Privacy Policy
Last updated
What Equific holds about you and your servers, how the credentials are protected, what leaves the platform, and what happens when you delete an account.
Draft — not yet reviewed by a lawyer
Every item written as [[ LIKE THIS ]] is a fact only the operator can supply. This document is not in force until they are filled in and the whole thing has had legal review.
Who we are
Equific is operated by [[ LEGAL ENTITY NAME ]], [[ REGISTERED ADDRESS ]]. We are the data controller for the information described here.
The service runs on infrastructure located in [[ HOSTING REGION ]].
What we hold
About you
- Your name and email address.
- A hashed password. We never store it in a readable form and cannot recover it.
- Two-factor secrets, recovery codes and registered passkeys, if you enable them.
- Session records, so you can be signed in on more than one device.
About your servers
This is the part worth reading carefully. To do its job, Equific holds:
- Hostnames, IP addresses and SSH ports.
- SSH credentials — the private key and, where you supply one, the root or administrative password.
- Database passwords, including the ones it generates for your sites.
- The contents of your sites' environment files, which typically contain API keys for your own third-party services.
- TLS certificate private keys.
- Object storage credentials for the bucket your backups go to.
- Webhook URLs for any alert destination you configure.
What your servers report back
- CPU, memory, disk and load samples.
- Uptime check results and response timings for the URLs you monitor.
- Certificate expiry dates and fingerprints.
- Deployment and provisioning output, including the raw output of tools like apt, certbot and mysql.
- Security events your servers report — bans, SSH logins, pending reboots.
- An activity log of what was done in the panel, by whom, and from which address. It records actions, never secrets.
Your server credentials
Every secret listed above is encrypted at rest with a key belonging to your account alone, rather than one shared across all customers. That key is itself encrypted with our application key before it is stored.
The practical effect is blast radius: your secrets can be rotated or destroyed independently of anyone else's, and a leak of one customer's data key does not expose another's.
What this does not protect against
We can decrypt your credentials. Anyone holding both our database and our application key can unwrap them — that includes us, and it would include an attacker who obtained both. Per-account keys limit how far one compromise spreads and make rotation possible. They are not a claim that your secrets are unreadable to us, and any vendor telling you otherwise about a system that has to log into your servers is describing something it cannot do.
If that is unacceptable for a particular server, the honest answer is not to connect it.
What leaves the platform
Only where you have configured it to:
- Alerts you set up are delivered to the email address, Slack, Discord or Telegram destination you choose. The alert contains the server or site name and what happened.
- Backups are written to object storage you own and control, using credentials you provide. We do not keep a copy.
- If you connect GitHub or GitLab, we hold the access token that grant issues and use it to read your repositories and register deploy keys.
We do not sell data, share it with advertisers, or use it to train anything. There are no analytics or tracking scripts on this site — see the cookie notice.
Sub-processors we rely on to run the service: [[ SUB-PROCESSOR LIST ]].
How long we keep it
- Uptime check results, heartbeat check-ins and server metrics: 30 days, then deleted automatically.
- Package update history: 365 days.
- Incidents: kept, because the record of what went wrong is usually needed long after it is fixed.
- Activity log: kept for the life of the account.
- Account and server records: until you delete them.
Deleting your account
Deleting your account removes your servers, sites, monitors, recipes and alert destinations from Equific, along with the key that encrypts your secrets. Those secrets become permanently unrecoverable — by you and by us.
Your actual servers are not touched. They keep running exactly as they are. Equific stops managing them and no longer holds the credentials to reach them, so make sure you have your own copy of anything you still need before you delete.
Activity log entries survive with the person removed from them, so the record of what happened to a server remains intact.
Your rights
Under [[ APPLICABLE DATA PROTECTION LAW ]] you may request a copy of your data, ask for it to be corrected or erased, or object to how it is handled. We respond within [[ RESPONSE WINDOW ]].
You can also complain to [[ SUPERVISORY AUTHORITY ]].
Contact
Privacy questions go to [[ PRIVACY CONTACT EMAIL ]].
To report a vulnerability, see the security page instead.