NAME
privacy — personal
data and what is done with it
DESCRIPTION
The controller of your personal data, under the Brazilian LGPD (Lei 13.709/2018), is Murilo Ijanc, an individual in Brazil. He is also the person in charge of data protection; write to contact@chroot.dev.
DATA
- account
- User name and ssh public keys.
- If you give one: to ask for an invitation, to sign up, or for notices.
- GitHub or sourcehut
- If you sign up with them: your user name there and its public keys. Nothing else is read from those accounts.
- connections
- IP address, port, date and time and user of each ssh, HTTPS and API connection.
- VMs
- Names, sizes, state, traffic and sharing settings.
- integrations
- Credentials you hand to integrations(1), kept on the host.
- payments
- Handled by Stripe. chroot.dev receives name, email, country, card brand and the last four digits; never the card number.
- browser
- browser(1) sets one session cookie. The site has no tracking cookies and no ads.
- site visits
- Counted with Umami, run by chroot.dev on its own servers: page, referrer, browser, system, device type and country. No cookies; the IP address gives the country and is not stored.
The contents of your VMs are yours. They are not read, except to investigate abuse or when required by law.
USE
- running the service
- Account, keys, VMs and integrations: to perform the contract (LGPD art. 7, V).
- connection records
- To investigate abuse and answer court orders: legitimate interest (art. 7, IX) and the Marco Civil da Internet (Lei 12.965/2014, art. 15).
- payment records
- Tax law: legal obligation (art. 7, II).
Data is not sold, not used for ads and not used for profiling.
PROCESSORS
- Stripe
- Payments.
- Cloudflare
- DNS, incoming email and the status page.
- Akamai
- Edge server in Sao Paulo; all traffic passes through it.
- rsync.net
- Off-site backups of VM disks and the account database, in the United States, with a copy in a second site. Not in use yet: during the beta there are no backups.
- GitHub, sourcehut
- Public key lookup, only if you sign up with them.
VMs, the account database and outgoing email live on servers in Brazil run by chroot.dev. Stripe, Cloudflare and rsync.net process data outside Brazil, under LGPD art. 33.
RETENTION
- account, keys, email
- While the account exists; deleted 30 days after it closes.
- VMs
- Deleted with rm(1); backup copies expire within 30 days.
- connection records
- 6 months.
- payment records
- 5 years.
- abuse cases
- While the case or a legal claim is open, at most 5 years.
RIGHTS
Under LGPD art. 18 you may ask to confirm that your data is processed, to access, correct, export or delete it, to know who it is shared with, and to withdraw consent. Write to contact@chroot.dev; requests are answered within 15 days. You may also complain to the ANPD: https://www.gov.br/anpd.
CHANGES
Changes are announced on the site and by email 30 days before they apply; the date above is the date of the current version.
SEE ALSO
browser(1), integrations(1), rm(1), account(7), costs(7), terms(7)