deloc

Privacy Policy

Last updated: May 15, 2026

What We Collect

When you use Deloc, we collect the following information:

  • Account information: email address, name, and username (provided during signup)
  • Uploaded files: the static files you deploy to the platform
  • Usage metrics: deploy counts, bandwidth usage, storage usage, and last login timestamps
  • OAuth data: if you sign in with Google or Microsoft, we receive your email, name, and profile picture from the provider
  • Payment information: if you subscribe to a paid plan, payment details are collected and processed by Stripe — we do not store card numbers
  • Activity logs: actions taken within the platform (deploys, settings changes, logins) and associated IP addresses, collected for security and abuse prevention purposes
  • Product analytics: aggregate, cookieless usage analytics — pages viewed within the Deloc dashboard and in-app events such as sign-ups, deploys, and plan upgrades. This is collected anonymously, is not linked to your account, and does not include your name or email. To count unique visitors without cookies, our analytics provider derives a temporary identifier from your IP address and browser user-agent on its servers; this identifier is never stored on your device, rotates every 24 hours, and is not used to build a profile of you.

What We Don't Do

  • We do not sell, rent, or share your personal data with third parties for advertising
  • We do not inject tracking pixels, analytics scripts, or advertising cookies into your hosted apps
  • We do not read or analyze the content of your uploaded files except for automated abuse detection (phishing, malware scanning)

Third-Party Services

We use the following third-party services to operate the platform:

  • Cloudflare: CDN, DNS, R2 object storage (file hosting), and Workers (edge compute). Your uploaded files are stored on Cloudflare R2.
  • Neon: PostgreSQL database hosting. Account metadata, app configuration, and usage data are stored here.
  • Stripe: Payment processing for paid subscriptions. Stripe's privacy policy governs payment data.
  • Google / Microsoft: OAuth authentication providers. We receive only the data you authorize during sign-in (email, name, profile picture).
  • Resend: Transactional email delivery (verification emails, password resets).
  • PostHog: Product analytics for the Deloc dashboard, used in cookieless mode — no analytics cookies and no persistent identifier are stored on your device. We do not send PostHog your name or email. To count unique visitors without cookies, PostHog derives a temporary, daily-rotating hash from your IP address and browser user-agent on its servers; it is not stored on your device, resets every 24 hours, and is not used for profiling or advertising. Processing occurs on PostHog's EU Cloud, hosted in the European Union, with PostHog acting as a data processor.

A complete list of subprocessors is available upon request by emailing [email protected].

Data Storage & Retention

  • Uploaded files are stored on Cloudflare R2 in the United States and processed globally via Cloudflare's edge network
  • Account metadata is stored on Neon PostgreSQL in the United States
  • Product analytics data is processed and stored by PostHog on its EU Cloud infrastructure in the European Union
  • Free-tier app files may be deleted 30 days after expiration
  • Paid-tier files are retained for the duration of your subscription
  • After account deletion, your data is permanently removed within 30 days

Cookies

We use cookies strictly for authentication and security purposes:

  • deloc_auth: HTTP-only session cookie for authenticating API requests
  • deloc_refresh: HTTP-only cookie for refreshing expired sessions
  • deloc_csrf: CSRF protection token

We do not use advertising or analytics cookies, or any third-party tracking cookies. Our product analytics is cookieless and stores nothing on your device, so no analytics cookie banner is required.

Data Deletion

You can request complete deletion of your account and all associated data by emailing [email protected]. Upon request, we will delete your account, uploaded files, and all associated metadata within 30 days. Some data may be retained in encrypted backups for up to 90 days before being purged.

Your Rights

If you are located in the European Economic Area (EEA), you have the right to access, correct, delete, restrict, or port your personal data under the GDPR. You may also object to certain processing. Our legal basis for processing your data is legitimate interest in operating the Service and fulfilling our contractual obligations to you.

If you are a California resident, you may request disclosure of the categories and specific pieces of personal data we have collected, and request deletion of your data under the CCPA.

To exercise any of these rights, contact [email protected]. We will respond within 30 days.

Children's Privacy

Deloc is not intended for use by anyone under the age of 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected data from a child under 13, we will delete it promptly. If you believe a child has provided us with personal data, contact [email protected].

Data Breach Notification

In the event of a data breach affecting your personal information, we will notify affected users and relevant authorities as required by applicable law, typically within 72 hours of becoming aware of the breach.

Changes to This Policy

We may update this privacy policy from time to time. If we make material changes, we will notify you by email or by posting a notice on the Service. The "Last updated" date at the top of this page indicates when the policy was last revised.

Contact

For privacy-related questions or concerns, contact us at [email protected].

← Back to signup