HostingFAQStatus ↗Log inSign up

Privacy Policy

Last updated: 14 September 2026

I keep things simple. This policy explains what minimal information I need to run the service and keep the server stable. The operating principle is straightforward: if a piece of data isn't absolutely required to host your site, I don't collect it or hold onto it in the first place.

1. Data Collected

To provision and manage your account, I need a strictly limited set of information. Nothing more is asked for, and nothing extra is stored:

2. What Is Not Collected

There are no Google Analytics pixels, no Facebook Pixel, no Plausible, no Fathom, no Hotjar. no third-party tracking scripts of any kind on the website, in the control panel, or on any hosted domain. I don't build behavioral profiles, I don't sell data, and I never inject advertising. The data I hold is exactly what's required to keep the server online. absolutely nothing beyond that.

One external element exists and it is functional, not tracking: forms that need bot protection (sign-in, registration, ordering) use Cloudflare Turnstile. When such a form loads, Cloudflare receives technical data (such as your IP address and browser characteristics) to tell humans apart from bots — see section 8 (Third Parties) and section 3 (Cookies).

3. Cookies & Local Storage

The panel uses a strictly necessary session cookie to keep you signed in — nothing more. Beyond that: your light/dark theme preference is stored in your browser's local storage, and dismissing a dashboard announcement sets a small cookie (30 days) so it stays dismissed. When a Turnstile-protected form loads, Cloudflare may set its own functional cookies for bot detection. There are no advertising, analytics or cross-site tracking cookies anywhere — not on the website, not in the panel.

4. Data Storage & Infrastructure

Your account data and hosted files live on a server I own and operate directly. While I control the server instance and all of its contents, the physical hardware, network, and power are provided by an upstream datacenter. Because I don't control their hardware or business decisions, the service could theoretically be affected by catastrophic upstream failure or changes to their terms. I do not maintain off-site backups of your data or the account database. You are solely responsible for keeping your own local backups at all times.

5. How Your Data Is Used

I use your email strictly for account-related communication. nothing more. Server logs help me diagnose technical issues, mitigate abuse, and ensure the shared environment stays stable for everyone. I don't send marketing emails, and you won't hear from me unless there's a technical or account-specific reason to reach out.

6. Provisioning & Account Monitoring

Account creation is automated; hosting packages are activated only after staff review of the order. To prevent abuse and keep the shared server clean and usable for everyone, I actively monitor all freshly created accounts. This includes automated and manual checks on initial file uploads, DNS configurations, and resource usage during the early stages of an account's life. During order review, staff also see your account context — other packages, recent support tickets and your recent account activity — solely to assess the order. This monitoring is strictly for security, abuse prevention, and ensuring compliance with the Acceptable Use Policy (AUP).

7. Data Retention

I keep your account information for as long as your account remains active. Across all services, content is handled differently from logs:

Web hosting: When an account is terminated or removed, all hosted content (files, databases, mailboxes, DNS zones) is immediately removed. There are no backups retained after termination.

Panel (the panel): When an account is closed, account information is removed. The same exception applies to logs as below.

Logs: Server access logs, error logs, and authentication logs are not immediately purged when an account is closed. They persist on the server and expire over a longer period. Logs are not kept forever, but they take longer to disappear naturally.

8. Third Parties

The upstream infrastructure provider operates the physical hardware, network and power; they never interact with your account dashboard or your files. Two services receive the minimum technical data their function requires: Cloudflare Turnstile protects sign-in, registration and order forms against bots and receives technical data (IP, browser characteristics) when such a form is used, under Cloudflare's own privacy policy; and Let's Encrypt issues the SSL certificates for hosted domains, which involves submitting your domain names to their certificate servers — a public, logged process required by the certificate authority model that involves no personal data. I never share your data with marketing firms, advertisers, or data brokers. not under any circumstances.

9. Your Rights

You have the right to access the personal data held about you, to have inaccurate data corrected, and to receive a copy of it in a common, machine-readable format. You may close your account and request erasure at any time. To exercise any of these rights, open a support ticket or contact the administrator and the request will be processed within a reasonable timeframe.

10. Right to Be Forgotten & Banned-Account Retention

You may request full erasure of your account at any time ("right to be forgotten", e.g. Art. 17 GDPR). On erasure, your account, sites, files, databases, mailboxes, DNS zones, tickets and panel records are permanently deleted. One exception applies: for accounts that were banned (terminated for violations of the Acceptable Use Policy), I retain the bare minimum needed to keep the service safe and to comply with legal obligations — specifically the account's email address and the last known IP address. This prevents circumvention of bans (re-registration) and allows me to respond to abuse reports or legal process. No hosted content is retained for banned accounts. To request erasure, open a support ticket or contact the administrator; banned-account holders can request erasure via email.

11. Audit Logging & Security Records

To keep the shared platform secure, the panel maintains an audit log of security-relevant actions. This includes sign-in attempts (successful and failed), two-factor authentication changes, hosting changes (files, databases, mail, DNS, domains), order and account administration, and support activity. Each record contains the time, the account, the action, the affected service, the source IP address, the requested URL, and the device type, browser and operating system parsed from your user-agent. Audit records are visible only to staff with an explicit audit permission; the records of your own account are disclosed to you on request.

Audit records serve security, abuse prevention and dispute resolution, and are visible to staff with the audit permission only. They are kept for up to 12 months and then automatically deleted. When an account is erased under the right to be forgotten, its audit records are pseudonymized — the link to the account is removed while the action and IP address may be retained for the remainder of the retention period for abuse prevention, based on our legitimate interest in keeping the service safe. For banned accounts the abuse-retention clause in section 9 applies accordingly.

12. Changes to This Policy

This policy may be updated at any time without advance warning. It is your responsibility to check this page periodically for changes. I will try my best to notify you of major updates through the dashboard, but no guarantee of advance notice is made. Continuing to use the service after changes take effect means you accept the updated policy.