dockxo beta
FeaturesPricingBlogChangelogGet started Sign in
Legal

Privacy Policy

What dockxo collects, why, where it is stored and how to get it removed.

updated Sep 26, 2026·beta

This policy explains what personal data dockxo (“we”) collects when you use the website at dockxo.com and the panel at panel.dockxo.com (the “Service”), why, and what your rights are. We are the data controller for the account data described below. Your applications and the data inside your containers and buckets are yours; we process them only on your instruction, as your processor, and only as described here.

What we collect

Account data. Your name, email address, a hash of your password, your two-factor secret (encrypted) and recovery codes (hashed), the time zone and appearance settings you choose.

Configuration data. Projects, services, domains, mounts, backup plans, monitors and the settings you enter. Environment variables, GitHub tokens, registry passwords, Cloudflare tokens, storage credentials and Telegram bot tokens are encrypted at rest with the panel’s secret key; we do not read them except to send them to your server or to the integration you connected.

Server data. For each server you connect: its name, IP address, the metrics the agent reports (CPU, memory, disk, network), the list of containers and their status, deploy and job logs, and, when you open them, streamed container logs and terminal sessions. Terminal sessions are relayed, not recorded.

Monitoring data. For each monitor: the URL, check results, response times and incidents. For each notification channel: the Telegram chat id or the email address you add. An email address other than your own receives a single confirmation mail and nothing else until its owner confirms.

Technical data. Standard web-server logs (IP address, user agent, requested URL, timestamp) kept for up to 30 days for security and debugging. We do not use third-party analytics or advertising trackers on the website or in the panel.

Email. Messages you send to us at hello@, security@ or [email protected]. We send transactional email to your account address: confirmation of the address, password reset links, security notices (new sign-in, password or email change, two-factor and API token changes) and the alerts you configure. These are sent through Cloudflare Email Service as our processor.

What we do not collect

We do not store the contents of your volumes or databases. Backups go from your server straight to your bucket; the panel sees the metadata of a run (what, when, sizes), not the bytes. We never see your sealed-backup passphrase.

Why we process it

  • to provide the Service you asked for (contract);
  • to secure the Service, prevent abuse and investigate incidents (legitimate interest);
  • to send you notices about the Service — security, material changes, the end of the beta (legitimate interest / legal obligation);
  • to answer your messages (legitimate interest).

We do not sell personal data and we do not send marketing email unless you opt in.

Where it is stored and who sees it

Account and configuration data is stored in a database operated by us in the European Union. Our hosting and infrastructure providers process data on our behalf under data-processing agreements. When you connect an integration (GitHub, Cloudflare, Telegram, an S3-compatible storage provider), the data needed for that integration is sent to that provider under its own privacy policy. We disclose data to authorities only when legally required.

How long we keep it

Account and configuration data for as long as your account exists, and up to 30 days after deletion in backups. Server metrics and monitor history are aggregated and pruned over time (detailed metrics after 7 days, monitor checks after 90 days). Web-server logs for up to 30 days.

Your rights

Depending on where you live you may have the right to access, correct, export or delete your personal data, to restrict or object to processing, and to complain to a supervisory authority. You can export and delete most data yourself in the panel; for anything else, write to [email protected] and we will answer within 30 days. Residents of the Republic of Türkiye have the rights set out in Law No. 6698 (KVKK); residents of the EU/EEA and the UK have the rights set out in the GDPR / UK GDPR.

Cookies

The panel sets a single session cookie needed to keep you signed in. The website sets no cookies.

Children

The Service is not directed at children under 18 and we do not knowingly collect their data.

Changes

We will post changes here and update the date at the top. Material changes are announced by email or in the panel.

Contact

[email protected]