The short version
We collect the little we need to log you in, bill you correctly, and keep the platform up. We do not sell it, we do not run ad tracking, and we do not use your code or your data to train models. The rest of this page is the specific version of those sentences, because a privacy policy that only says the short version is not telling you anything.
What we collect
To sign you in. Your email address, and a session cookie once you are in. The emailed login code is stored as a hash rather than as the code itself, and it is consumed the first time it is used.
To bill you. A record of what your machines used, sampled continuously: CPU-seconds, memory held, and bytes stored. This is per-machine, per-second arithmetic, not a record of what was running. Card details go to Stripe and never reach us; what we keep is a customer reference, and the invoices and balance history attached to it.
To run your machines. The metadata you give them: names, sizes, the templates you build from, snapshots, network and ingress configuration, and the API tokens and secrets you register.
To keep the service working. Request logs from the API and the website, holding IP addresses, user agents, timestamps, and a correlation id that lets us follow one request through the system. We use these to debug failures, find abuse, and answer your support questions.
If you link Discord. Your Discord user id, and whether that account is a member of our server. That pair is the whole point of the link: it is how the signup credit is limited to one per person. We do not read your messages and we could not if we wanted to.
If you write to us. The email, in our inbox, for as long as email lives in inboxes.
What is inside your machines
The contents of your machines - your files, your databases, your environment variables, your secrets - are yours, and we treat them as opaque. We do not index them, scan them for content, or read them to learn what you are building, and we do not train models on them.
Our operations staff can reach guest storage, because running a hosting platform means someone can. That access is used to keep the platform working, to respond to a report of abuse or a security incident, or where the law requires it, and not otherwise.
Website analytics
The website uses PostHog to count page views and see which parts of the site people actually use. It processes your IP address, which gives it an approximate location, and it is configured to build a per-person profile only for signed-in users. There is no advertising network involved and nothing here follows you to other sites.
Two honest details. The analytics requests go out through a path on our own domain rather than directly to PostHog, so a content blocker keyed to PostHog's domain will not catch them; a blocker that blocks by request path will. And the site does not currently act on a Do Not Track header, so please do not read one as an opt-out here.
Who else touches it
Five companies process some of this on our behalf:
- Stripe - payments, cards, invoices, and subscriptions
- Resend - the transactional email we send you (login codes, receipts, notices)
- Cloudflare - serving this website and its DNS, plus a bot-check script the site loads on every page
- PostHog - the website analytics described above
- Google Workspace - the mailboxes that receive email you send us
If you link Discord, Discord is in the path too, on their terms as well as ours. Everything else - your machines, your volumes, the metering, the logs - runs on hardware we operate ourselves, in data centers in the United States. If you are outside the US, your data is processed in the US.
What we do not do
- We do not sell personal data, and we have never had a reason to want to
- We do not share it with advertisers or data brokers
- We do not use your code, data, or machine contents to train models
- We do not hand data to law enforcement without valid legal process, and where we are allowed to tell you about a demand, we will
How long we keep it
Billing and usage records stick around, because they are the account's history and we may be required to keep them. Machine and snapshot data is deleted when you delete the machine or snapshot; copies can persist briefly in backups until those roll off. Operational logs age out on their own schedule, and rather than invent a number for this draft we will state the real one once legal review sets it.
Your choices
You can delete your own data yourself, at any time: machines, API tokens, secrets, and templates from the dashboard, and all of that plus snapshots from the CLI. You can unlink Discord; the credit already granted stays granted, and the link stops being checked. You can close your account, and we remove what is left of it.
For anything the product does not do for you - a copy of what we hold, a correction, deletion of the rest - email hari@ix.dev and a person will do it by hand. Depending on where you live you may have a formal right to some of this; we would rather just do it than argue about which law applies.
Security
Traffic to ix is encrypted in transit. Each machine is a real virtual machine, isolated from every other tenant, and access to production systems is limited to the people who operate them. We will not claim more than that here: we are early, we have not been audited, and there is no certification to point at yet. If you find a hole, email us and we will treat you well for it.
Children
ix is a tool for building software and is not directed at children. We do not knowingly collect personal data from anyone under 13, and we delete it if we learn we have.
Changes to this policy
The current version lives at this URL with the date it last changed at the top. If we start collecting something materially new, or add a processor that sees your data, we will update this page and email the address on your account.
Contact
Email hari@ix.dev with anything on this page, including the parts you think are wrong.