1. Who controls your data
plugged.host, Paris, France is the controller for personal data processed to provide the plugged.host websites, panel, hosting service, status page, and related support (the Service).
To ask a privacy question or exercise a right, join the plugged.host Discord and open a private support ticket. Never post personal data or account details in a public channel.
2. Scope
This Policy applies when you visit plugged.host or status.plugged.host, create or use a panel account, connect Discord, operate hosted workloads, or contact support. Third-party services have their own policies; in particular, Discord and Cloudflare process data under their policies when you use their services.
We do not currently use advertising or analytics, sell personal data, or process payments. The static landing and status sites do not set their own cookies.
3. Personal data we collect
Data you provide
- account information such as username, email address, securely hashed password, preferred language and timezone;
- security information such as passkey records, multifactor settings, API/SSH keys, and account recovery state;
- files, databases, backups, server names, configuration, logs, and other content or metadata you choose to host;
- support requests, incident reports, and other communications you send us.
Data received from Discord
If you use Discord OAuth, we receive the Discord account identifier, email address, username or display information necessary to link or create your plugged.host account. We do not receive your Discord password.
Data collected automatically
- IP address, timestamps, requested pages, response information, browser/device details sent in normal HTTP headers, session events, and security signals;
- panel activity such as authentication, account, API, server, file, backup, database, network, and administrative actions;
- essential session, CSRF, authentication, preference, and security cookies or browser storage;
- resource and health telemetry from hosting nodes and workloads, including CPU, memory, storage, availability, and diagnostic state;
- acceptance records showing the policy version, authentication method, and time you accepted the Terms and acknowledged this Policy.
4. Why we process data
- To perform our agreement: create and secure accounts, authenticate you, allocate resources, run workloads, provide panel functions, support requests, and communicate service information.
- For legitimate interests: prevent abuse and fraud, protect users and infrastructure, investigate incidents, troubleshoot, measure capacity, maintain reliable operations, and establish or defend legal claims. We balance these interests against your rights.
- To comply with law: respond to valid legal requests, preserve required records, enforce rights, and meet security or regulatory duties.
- With consent where required: for optional processing that is not necessary to provide the Service. You may withdraw such consent without affecting earlier lawful processing.
Acknowledging this Policy during sign-in does not turn all processing into consent; we use the appropriate legal basis for each purpose.
6. International transfers
Some providers, including Cloudflare and Discord, may process data outside France or the European Economic Area. Where required, transfers rely on an adequacy decision, approved contractual safeguards, or another lawful transfer mechanism. Provider-specific details are available in the Cloudflare Privacy Policy, Turnstile Privacy Addendum, and Discord Privacy Policy.
7. How long we keep data
- nginx web access and error logs rotate daily and are normally retained for approximately 14 days;
- panel activity logs are normally retained for 90 days;
- webhook delivery records are normally retained for 30 days;
- public infrastructure snapshots are retained for 90 days; incidents may remain as an operational record;
- account information, hosted content, configuration, and security credentials remain while the account or workload is active and are removed when deleted, subject to technical backup cycles and legal needs;
- legal acceptance records remain with the account and are deleted when the account is deleted;
- support communications on Discord follow our support needs and Discord’s own retention controls.
We may retain limited information longer when reasonably necessary for security, dispute resolution, enforcement, or a legal obligation. Data may be anonymized or aggregated so it can no longer identify you.
9. Security
We use measures intended to protect data, including TLS, access controls, password hashing, encrypted secrets, authentication controls, restricted administrative access, logging, rate limits, security monitoring, and infrastructure isolation. No online service is completely secure. Protect your credentials, enable multifactor authentication, maintain independent backups, and report suspected compromise promptly.
10. Your data protection rights
Depending on applicable law, you may ask us to provide access to your personal data; correct inaccurate data; erase data; restrict or object to processing; provide portable data; or explain relevant processing. Where processing relies on consent, you may withdraw it. You may also object to direct marketing, although we do not currently conduct it.
Open a private Discord support ticket to make a request. We may ask for information necessary to verify your identity and protect the account. We will respond within the period required by applicable law.
You may complain to a data protection authority, particularly the authority where you live or work. In France, the supervisory authority is the Commission Nationale de l’Informatique et des Libertés (CNIL).
11. Children and age requirements
The Service is not for anyone under 13 or the higher minimum age required where they live, including 15 in France. Users below the age of legal majority also require a parent or guardian to agree to the Terms. We do not knowingly collect data from an ineligible child. A parent or guardian who believes this occurred should contact us privately so we can investigate and delete it where appropriate.
12. Changes to this Policy
We may update this Policy to reflect changes in the Service, providers, law, or our practices. We will publish the updated version and effective date here. The current Policy is linked during each registration and sign-in.
13. Contact
Data controller: plugged.host, Paris, France.
Join the plugged.host Discord and open a private support ticket for privacy questions or rights requests. Do not use a public Discord channel for personal information.