Last updated 4 August 2026
This explains what we collect, why, and what you can do about it. It is written to be read, not to be survived.
The short version. We collect the least we can: your email address, what you deploy, and enough operational data to run and bill the service. We do not sell anything to anybody, we do not track you across the web, and there are no advertising or analytics trackers on this site.
DeepDas is the data controller — registered in the Netherlands, Chamber of Commerce (KvK) 93932995, at Spanjaardsgoes 114, 3901 HC Veenendaal. For anything in this document, write to legal@picocloud.io.
Your account. Your email address. Optionally your name and profile picture, if you connect a GitHub account. There is no password, because we do not use one.
What you deploy. Your source code, the container images we build from it, and your app's configuration. Also your secrets — encrypted, and covered separately below.
Running your apps. Logs your app produces, and counts of requests, bytes and cold starts. Those counts are aggregated per app: we do not record the IP address, page or identity of the people who visit your app.
Security records. When you sign in or change something, we record the action, the time, and the IP address and browser it came from. This is what makes a compromised account investigable, so it is kept even after other data goes.
Visitors you invite. If you share a private app with someone by email, we store that email address so we can let them in, and when they last used it. That person is not our customer; we use it for nothing else.
Support. Whatever you write in a ticket, and our replies.
Payments. If you pay us, Stripe handles the card. We never see or store your card details — we keep an identifier, your plan, and your invoices.
and covers your account, your apps and your billing.
detection, security records, aggregate usage.
Secrets are treated differently from everything else.
They are encrypted before they are stored, with a key our database does not contain. No part of our system will show you a secret's value once you save it — there is no page, no API endpoint, and no support process that reveals one. If you lose a value, you replace it.
They are not in your data export, they are not in logs, and staff cannot read them.
Not by hand. Nobody at PicoCloud browses customer projects.
Automatically, yes: everything deployed is scanned at build time for signs of abuse — phishing kits, malware, credential harvesting. The scanner looks at what code does rather than words it contains. Nearly always this produces nothing and nobody ever sees it. When something is flagged, a person reviews that evidence, and only that.
If you write to support about a problem, we work from error messages and build logs, not from reading your source.
deleted automatically
We use these companies to run the service. Each sees only what it needs:
States)*
(United States and EU)
pick (United States)
out before you have to tell us (European Union)
An error report carries what went wrong and, where we know it, the account it happened to — so that we can tell whether a fault hit one person or everybody. Credentials, secret values and connection details are stripped out before a report leaves our systems, and we do not attach visitors' IP addresses to them.
We are established in the Netherlands. Most of the companies above store data in the United States; that transfer relies on the standard contractual clauses each of them offers, together with their own safeguards.
We do not sell personal data, and we have never received a government request for customer data.
Two, both strictly necessary, neither used for tracking:
private app
There is no analytics cookie and no advertising cookie, which is why this site has never asked you to accept anything.
as one JSON file, immediately
immediate. Your apps stop and are destroyed, your secrets and storage are erased, and your details are removed from your account record. Invoices and security records survive with your identity stripped out, for the reasons above
Persoonsgegevens (autoriteitpersoonsgegevens.nl); you may also complain to the authority where you live, such as the ICO in the UK
We answer within 30 days and we do not charge for it.
If personal data is exposed, we will tell the relevant authority within 72 hours where required, and we will tell you directly if it puts you at risk — plainly, saying what happened and what to do.
PicoCloud is not for under-16s and we do not knowingly collect their data. Tell us if you believe a child has an account and we will remove it.
We will post changes here and update the date at the top. If a change materially affects you, we will email you first.
legal@picocloud.io, or open a support ticket from your dashboard.
DeepDas Spanjaardsgoes 114, 3901 HC Veenendaal, Netherlands Chamber of Commerce (KvK): 93932995 VAT: NL005052734B37