PicoCloud
Sign in

Privacy policy

Last updated 4 August 2026

This explains what we collect, why, and what you can do about it. It is written to be read, not to be survived.

The short version. We collect the least we can: your email address, what you deploy, and enough operational data to run and bill the service. We do not sell anything to anybody, we do not track you across the web, and there are no advertising or analytics trackers on this site.

DeepDas is the data controller — registered in the Netherlands, Chamber of Commerce (KvK) 93932995, at Spanjaardsgoes 114, 3901 HC Veenendaal. For anything in this document, write to legal@picocloud.io.

What we collect

Your account. Your email address. Optionally your name and profile picture, if you connect a GitHub account. There is no password, because we do not use one.

What you deploy. Your source code, the container images we build from it, and your app's configuration. Also your secrets — encrypted, and covered separately below.

Running your apps. Logs your app produces, and counts of requests, bytes and cold starts. Those counts are aggregated per app: we do not record the IP address, page or identity of the people who visit your app.

Security records. When you sign in or change something, we record the action, the time, and the IP address and browser it came from. This is what makes a compromised account investigable, so it is kept even after other data goes.

Visitors you invite. If you share a private app with someone by email, we store that email address so we can let them in, and when they last used it. That person is not our customer; we use it for nothing else.

Support. Whatever you write in a ticket, and our replies.

Payments. If you pay us, Stripe handles the card. We never see or store your card details — we keep an identifier, your plan, and your invoices.

Why we are allowed to

  • To provide the service you asked for — this is the contract between us,

and covers your account, your apps and your billing.

  • Our legitimate interests in keeping the platform working and safe: abuse

detection, security records, aggregate usage.

  • Legal obligations, principally keeping financial records.
  • Your consent, where we ask for it — you can withdraw it at any time.

Your secrets

Secrets are treated differently from everything else.

They are encrypted before they are stored, with a key our database does not contain. No part of our system will show you a secret's value once you save it — there is no page, no API endpoint, and no support process that reveals one. If you lose a value, you replace it.

They are not in your data export, they are not in logs, and staff cannot read them.

Do we look at your code?

Not by hand. Nobody at PicoCloud browses customer projects.

Automatically, yes: everything deployed is scanned at build time for signs of abuse — phishing kits, malware, credential harvesting. The scanner looks at what code does rather than words it contains. Nearly always this produces nothing and nobody ever sees it. When something is flagged, a person reviews that evidence, and only that.

If you write to support about a problem, we work from error messages and build logs, not from reading your source.

How long we keep things

  • App logs — 7 days on Free, 30 on Hobby, 90 on Pro, 365 on Team, then

deleted automatically

  • Your account and apps — until you delete them
  • Security records — kept after account deletion, with your identity removed
  • Invoices — kept as long as tax law requires, typically 6–7 years
  • Support tickets — deleted with your account

Who else touches your data

We use these companies to run the service. Each sees only what it needs:

  • Fly.io — runs your apps and issues their security certificates *(United

States)*

  • Supabase — our database (United States)
  • Cloudflare — stores your source code and build cache (United States)
  • Resend — sends our email, including your sign-in links (United States)
  • Stripe — takes payments, and holds your card details so we never do

(United States and EU)

  • GitHub — only if you connect it, and only to read the repositories you

pick (United States)

  • Sentry — receives a report when something breaks on our side, so we find

out before you have to tell us (European Union)

An error report carries what went wrong and, where we know it, the account it happened to — so that we can tell whether a fault hit one person or everybody. Credentials, secret values and connection details are stripped out before a report leaves our systems, and we do not attach visitors' IP addresses to them.

We are established in the Netherlands. Most of the companies above store data in the United States; that transfer relies on the standard contractual clauses each of them offers, together with their own safeguards.

We do not sell personal data, and we have never received a government request for customer data.

Cookies

Two, both strictly necessary, neither used for tracking:

  • `pico_session` — keeps you signed in to the dashboard
  • `pico_app_session` — remembers that a visitor proved they may open a

private app

There is no analytics cookie and no advertising cookie, which is why this site has never asked you to accept anything.

What you can do

  • See it — download everything we hold about you from your account settings,

as one JSON file, immediately

  • Correct it — change your details in the dashboard, or ask us
  • Delete it — delete your account from your account settings. It is

immediate. Your apps stop and are destroyed, your secrets and storage are erased, and your details are removed from your account record. Invoices and security records survive with your identity stripped out, for the reasons above

  • Object, or restrict what we do — write to us
  • Complain — to a data protection authority. Ours is the Dutch Autoriteit

Persoonsgegevens (autoriteitpersoonsgegevens.nl); you may also complain to the authority where you live, such as the ICO in the UK

We answer within 30 days and we do not charge for it.

If something goes wrong

If personal data is exposed, we will tell the relevant authority within 72 hours where required, and we will tell you directly if it puts you at risk — plainly, saying what happened and what to do.

Children

PicoCloud is not for under-16s and we do not knowingly collect their data. Tell us if you believe a child has an account and we will remove it.

Changes

We will post changes here and update the date at the top. If a change materially affects you, we will email you first.

Contact

legal@picocloud.io, or open a support ticket from your dashboard.

DeepDas Spanjaardsgoes 114, 3901 HC Veenendaal, Netherlands Chamber of Commerce (KvK): 93932995 VAT: NL005052734B37