Privacy Policy
Last updated: 18 July 2026
This policy explains what personal data Pyvolt collects, why, and your rights over it. Pyvolt is operated by Digital Outback Ltd (company number 13170273), a company registered in England and Wales ("Pyvolt", "we", "us"). We are the data controller for the personal data described here.
For any privacy question or to exercise your rights, contact us at [email protected].
1. What Pyvolt is (and what stays yours)
Pyvolt provisions and deploys applications to servers that run on your own cloud account (for example your own Hetzner, DigitalOcean, or other VPS). We connect over SSH to configure and deploy. We do not host your applications and we do not access the data your deployed applications process at runtime. Your servers, and the data on them, remain under your control and are governed by your agreement with your own cloud provider.
2. Data we collect
- Account data: your name, email address, and either a password (stored only as a salted hash) or, if you sign in with GitHub, your GitHub account identity.
- Source-control data (only if you connect GitHub): your GitHub username and email, the repositories you grant access to, and an installation token we use on your behalf to list repositories and push deploy keys. We do not read your source code beyond the metadata needed to deploy.
- Service configuration: the servers, applications, domains, IP addresses, repository URLs, and settings you enter, plus environment variables you choose to store. Environment variable values may contain secrets you provide; treat them as sensitive and only enter what you need.
- Operational data: deployment and provisioning logs, and status information reported by your servers.
- Technical data: your IP address, browser type, and request timestamps, captured in server logs.
- Support data: messages, feedback, and bug reports you send us.
We do not use third-party advertising or analytics trackers.
3. Cookies and local storage
We use a strictly necessary session cookie to keep you signed in and a CSRF cookie for security. Your light or dark theme choice is stored in your browser's local storage. We do not set tracking or advertising cookies.
4. Why we use your data and our legal bases
- To provide the service (create your account, authenticate you, provision servers, deploy your apps): performance of our contract with you.
- To send service emails (password resets, security and account notifications): performance of our contract, or our legitimate interest in operating the service.
- To keep the service secure and prevent abuse (logging, rate limiting, fraud prevention): our legitimate interests.
- To provide support and improve the product: our legitimate interests.
- To comply with law: compliance with a legal obligation.
Where we ever rely on consent (we currently do not send marketing email), you can withdraw it at any time.
5. Sub-processors
We share personal data with the following processors, only as needed to run the service. Each is bound by a data processing agreement.
- Hetzner Online GmbH (Germany) - hosting for the Pyvolt application and database.
- Cloudflare, Inc. (USA) - DNS, content delivery, and static asset serving for pyvolt.com.
- Resend (USA) - delivery of transactional email.
- Functional Software, Inc. (Sentry) (USA) - application error and performance monitoring.
- GitHub, Inc. (USA) - only if you connect a GitHub account, for repository access and deploy-key management.
Note: when you provision a server, you supply credentials for your own cloud provider. That provider is engaged by you, not by us, and processes your data under your agreement with them.
6. International transfers
Some sub-processors above are located in the United States. Where personal data is transferred outside the UK or EEA, we rely on appropriate safeguards such as the UK International Data Transfer Agreement or the EU Standard Contractual Clauses, as offered by each provider.
7. How long we keep it
We keep your account data for as long as your account is active, and for a reasonable period afterwards to meet legal, security, and accounting needs. Operational and technical logs are kept for a shorter period. When you delete your account we remove or anonymise your personal data, except where we must retain it by law.
8. Your rights
Under UK and EU data protection law you have the right to access, correct, delete, restrict, or object to our processing of your personal data, to data portability, and to withdraw consent where we rely on it. To exercise any of these, email [email protected]. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk, or your local supervisory authority.
9. Security
We protect data in transit with TLS, store passwords only as salted hashes, and restrict access to production systems. No system is perfectly secure, so we cannot guarantee absolute security, but we take reasonable technical and organisational measures to protect your data.
10. Children
Pyvolt is not intended for anyone under 16, and we do not knowingly collect data from children.
11. Changes to this policy
We may update this policy from time to time. We will change the date above and, for material changes, notify you by email or in the app.
12. Contact
Digital Outback Ltd, trading as Pyvolt. Email [email protected].
See also our Terms of Service.