Privacy Policy
What we collect, why, how long we keep it, and how to get it back or have it deleted.
Privacy Policy
Effective: 21 August 2026
This policy explains what Sahabti collects when you use the platform at sahabti.com and its
subdomains, why we collect it, how long we keep it, and what you can ask us to do with it.
Sahabti is the controller for the data described here. Where you use Sahabti to process personal data belonging to your users, you are the controller and we are your processor — that relationship is governed by the Data Processing Agreement.
1. What we collect
Account data. Your name, email address, a hashed password (we never store the password itself), your interface and email language preference, and whether your email is verified. If you sign in with GitHub or Google we receive your provider account id, email address and display name from them — never your password with that provider.
Session and security data. A session token, the IP address and browser user-agent of each sign-in, and the time of each session. This is what powers the active-sessions list in your account settings and lets you revoke a device you no longer recognise. We also count authentication attempts per IP address in order to rate-limit sign-in, sign-up, password reset and one-time-code requests.
Workspace and resource data. Workspace names and slugs, membership and roles, invitations, and the configuration of what you create: instance names, plans, engine types, network settings, snapshot metadata, domains you add, quota requests, and an audit log of who did what in the workspace.
Credentials you create. API tokens and SSH keys are stored as hashes or public keys — a token value is shown to you once, at creation, and cannot be recovered from us afterwards.
Integration data. If you connect GitHub, we store the installation id and the repositories you select, and we receive webhook events for them.
Support correspondence. Whatever you send us by email.
Content on your instances. Databases, files and workloads you run stay on the instances you create. We do not read them, index them, or use them to train anything. Staff access is limited to what Who can see your data describes below.
We do not use advertising trackers, and we do not sell personal data.
2. Why we use it
| Purpose | Data used |
|---|---|
| Creating and running your account | Account data, session data |
| Provisioning and operating what you create | Workspace and resource data |
| Keeping accounts secure — rate limits, abuse detection, session revocation | Session and security data |
| Answering support requests | Correspondence, account data |
| Meeting legal obligations and responding to abuse reports | Any of the above, as relevant |
Our legal bases are: performing our contract with you (running the Service), our legitimate interest in keeping the platform secure and abuse-free, your consent where we ask for it, and compliance with legal obligations.
3. Cookies
We set a session cookie so you stay signed in, and a cookie that remembers your language. Both are strictly necessary — there are no analytics or advertising cookies, so there is no consent banner to click through.
4. Subprocessors
| Subprocessor | What it does | Data it can see |
|---|---|---|
| Cloudflare | Public ingress, TLS termination, DDoS protection | Request metadata, IP addresses |
| GitHub | Optional sign-in, and the repository integration | Account identifiers, selected repository names |
| Optional sign-in | Account identifiers | |
| Transactional email provider | Verification codes, password resets, notifications | Email address, message contents |
This list covers providers that can access customer personal data. Internal tooling that never touches it — our operator network access, monitoring and build systems — is not a subprocessor and is not listed.
Compute, storage and databases run on hardware we operate ourselves; they are not handed to a third-party cloud. We will name the data-centre facility and region on request at [email protected].
We will publish notice of a new subprocessor at least 30 days before it starts processing customer personal data.
5. Who can see your data
Platform staff reach production only through a private network path — there is no publicly exposed operator interface — and access is limited to the people who operate the platform. We access a customer instance only to resolve a support request you raised, to respond to an abuse report, or to restore service during an incident. Actions taken from the operator console are written to an internal audit trail, and a support sign-in to your account is recorded there. You can request a record of staff access to your account at [email protected].
6. How long we keep it
We keep personal data no longer than we need it for the purpose it was collected for.
| Data | Retention |
|---|---|
| Account and workspace data | For as long as the account exists |
| Data after account deletion | Removed from live systems within 30 days. Copies held in backups go as those backups are rotated or overwritten. |
| Instances, volumes and snapshots | Deleted with the resource, or with the account, as above |
| Security and operator audit records | Kept while they remain useful for security, abuse handling and legal purposes |
| Session records | Until the session expires or you revoke it |
| Rate-limit counters | Rolling window, hours at most |
| Support email | No longer than we need it to support you and keep a record of the issue |
| Records we must keep by law (e.g. tax) | For the statutory period |
7. Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict or object to processing, or export it in a portable form. Email [email protected] from your account address. We aim to respond within 30 days; if a request is complex we will tell you and explain why we need longer.
Much of this you can do yourself: account settings let you change your details, revoke sessions and tokens, and delete your account.
If you are in Jordan you may complain to the Personal Data Protection Council at the Ministry of Digital Economy and Entrepreneurship. If you are in the EEA or UK, you may complain to your local supervisory authority.
8. International transfers
Customer workloads and their data stay on our own infrastructure. Some of the subprocessors listed above operate globally, so limited account and request metadata may be processed outside your country. Jordan's Personal Data Protection Law permits such transfers where the data keeps a level of protection no lower than the law requires; we rely on the mechanism the receiving provider offers — Standard Contractual Clauses, or an adequacy decision.
9. Security
How we protect this data — encryption in transit, tenant network isolation, access control, and how to report a vulnerability — is described on the Security page.
If a personal data breach affects you, we will notify you without undue delay, and we will notify the relevant regulator where the law requires it.
10. Children
We do not knowingly collect personal data from children under 13. If you are under 18, a parent or legal guardian must agree to your use of the Service and is responsible for the account.
If you run something on Sahabti whose users include children — a game server, for example — you are the controller for those players' data, and obtaining any consent the law requires is your responsibility, not ours.
If you believe a child has given us personal data without that consent, write to [email protected] and we will delete it.
11. Changes
We will announce material changes by email to your verified address and in the console at least 30 days before they take effect. The effective date at the top of this page always reflects the current version.
12. Contact
Privacy questions and rights requests: [email protected].