LEGAL

Privacy Policy

Last updated September 14, 2026

1. What we collect

  • Account data: name, email address, password hash, optional two-factor secret, timezone and notification settings (email, webhook URL, Telegram bot token and chat id) you enter.
  • Server data sent by the agent: server name, hostname, operating system, architecture, agent version and the public IP address it connects from.
  • Job data: the commands, schedules, environment variables and options you configure, and for every run its timing, exit code and the output (stdout and stderr) the agent streams back.
  • Technical data: IP addresses and timestamps of API requests, used for rate limiting and security.

We do not use tracking cookies or third-party analytics. The only cookie is the session cookie that keeps you logged in.

2. Why we use it

To run the service: scheduling your jobs, showing their logs, sending the alerts you configured, securing your account and preventing abuse. We do not sell your data or use it for advertising.

3. Your job output may contain sensitive data

Everything a command prints is stored so you can read it later. Do not print secrets in your jobs, or restrict them, because output is retained as described below and is visible to anyone who can access your account.

4. Retention

  • Run history and logs are kept for 30 days, then deleted automatically.
  • Jobs, servers and settings are kept until you delete them.
  • Deleting a server deletes its jobs and run history; deleting your account deletes everything.

5. Sharing

Data is shared only with the services you configure yourself: your email provider receives alert emails, a webhook URL you enter receives alert payloads, and Telegram receives alert messages if you added a bot. Our hosting provider stores the database on our behalf under a data-processing agreement. We disclose data to authorities only when legally required.

6. Security

Connections are encrypted with TLS. Passwords are stored as bcrypt hashes; two-factor authentication is available for every account. Each server has its own token, and the agent only makes outbound connections. No system is perfectly secure; keep your tokens and trigger URLs private and rotate them if they leak.

7. Your rights

You can see and change your account data in Settings, export your jobs through the API, and delete servers, jobs and runs at any time. To delete your whole account or to exercise any other right you have under applicable data-protection law (access, correction, portability, objection), write to [email protected].

8. Changes

We may update this policy; the date at the top shows the current version. Material changes will be announced in the dashboard.

9. Contact

Privacy questions: [email protected].

© 2026 Cronxo