← Back

Privacy Policy

Version: 2026-07-02

1. Data controller

The data controller for personal data processed in connection with Server Manager is Igor Cardines, Italian sole trader (libero professionista). Contact: support@servermanager.dev.

As a sole trader, we do not have a formally designated Data Protection Officer (DPO); please direct all data-protection inquiries to the contact email above.

2. What personal data we collect

For a plain-English breakdown with examples, see the help article What Server Manager stores about you. The formal categories of data we process:

  • Account information: email address, name (if provided via Google OAuth), authentication provider used, account created date, role (user / admin).
  • Saved server profiles (opt-in): server alias, host/IP, port, username, and an encrypted credential blob (AES-256-GCM, key derived from a passphrase only you know via scrypt; we never see your passphrase or the plaintext credentials in storage).
  • Active session data: SSH credentials necessary to operate your session, held only in process memory while the session is open. Never written to disk. Discarded when the session ends.
  • Server connection records: IP/hostname you connect to plus claim timestamps. Used for the one-active-user-per-host check and free-tier abuse prevention.
  • Billing data: Stripe customer ID, optional saved-payment-method ID, pass start/end dates, cumulative LLM cost on the current pass, billing-address details you provide at checkout. Card numbers and similar sensitive data are handled by Stripe directly and never reach our servers.
  • Per-purchase consent records: timestamp, IP address, user-agent, version of these Terms and Privacy Policy accepted at each purchase. Required as the audit trail for the Art. 16(m) right-of-withdrawal waiver.
  • Usage logs: per-LLM-call token counts, model name, calculated cost in EUR, session ID. Does not include chat content.
  • Free-tier anti-abuse records: grant date and optional revocation date, plus list of VPS hosts observed under the grant (within a 90-day window).
  • File snapshots (Undo): command text, file paths, file contents (base64) for files Faro modifies; captured for the Undo feature, auto-deleted 30 days after capture.
  • Browser extension & monitoring data (opt-in): if you use the optional browser extension and enable server monitoring, a device pairing token (hashed at rest) and the latest status snapshot of each monitored server (metrics, pending-update counts, reachability — no credentials, no chat). See section 14.
  • Support correspondence: the content of messages you send us by email (support@servermanager.dev) or through the contact form, together with your name and email address, stored as a support ticket so we can track and answer your request.
  • Invoicing / fiscal data (only if you request a fattura): when you ask for an Italian electronic invoice at checkout, the fiscal details you provide — name or company name, address, country, codice fiscale and/or partita IVA, and codice destinatario or PEC — are stored and used to issue and transmit the fattura through SdI.

3. Data we do NOT collect

  • SSH passwords or private keys in plaintext (in storage)
  • Your encryption passphrase (for saved server profiles)
  • Card numbers, CVVs, or expiry dates (Stripe handles these)
  • Persistent chat history past your session (chat is RAM-only by design)
  • IP address logs for analytics or fingerprinting (only captured per-purchase as a consent audit trail)
  • Analytics or marketing cookies (only the auth session cookie is used)

4. Lawful basis for processing

We process your personal data under the following GDPR Art. 6 bases:

  • Contract (Art. 6(1)(b)): account creation, authentication, processing your purchases, operating the agent against your server, billing, customer support.
  • Legitimate interests (Art. 6(1)(f)): abuse prevention (free-tier anti-fraud, rate-limiting), security monitoring, service stability, product analytics and service improvement (pseudonymous, cookieless usage measurement). Where we rely on legitimate interests, we've assessed that our interests do not override your rights and freedoms.
  • Legal obligation (Art. 6(1)(c)): retention of invoicing records required by Italian tax law; responding to lawful requests from authorities.
  • Consent (Art. 6(1)(a)): the Art. 16(m) right-of-withdrawal waiver at purchase; saving a card for auto-refill.

5. Purposes of processing

  • Providing the service — running agent commands you approve against your server, rendering the UI, managing your sessions
  • Billing — processing payments via Stripe, generating receipts, tax compliance
  • Abuse prevention — detecting attempts to defeat the free-tier limit, suspending accounts in violation of acceptable use
  • Service operation — diagnosing errors, security monitoring, capacity planning (aggregate non-identifying metrics only)
  • Communications — authentication emails, service-critical notices (TOS changes, security issues), responses to your support requests

We do not use your data for advertising, marketing email lists, profiling for ad targeting, or sale to third parties.

Automated processing & AI. Server Manager operates through AI systems — the Faro agent and our support assistant — built on a third-party general-purpose AI model (currently OpenAI); Section 6 describes the data they process, and our Terms of Service cover AI-transparency details under the EU AI Act (Regulation (EU) 2024/1689). We do not carry out solely automated decision-making that produces legal or similarly significant effects on you within the meaning of GDPR Art. 22: Faro acts only on your explicit, per-command approval, and a human reviews any AI-drafted support reply before it is sent.

6. Third-party processors (sub-processors)

We rely on the following sub-processors to operate Server Manager. Each has its own privacy policy and processes only the data necessary for the function described.

  • Stripe (Ireland EU entity for European customers; United States transfers covered by Standard Contractual Clauses): handles all payment processing. Receives your card details, billing address, payment-history data. We see only opaque IDs.
  • OpenAI (United States, SCCs): receives the content of your chat messages plus relevant server context (file contents Faro reads, command outputs) for the purpose of generating Faro's responses. When you contact us by support email or the contact form, the content of your message is also sent to OpenAI to draft a suggested reply, which a member of our team reviews before it is sent. Per OpenAI's API terms, your data is not used to train their models; they retain operational logs for up to 30 days.
  • Resend (United States, SCCs): sends transactional emails (authentication links, support replies).
  • Aruba (Aruba PEC S.p.A.) (Italy): our electronic-invoicing intermediary. When you request a fattura, it receives that invoice's fiscal data (the FatturaPA file) to transmit it to the Italian tax authority's Sistema di Interscambio (SdI) and to preserve it as legally required. Used only for customers who request an invoice.
  • Neon (EU region, PostgreSQL hosting): stores our database.
  • Application hosting provider: runs our application servers. Sees only the data necessary to handle requests in transit.
  • PostHog (European Union region — PostHog Cloud EU): product and website analytics. Receives pseudonymous usage events linked to your account identifier — sign-up, server connections, recipe runs, and product-funnel events such as reaching a usage limit or purchasing a pass — together with cookieless page-view data and standard request metadata (browser and device type, and an approximate country derived from your IP address, which is used only for that lookup and then discarded — we do not store your IP address). We use this only to understand how Server Manager is used and to improve it. It is configured without cookies and without cross-site tracking, is not used for advertising, and receives no chat content, server credentials, or file contents.
  • Sentry (European Union region): application error monitoring. When the app encounters an unexpected error, Sentry receives a diagnostic report — the error type and stack trace, the route involved, and browser/operating-system type, associated with a pseudonymous identifier — so we can detect and fix faults. It is configured not to transmit personal data from request contents, and processes no chat content or credentials.

We add or change sub-processors only as needed for service operation. Material changes will be reflected in this policy with notice.

7. International data transfers

Some of our sub-processors (Stripe US ops, OpenAI, Resend) are located in the United States. These transfers are covered by Standard Contractual Clauses (SCCs) adopted by the European Commission, as a valid GDPR Chapter V transfer mechanism following the Schrems II ruling.

8. Retention periods

  • Chat content: in-memory only; lost when your session ends. No persistent storage.
  • Account record: for the lifetime of your account. On deletion: soft-deleted for 30 days, hard-deleted after.
  • Billing records and consent audit trail: retained for 10 years to comply with Italian tax law (conservazione delle scritture contabili), in minimized form (transaction date, amount, invoice ID, accepted-TOS version).
  • Usage logs: retained for 12 months for abuse detection and aggregate reporting; deleted thereafter.
  • Support tickets: the content of your support correspondence and our replies, retained for up to 24 months to handle follow-ups and recurring issues, then deleted — or sooner on request, except where a message relates to a billing record we must keep.
  • Electronic invoices (fatture): when you've requested one, the fattura and its fiscal data are preserved for 10 years as required by Italian law (conservazione a norma), through our invoicing provider.
  • File snapshots (Undo): 30 days from capture, then auto-deleted by a scheduled job.
  • Free-tier abuse records (observed VPS hosts): 90 days from observation; used only for cross-account matching during this window.
  • Authentication tokens and session cookies: session-cookie lifetime, typically 30 days unless you sign out earlier.

9. Your GDPR rights

As an EU data subject, you have the rights described in GDPR Chapter III. For the practical "how to exercise each one" version, see the help article Your GDPR rights & data export. In summary:

  • Right of access (Art. 15) — receive a copy of your data
  • Right of rectification (Art. 16) — correct inaccurate data
  • Right of erasure (Art. 17) — delete your data; one-click via the Account page
  • Right to data portability (Art. 20) — receive your data in a machine-readable format
  • Right to object (Art. 21) — to processing based on legitimate interests
  • Right of restriction (Art. 18) — pause processing during dispute review

You also have the right to lodge a complaint with a supervisory authority. The lead authority for Server Manager is the Italian Garante per la protezione dei dati personali; you may also contact your national data protection authority.

To exercise any of these rights, email support@servermanager.dev from the email address registered to your account. We respond within 30 days as required by GDPR.

10. Cookies

We use only essential cookies — specifically the authentication session cookie that keeps you logged in. We do not set analytics cookies, advertising cookies, social-media tracking pixels, or third-party trackers. No cookie banner is required under EU/Italian guidance because no consent-requiring cookies are used.

11. Minimum age

Server Manager is a paid service requiring a binding contract and is not directed at minors. You must be at least 18 years old to create an account. If we become aware that we have collected personal data from someone under 18, we will delete it promptly.

12. Security

We apply appropriate technical and organizational measures to protect your data, including:

  • TLS encryption for all data in transit
  • Encryption at rest of saved-server credentials using AES-256-GCM with passphrase-derived keys (scrypt KDF)
  • SSH credentials held only in process memory for active sessions; never written to persistent storage
  • Card details handled by Stripe under PCI DSS Level 1 certification; we never see them
  • Minimum-necessary access control on internal systems
  • Regular dependency-update review for known vulnerabilities

No system is perfectly secure. In the event of a personal-data breach that is likely to result in risk to your rights and freedoms, we will notify the Garante within 72 hours and the affected users without undue delay, as required by GDPR Art. 33 and 34.

13. Changes to this policy

We may update this policy as our practices change. Material changes (new sub-processors, expanded data collection, new purposes) will be announced with at least 30 days' notice via email and an in-app banner. The version stamp at the top of this page reflects the current revision.

14. Browser extension & server monitoring (optional)

Server Manager offers an optional browser extension that shows the status of servers you choose to monitor, directly in your browser toolbar. It is free and entirely opt-in: if you do not install it and do not enable monitoring, none of the processing in this section occurs.

  • Device pairing token: when you connect the extension to your account, we issue a token that links that browser to your account. It is stored locally in the browser (extension storage) and, in hashed form, on our servers. You can revoke it at any time from Account → Connected extensions; revoking immediately stops the extension from seeing your servers.
  • Server status snapshots: for each server you enable monitoring on, we store the latest status snapshot — load, memory, disk, pending-update counts, basic host info (OS, kernel, uptime) and the server's HTTP reachability. This is the same operational data shown in the app. The extension reads it over HTTPS to render the toolbar badge and popup, and the latest status is also held in the browser's local extension storage. Snapshots contain no chat content and no credentials.
  • On-server monitoring agent: enabling monitoring installs a small read-only agent on your server (a script run by an unprivileged, no-login system user on a scheduled timer). It reads local metrics and pending-update counts and sends them to your account over HTTPS roughly every five minutes. It cannot make changes, run commands, or read your files, and it stores no SSH keys. Turning monitoring off for a server (from the app) removes the agent.

The extension communicates only with your own Server Manager account at servermanager.dev. It uses no remote code, sets no advertising or analytics trackers, and transmits your data to no third party. Snapshot data is kept only as the latest value per server (each update overwrites the previous one) and is deleted when you disable monitoring or delete your account.

Contact

Privacy and data-protection inquiries: support@servermanager.dev. Postal correspondence (if needed for formal requests) on request.