Serverwright processes your account identity, the servers you connect, the changes you make to those servers, billing status, and diagnostic events to provide and secure the service.
We use the data described above only to provide and secure Serverwright, and not for unrelated purposes.
Remote credentials and server data
The credentials you use to connect a server are encrypted and used only inside authorized operations scoped to your account. Your credentials in plain text are never placed in client-readable state, analytics, or application logs.
Storage and retention
Account and server information is stored for as long as your account is active. Removing your account blocks access immediately and starts a resumable deletion of its product data. An upload authorized just before removal can still place unlinked bytes in storage for up to one hour. An hourly cleanup removes those bytes, so they are scheduled for deletion within two hours of removal. A service interruption can delay scheduled cleanup.
When our identity provider confirms that it deleted your identity, we retain the closure record for 30 days to settle delayed provider events. If Serverwright closes an account while its external identity remains active, we retain a closure identifier so signing in cannot recreate the account. We may retain records longer when the law requires it.
Service providers
Serverwright relies on specialized providers for identity, hosting, application data, encrypted storage, key management, payments, and monitoring. Each provider receives only the data needed for its role.
Your choices
You control which servers are connected. You can disconnect a server, remove your account, and request deletion of your data at any time.
Contact
Privacy requests may be sent to privacy@serverwright.io. This policy will be updated before public launch with the operating entity and jurisdiction-specific disclosures.