notices from GitHub: a delivery id | To ignore a notice sent twice. | 7 days. |
| Operational logs on the plane: requests, errors and job output | To run and secure the service. | TODO (owner): the web server's and the plane's own log contents and retention are set by the host, not by the code, and are not confirmed here. |
What ox does not keep
- Variables and secrets for your apps stay on your server. The plane carries them to the agent and keeps no copy.
- Your app's data, databases, uploads and its users' data are on your server only.
- Run logs are written on your server. The plane shows them live and, while a run is in progress, holds the output in memory only. TODO (owner): confirm no run output is written to the plane's disk.
- No password. ox has no passwords: sign-in is through GitHub.
- ox does not sell your data, does not share it for advertising, and does not profile you.
3. Cookies and tracking
ox sets only the cookies it needs to work, so no consent banner is shown:
ox_plane_session: keeps you signed in. Not readable by scripts. 30 days.ox_plane_csrf: protects forms from being submitted by another site. Ends with your browser session.ox_oauth: ties a GitHub sign-in to the browser that began it. Lasts 10 minutes.
ox has no analytics, no advertising trackers, and no third-party scripts. The landing, docs and sign-in pages load their fonts and scripts from ox itself. The signed-in console loads two typefaces (Inter and JetBrains Mono) from Google Fonts, so Google receives your IP address and browser details when you open the console. TODO (owner): self-host these fonts, as the landing already does, to remove the last third-party request. ox does not store a theme preference.
4. Who else handles the data (sub-processors)
- GitHub: your identity provider, and where your repositories are. ox uses a GitHub App with read access to the repositories you pick. GitHub's own policy applies to what it holds.
- Cloudflare: getox.in sits behind Cloudflare as proxy and CDN, so Cloudflare sees traffic to the site, including your IP address.
- DigitalOcean: hosts the plane's server. TODO (owner): confirm the provider and its region for the production plane.
- The storage for plane backups: the plane's database is copied every hour to an S3-compatible bucket owned by ox; the newest 7 days of copies are kept. TODO (owner): name the bucket's provider and region.
- Alerts: when a deploy or backup fails, a process keeps crashing, a server stops answering, or a project stops responding, ox emails the address from your GitHub account through an email provider, and, if you set one in Settings, posts the alert to your webhook address. The webhook address and its signing secret are stored encrypted. TODO (owner): name the email provider here before turning email alerts on. Webhook endpoints you add receive events as signed JSON with names and links only: no variable values, tokens, passwords, or log lines. The address, signing secrets, and any header value are stored encrypted, and the delivery log (time, event, status, latency, and at most 1 KB of a failed answer) is kept 7 days.
- Your own services: your servers' hosting company, and your S3 bucket if you set one, are chosen by you and are your processors, not ox's.
- ox does not rent or sell data to anyone else.
5. Where data goes, and international transfers
Customers are worldwide, so account data is processed on the plane, wherever its host is (see the sub-processors above). Where the law requires a transfer mechanism for data sent out of the UK, EU or EEA, ox relies on the standard contractual clauses (and the UK addendum) with its providers where they offer them. TODO (owner): confirm the plane's region and the transfer terms with each provider.
6. Legal bases (GDPR and UK GDPR)
- Running your account and the service you asked for (contract): the identity, servers, projects, settings and tokens in section 2.
- Security and preventing abuse (legitimate interests): the audit log, IP addresses, rate limits and logs.
- Keeping the service running (legitimate interests): backups of the plane's database.
- Meeting legal duties, where they apply to ox.
ox does not use automated decisions that have legal effects on you.
7. Your rights, and how to use them
Two of them need no email. Get a copy: in the console, Settings, Your data, Download my data, or ox account export. You get one JSON file with your profile, servers, projects, runs, audit log, token names and settings; it holds no secret, and your apps' variables and data are on your own servers, so they are not in it. Three downloads an hour. Delete your account: Settings, Delete account, or ox account delete --confirm <your GitHub login> (section 8). For anything else, such as a correction or an objection, email [email protected] from the address on your account, or say which GitHub login is yours. ox answers within 30 days.
- Everyone: ask what ox holds about you, get a copy, have it corrected, or have it deleted.
- In the EU, EEA and UK (GDPR, UK GDPR): also object to or restrict processing, take your data in a portable form, withdraw consent where it is the basis, and complain to your data protection authority (in the UK, the ICO).
- In California (CCPA/CPRA) and other US states: know, access, delete and correct your personal information, and not be treated worse for using these rights. ox does not sell or share personal information for cross-context advertising, so there is nothing to opt out of, and it does not use sensitive personal information to infer traits about you.
- Elsewhere: ox applies the same rights to every customer, whatever local law adds.
For data in your applications, which is on your server, make the request to the app's owner (your customer, if you are their user). ox cannot see it.
8. What happens when you delete things
- Delete a project: the plane removes the project and its run records at once. On your server, the app stops and its files, database and users are removed, and ox keeps a copy of its data and variables in a trash folder on your server for 7 days, so you can restore it, and then removes it. Backups you copied to your own S3 bucket stay there until you delete them. Audit rows about the project stay.
- Forget a server: allowed once it has no projects. The plane deletes the server record and its credential. The server keeps running until you run
ox uninstallon it. - Revoke a token: it stops working at once.
- Delete your account: in Settings, Delete account (or
ox account delete --confirm <your GitHub login>). You type your GitHub login to confirm. It is refused while you still have servers: forget each one first (Servers page, orox servers forget). Forgetting a server uninstalls nothing on it, so your apps keep running on your own servers, unmanaged, until you runsudo ox uninstallthere. When you delete, at once ox removes your sessions and personal tokens (they stop working), your projects and their run records, your settings (S3 target, Hugging Face token, webhook, notification choices), your alert records, your GitHub connections, and your account record with the GitHub tokens it held. ox then asks GitHub to revoke its authorization on your GitHub account; if GitHub does not answer, the page says so and you can remove ox at github.com/settings/applications. If ox has a mail server, it sends a confirmation to your address. Kept: the audit rows stay for security, each with only its action and time: your login, the address and what was acted on are removed. Removing the ox GitHub App from your repositories is done on GitHub, and ends ox's access to them. - Backups of the plane: deleted data can remain in the plane's hourly database copies for up to 7 days (the newest 168 are kept in the bucket, and 24 on the plane's host) and is then gone. Those copies are not edited, so a deleted account is gone from them only as they age out.
9. Security
Secrets on the plane are encrypted, tokens are stored as hashes, each account sees only its own data, the agent on your server connects out to the plane (no open inbound port for ox), and every action is audited. No system is perfectly secure. If a breach affects your personal data, ox will tell you and the authorities as the law requires.
10. Children
ox is for developers and is not meant for anyone under 16. ox does not knowingly collect data from children.
11. Changes
If this policy changes in a way that matters, ox will say so on this page and, for material changes, tell account holders ahead of time. The date at the top is the last edit.