Privacy & cookies

What we collect, why we need it, and how you can control it.

Updated

Who handles your information

vpsmon Cloud is operated by Leonidas D., an individual based in Vilnius, Lithuania. Contact support@vpsmon.cloud for support, privacy requests, or security reports.

The operator is responsible for account, support, and service-operation information. If you use Cloud to process personal information on behalf of another person or organization, you remain responsible for your authority to do so. Contact us about a data-processing agreement before sending that information; avoid personal or sensitive information in server, process, and container names.

Account and email information

Cloud stores your email address, password hash (not your readable password), account and workspace identifiers, verification status, and expiring security tokens. Session tokens are stored as hashes. We also keep alert settings, recipient verification, notification content and delivery status, and support correspondence you send us.

If you enable webhook alerts, Cloud stores the receiver URL, format, signing secret, incident payloads, and delivery status. Incident starts and recoveries send server identifiers, hostname, the affected resource, value, threshold, and time to the endpoint you choose. Webhooks do not send live processes or incident snapshots. You can pause webhook delivery independently of email alerts.

Your verified signup email is the default incident and recovery recipient. You can disable email alerts or verify a different destination in Alert settings. Verification, password-reset, and trial-reminder messages go to your account email. These are service messages, not marketing subscriptions.

Connected-server information

The separate vpsagent sends telemetry over outbound HTTPS only after you install and pair it. The local vpsmon dashboard does not upload to Cloud. Samples include hostname, uptime, load, CPU, memory and swap use, network counters, process count, and writable disk names, device labels, and capacity. We use these for your dashboard, history, and incident detection.

Opening server details requests the top five process names and CPU/memory percentages while you view them. Live processes stay in bounded Cloud memory only, outside the database, history, application logs, and database backups. Closing the dialog stops requests; hidden tabs stop renewing them. Requests and samples expire after 30 seconds without renewal and are cleared by the next cleanup sweep, within another 15 seconds. They do not include command arguments, environment variables, logs, or listening sockets.

Saved process and container details are a separate, one-time incident snapshot, off by default. If you enable snapshots on your agent, a threshold crossing can send top process names and CPU/memory use, plus Docker container ID, name, image, state, health, uptime, restart count, port mappings, CPU, and memory. Snapshots omit process IDs, command lines, environment variables, logs, and listening sockets. These labels may reveal what you run.

Agent management stores installed version, operating system and architecture, remote-update availability, last contact, and update requests with the requesting account email, target version, timestamps, and progress. Updates require local opt-in and an authenticated request from your Cloud account.

Why we use this information

We use account details and the telemetry you request to provide the service under our agreement with you. Our legitimate interests in keeping Cloud secure and reliable support abuse prevention, diagnostics, and handling support requests. Where a legal obligation applies, we retain information required to comply with it. Optional incident snapshots are controlled on your agent; you can stop future collection by turning them off or disconnecting the agent.

Hosting and network providers process IP addresses and technical requests to deliver and protect the site. Application diagnostics are normally rotated within 14 days. Email-abuse quotas use keyed, pseudonymous identifiers rather than readable recipient or IP values. We do not sell personal information, serve targeted advertising, or make decisions with legal or similarly significant effects solely by automated profiling.

Hosting, integrations, and international transfers

The Cloud application and its main SQLite database run on a Hostinger VPS in Vilnius, Lithuania. Hosting administration and provider services have their own processing arrangements; this does not mean every provider system is located in Lithuania.

Resend delivers account and alert emails. It receives recipients and message content, which can include server names, resource values, and incident details. Resend stores data in the United States even when an EU sending region is selected. Its data-processing agreement includes Standard Contractual Clauses for international transfers. Resend documents 30-day email/log retention on its standard plans; its own backups and account records follow its published retention terms.

Webhook receivers, including Slack when selected, process the incident information you choose to send under their own terms, privacy notices, and retention policies. Their data locations depend on the receiver and your settings. Configure only an endpoint you control or are authorized to use.

For subscription purchases through Stripe Managed Payments, Stripe/Link processes the payment and customer information needed to sell the subscription, handle receipts, taxes, and payment support. Cloud retains customer/subscription identifiers, status, and billing-period records, not full card numbers.

Agent release checks and downloads use GitHub and signature-verification services, which receive technical network requests from Cloud or your agent. Information may also be disclosed when legally required or necessary to investigate a security incident. Contact us for information about the safeguards applicable to your data.

How long information stays

Support correspondence is kept as needed to resolve your request and document its outcome, or meet a legal obligation. Ask us about deleting it when it is no longer needed.

  • Raw metric samples: about four hours. Five-minute history: one day. Hourly history: 30 days. Rollup boundaries and periodic cleanup can slightly extend these windows.
  • Resolved incidents, their snapshots, and associated alert delivery records: 90 days after resolution. Active incidents remain until resolved or the server/account is deleted.
  • Account details, server registrations and last-known summary values, settings, and trial-reminder records: until account or server deletion as applicable. Update records are limited to the latest 20 requests per server.
  • Unverified abandoned accounts: 30 days. Sessions expire within seven days, or sooner for short sessions. Expired security tokens and inactive abuse-limit records are removed during scheduled cleanup.
  • Scheduled encrypted database backups: one snapshot every hour. The service and its off-host collector each retain their latest successful copy; an older copy is removed after its replacement succeeds. Failed replacements preserve the last recovery copy until a new one is available. Deployment recovery keeps the latest two pre-upgrade snapshots and the binaries needed to restore them. Material from a failed upgrade is retained until recovery is resolved. Manual recovery copies and hosting-provider backups follow their own retention. A deleted account can remain in those copies until they are removed.

Deleting an account or server

You can delete your personal Cloud account in Account after confirming your password. This deletes its workspace, server credentials, metrics, incidents, snapshots, update records, and alert settings from the active database. Removing a server deletes its Cloud records and revokes its Cloud credential. Local vpsmon keeps running.

Database deletion does not immediately erase older backups, browser preferences, provider records, or support correspondence. Backup copies are held for recovery with restricted access. Provider records remain subject to their own retention and applicable law. You can clear browser storage yourself and contact us about other retained information.

Cookies and browser storage

The site uses a necessary session cookie to keep you signed in and protect account actions. The dashboard stores an onboarding-completion preference locally in your browser, under a key containing your account email, so the checklist stays dismissed after refresh. This preference contains no credentials or server telemetry and remains until you clear that storage. The site does not use advertising or analytics cookies.

Your privacy rights

Where applicable, you can request access, correction, deletion, a portable copy, or restriction of your personal information, and object to processing based on legitimate interests. Email support@vpsmon.cloud; we may need to confirm your identity before sharing or changing account information. We normally respond within one month and will explain any lawful extension or exception.

You may complain to Lithuania's State Data Protection Inspectorate or your local supervisory authority. Account information and necessary telemetry are required to provide the corresponding Cloud features; you can choose not to pair a server or end the service. Material changes to this notice will be communicated through the service or account email.