Privacy Policy

This policy explains what personal data Superjolt collects, why, how long we keep it, and the rights you have over it. It applies to your use of the Superjolt platform, API, dashboard, MCP interface, and websites.

Who controls your data

The data controller is Superjolt Limited, a company registered in England and Wales (company number 17288241), registered office 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ. For data questions, contact [email protected].

For the personal data inside the VMs and content you run on Superjolt, you are the controller and we act as your processor — see the Data Processing Agreement. This policy covers the account-level data we control directly.

What we collect

  • Account email. Used for identity, billing receipts, and security notifications. Your email is your account identity.
  • Sign-in identifiers. OAuth subject identifiers from Google, Microsoft, or GitHub when you sign in via those providers.
  • Sessions and sign-in events. Including IP address and user-agent, used to keep you signed in and to detect suspicious access.
  • Usage and metering metadata. Which VMs and resources you create, when they run, and how much CPU/RAM/storage they use — so we can bill you accurately and operate the platform.
  • Billing data. Top-ups, balance, and the Stripe customer reference. Card details are handled by Stripe, not stored by us.
  • Server logs. Request path, status code, and IP, retained for security and debugging.
  • Support correspondence. Messages you send us and our replies.

What we don't do

  • We don't read the contents of your VMs.
  • We don't sell your personal data.
  • We don't add third-party analytics scripts that profile you across sites.

Why we use it (legal bases)

Under UK and EU GDPR we rely on: performance of a contract (to provide the Service and bill you); legitimate interests (to secure and operate the platform, prevent abuse and fraud, and improve the Service); legal obligation (to keep billing and tax records); and consent (for analytics cookies on the marketing site, which you can withdraw at any time).

Who we share it with

We use a small set of vetted service providers to run the Service, covering categories such as payment processing, email delivery, infrastructure and hosting, content delivery, and error monitoring. We share personal data with them only as needed to provide the Service, and they're bound by data-protection terms. A list of our current providers is available to customers on request to [email protected]. We may also disclose data where required by law.

International transfers

Some of these providers are located outside the UK/EEA (for example in the United States). Where personal data is transferred internationally, we rely on appropriate safeguards such as the UK International Data Transfer Agreement / EU Standard Contractual Clauses or an adequacy decision.

How long we keep it

  • Account, billing, and audit records are kept for as long as your account is active and as required for legal and accounting purposes.
  • Server logs and sign-in events are retained for a limited period for security and debugging.
  • Platform database backups (our control-plane Postgres) are retained on a tiered schedule — roughly hourly for 48 hours, daily for 7 days, weekly for 4 weeks, and monthly for 12 months — then deleted.
  • Your VM and volume backups follow their own lifecycle: a daily scheduled snapshot, with the most recent retained on a rolling basis — 5 by default, though the exact number depends on your account entitlements — plus any on-demand snapshots you create. They live and die with the source VM/volume.
  • Deleted VMs stay recoverable for 24 hours (after the first hour) before permanent deletion.
  • VM performance metrics are kept on a rolling 24-hour window.
  • Email stored on your behalf is retained until you delete it or your account is deleted.

How we protect it

Sensitive fields — authentication tokens, SSH credentials, and per-inbox email passwords — are encrypted at rest with AES-256-GCM. Each tenant's VMs and network are isolated from other tenants. Access to production systems is restricted and audited. See our Security page for the technical detail.

Analytics and error monitoring on superjolt.com

We use Google Analytics 4 on the public marketing site (this domain) to count visits and understand which pages people find useful, and we don't combine analytics data with your account. By default it runs cookieless — setting no cookies and measuring only in aggregate, which we rely on as a legitimate interest. If you click "Allow" on the consent banner we additionally enable analytics cookies for more accurate measurement; declining keeps it cookieless. GA4 does not store IP addresses. See our Cookie Policy for detail. Dashboard and admin surfaces never load third-party analytics.

We also run lightweight error monitoring on this site: when a page hits an uncaught browser error, we record the error message, stack trace, page address, and your IP so we can fix it. This is error diagnostics, not analytics — it sets no cookies (only a temporary in-browser session identifier that is cleared when you close the tab, used to group related errors), doesn't profile you, and isn't combined with your account. Because keeping the site working depends on it, it runs under our legitimate interest rather than the analytics consent banner. The data goes to the error-monitoring provider noted above and is retained for a limited period.

Your rights

Subject to applicable law, you can ask us to: access the personal data we hold about you; correct it; delete it; restrict or object to certain processing; and receive a portable copy. You can delete your account yourself from the dashboard — this destroys your VMs and removes your tenant data — or ask us to do it. Audit records may be retained where we have a legal basis to keep them. To exercise any right, email [email protected]. You also have the right to complain to your data-protection authority (in the UK, the ICO).

US privacy (CCPA/CPRA)

If you are a California resident: we collect the categories of personal information described above (identifiers, commercial/billing information, internet activity, and geolocation inferred from IP). We do not sell or share your personal information as those terms are defined under California law, and we don't process it for cross-context behavioural advertising. You have the right to know what we collect, to request deletion, and not to be discriminated against for exercising these rights. Submit requests to [email protected].

Children

The Service is not directed at children and is not intended for anyone under the age at which they can form a binding contract. We don't knowingly collect data from children.

Changes

We may update this policy from time to time. We'll change the date at the top and, for material changes, notify you where appropriate.

Contact

Data questions and requests: [email protected].