Privacy Policy

Last updated: July 26, 2026 · Yeeted (beta) · see also the Terms of Service

What we collect

When you create an account we collect your email address, a hash of your password (we never store the password itself), and a record of your acceptance of our terms (timestamp and terms version). When you use the service we store the things you deploy: your application code and built images, the contents of managed databases you attach, secrets you set (encrypted at rest), application logs and metrics, and an audit trail of account actions (who did what, when, and from which IP address). Payment details for paid plans are collected and processed by our payment provider - card numbers never touch our systems.

How we use it

We use this data for exactly one purpose: operating the service - running your deployments, storing and serving your data, showing you your logs and metrics, securing accounts, preventing abuse, and billing paid plans. We do not sell personal data, use it for advertising, or train models on your code or data.

Source code you deploy

When you deploy, we store your source code (and the images built from it) because we have to in order to build, run, relaunch, and roll back your application. Beyond running it, our team may read your deployed source code when we are investigating a problem with the platform - for example a build that fails for a reason we don't understand, a workload that won't start, a crash we cannot reproduce, or a suspected security or abuse issue. Looking at the code is often the only way to tell a platform bug apart from an application bug, and fixes we make from what we learn benefit every customer. Access is limited to the people doing that work and to that purpose; we do not browse customer code otherwise, and we do not use it to train models or build competing products.

Please don't push anything sensitive or proprietary. Yeeted is a beta platform. Treat what you deploy as visible to our engineers when something breaks. Specifically: put credentials in Secrets (encrypted at rest and injected at runtime) rather than in your code, and don't deploy trade secrets, third-party confidential material, regulated data, or anything whose exposure would harm you or someone else.

Where it lives

Your account is homed to one geographic area (for example the US or the EU) when you sign up. Everything you deploy or store - applications, databases, logs - remains physically within that area and is never moved or replicated outside it. Account and login records are held in our global authentication system so you can sign in from anywhere.

Third parties

We share data only with the service providers needed to operate: our payment processor (billing details for paid plans) and our infrastructure providers (the servers your deployments physically run on, within your home area). We do not share personal data with anyone else except where the law requires it.

Analytics and cookies

We use Google Analytics to understand how people find and use Yeeted (pages visited, approximate region, browser type). No analytics cookies are set unless you accept the consent banner shown on your first visit: until then Google receives only anonymous, cookieless pings that cannot be linked to you across pages or visits. If you decline, that stays the case permanently. We do not use analytics data for advertising, and ad-personalisation signals are disabled regardless of your choice. Your choice is stored in your browser; clearing site data shows the banner again. Essential cookies (your login session) are always set - the dashboard cannot work without them.

Retention and deletion

Your rights

You can download everything we hold about you (account record, projects, database metadata, billing history, and your audit trail) from your account at any time, and export full dumps of your databases in standard formats. You can correct your account details, close your account yourself, and request immediate erasure. If you are in the EU/EEA or UK, these correspond to your GDPR rights of access, portability, rectification, and erasure.

Security

Access to the service is authorized through OAuth 2.0 - agents and scripts hold short-lived, revocable tokens, never passwords. Secrets are envelope-encrypted at rest, credentials are redacted from logs, and each customer's workloads run in isolated virtual machines on isolated networks.

Contact

Privacy questions or requests: [email protected].

Yeeted is a research preview; this policy will evolve with the product and material changes will be announced to account holders.