Legal

Privacy Policy

Last updated 2026-09-12. This covers the hosted TurboPanel service at turbopanel.app. A self-hosted instance sends TurboPanel nothing — the data described below lives entirely on your own servers and your own database.

Draft, not legal advice. Written to match what the hosted service actually collects today; needs attorney review — particularly the international-transfer and regional-rights sections — before it governs real signups.

1. Self-hosted vs. hosted

If you run TurboPanel yourself, this policy doesn't apply to that instance — there is no connection back to TurboPanel, no telemetry phoned home, and no data collected by us. Your organization, your servers, your database. Everything below is specific to the hosted service at turbopanel.app.

2. Information we collect

Account information — your email address, name if provided, and organization details, whether you sign up directly or via a connected OAuth provider (GitHub or GitLab, for repository access).

Billing information — for paid tiers, Stripe collects and stores your payment details directly; we receive and retain only what Stripe reports back (subscription status, plan tier, invoice history), never your full card number.

Infrastructure metrics — if you enroll a server with the TurboPanel daemon, that server reports host-level metrics (CPU, memory, disk, network, and — where enabled — ingress and database-proxy statistics) back to the control plane so we can show you your own dashboards. This is operational telemetry about infrastructure you control, not personal data about your end users, and it is never sold or shared outside of operating the service for you.

Deployed application content— the code, containers, and data your deployed applications process are yours; we store and transmit them only as needed to run the service (for example, a Git checkout for a deploy, or a database your application connects to). We don't inspect or use this content for any purpose beyond delivering the service.

Usage and log data — standard web request logs, session identifiers, and error diagnostics generated by using the control plane and web UI.

3. How we use it

To operate, secure, and improve the hosted service; to authenticate you and enforce organization boundaries; to process billing; to communicate service-relevant notices (security incidents, planned maintenance, changes to these policies); and to diagnose problems you or we report.

4. Cookies

The hosted service uses a session cookie to keep you signed in. There is no third-party advertising or cross-site tracking on turbopanel.app.

5. Who we share it with

We share data only with the subprocessors needed to run the service: Stripe (payments), Cloudflare (hosting, network, and edge infrastructure the control plane and UI run on), and — for organizations that connect one — GitHub or GitLab (repository access via the App/OAuth integration you authorize). We do not sell personal data, and we do not share it with anyone else except where required by law or with your direction.

6. Data retention

Account and billing records are kept for as long as your account is active and for a period after closure as needed for legal, tax, and dispute-resolution purposes. Infrastructure metrics are retained on a rolling window sized to the reporting views the product offers, not indefinitely. Deleting your account or disenrolling a server removes what we hold for it, subject to the retention above.

7. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete the personal data we hold about you, and to object to or restrict certain processing. Request any of these at privacy@turbopanel.io [confirm inbox exists before publishing]. We'll respond within the timeframe your local law requires. [GDPR/CCPA-specific language — legal basis for processing, EU representative if applicable — to be set with counsel.]

8. Security

Secrets are sealed at rest under a rotatable root key; passwords and tokens are never stored in plain text. See the security page for how to report a vulnerability. No system is perfectly secure, and we can't guarantee absolute security of information transmitted to the hosted service.

9. Children's privacy

The hosted service is not directed at children under 16, and we do not knowingly collect personal data from them.

10. International transfers

[Where data is processed and stored, and the mechanism relied on for cross-border transfer — to be set with counsel once hosting regions are finalized.]

11. Changes to this policy

We'll update the date above when this policy changes, and post material changes here before they take effect.

12. Contact

privacy@turbopanel.io — or [Company Legal Name], [Registered Address].