This policy explains what personal data Poof processes, why, and for how long. We never sell your data.
1. What we collect and why
Account data. When you sign up, we ask for your name, email address, and a password (which we store only as a hash, never in plain text). This is so you can sign in and so we can reach you about your account. If you add a profile picture, we keep it on the server that runs the panel, not in a shared bucket — it never leaves that machine.
Billing data. Your card details go directly to Paddle, our merchant of record — they never reach our servers. We keep a record of your subscription and its status; when you view your payment history or an invoice, we read it live from Paddle rather than storing our own copy.
Your application and its data. The application you run through the Service, and any database it uses, live on the server we assign to it, in the EU. We do not keep a separate copy of your application's secrets or its data — the server it runs on is the only place they live.
Sign-in and security data. We log sign-ins together with the IP address used, to secure your account and to show you, in your list of active sessions, on which devices you are signed in.
Cookies. Only cookies strictly necessary for the Service are set, so no consent banner is shown:
PHPSESSID— your session; only set once something needs it, such as signing in; ends when you close your browser.REMEMBERME— keeps you signed in, only if you chose "Keep me signed in".ACCOUNT_SWITCH— remembers the accounts you are signed in to in this browser, so you can switch between them; set when you sign in, unless account switching is turned off for the site.locale— the interface language you chose; one year.
2. When we access or disclose your information
Sub-processors. We use third-party providers to run the Service: Amazon Web Services (the servers that run applications and databases, our object storage, and outgoing email delivery) and Paddle (payment, invoicing, and tax handling — see its own privacy policy). We do not use any other sub-processor to handle your personal data.
Support, with your consent. If we need to look at your account or application to help with a support request, we will ask first.
Automated failures. If an automated process fails partway through, we get an alert; when we can fix it and resume without looking at any personal data, we do. In the rare case we cannot, we look at the minimum needed to fix the root cause.
Legal requests. We disclose personal data in response to a legally binding request only to the extent the law requires, and we tell you about it first unless we are legally prohibited from doing so.
3. Your rights
Because your data is processed in the EU, you have the rights the GDPR gives you, wherever you are:
- Access — a copy of the personal data we hold about you.
- Rectification — correction of data that is wrong or incomplete.
- Erasure — deletion of your personal data, subject to what we must keep by law; deleting your account removes your account data and, through it, everything that depends on it.
- Restriction and objection — limiting or objecting to how we process your data in certain cases.
- Portability — receiving your data in a portable format.
- Complaint — lodging a complaint with a data protection supervisory authority.
To exercise any of these, contact us at privacy@poof.run.
4. Security
Traffic to the Service is encrypted in transit over TLS. We limit who can access production systems and applications to what each of our own processes needs.
5. Data retention
We keep your account data for as long as your account exists. If you delete your account, that deletion cascades to the data that depends on it. What happens to an application and its data when a subscription is canceled, suspended, or a payment fails is described in our Terms of Service, §4: in short, a stopped application and its data are kept for 30 days — with a reminder email 7 days and again 24 hours before the deadline — and are then permanently deleted within about a day.
6. Location of data
Applications, their databases, and our object storage run in the EU. The one exception is domain name management, which — by a limitation of our hosting provider, not a choice of ours — goes through an API endpoint in the US; no application or account data is stored there. Paddle processes your billing data under its own privacy policy, linked in §2.
7. Changes to this policy
We may update this policy to reflect a new practice or a change in the law. If we make a material change, we will notify account holders — for example by email or a notice within the Service — before it takes effect. This version is effective as of 27 September 2026.
8. Questions
Questions about this policy or your data can be sent to privacy@poof.run.
Adapted from the Basecamp open-source policies, licensed under CC BY 4.0.