Privacy & cookies
A plain-language account of the information vpsmon Cloud handles in this preview.
Who operates the service
vpsmon Cloud is a hosted monitoring service from the vpsmon project. The operator's legal name and postal address, and a monitored privacy/support contact, have not yet been confirmed. This draft is therefore not a complete privacy notice and must be completed before public registration.
Information in a Cloud account
If you create an account, Cloud stores your email address, a password hash (not your readable password), account and workspace identifiers, and account-security records such as email-verification status and expiring sign-in or recovery tokens. Session cookie token values are stored as hashes. A session cookie is used only to keep you signed in and protect account actions.
If you configure incident email, Cloud stores the verified destination address and delivery status for incident and recovery notifications. Account verification, password reset, and trial-reminder messages use the email address on the account.
Information sent by a connected server
The vpsmon dashboard does not upload to Cloud. Installing and pairing the separate vpsagent starts outbound HTTPS telemetry. Normal samples can include the server hostname, uptime and load, CPU, memory and swap use, network counters, process count, and mounted disk names, device labels, and capacity. Cloud uses these samples for the fleet view, resource history, and incident rules.
Process and container details are a separate, one-time incident snapshot and are off by default. If you opt in, a threshold crossing can send top process names with CPU and memory use (no PID or command line), plus Docker container ID, name, image, state, health, uptime, restart count, port mapping, CPU, and memory. These labels may reveal what you run. Snapshots do not include logs, environment variables, or listening sockets.
Billing and service operation
Real billing is not enabled in this preview. When a test Stripe integration is explicitly configured, Cloud may store Stripe customer and subscription identifiers, subscription status, and billing-period state received from signed provider events. Cloud does not store full card numbers. Any future live-payment provider and its data locations must be disclosed before paid service begins.
Cloud and its hosting/network providers may process IP address and technical request information to deliver the site, prevent abuse, and keep the service secure. Rate-limit keys are stored in a keyed, non-readable form. The final hosting provider, processing locations, and applicable international-transfer safeguards still need to be confirmed for launch.
Email and other providers
If the operator configures Resend, it receives transactional email addresses and message content needed to deliver verification, reset, trial, and incident messages. Stripe is used only for local test-mode billing in the current code. The production hosting, email, and payment-provider list is not final and must be completed before public signup.
Retention and deletion
Cloud keeps raw metric samples for about four hours, five-minute history for one day, and hourly history for 30 days. Resolved incidents are kept for 90 days; active incidents remain until resolved. Unverified abandoned accounts are removed after 30 days. Expired sign-in and one-use tokens are pruned.
You can delete your personal Cloud account from the Account area after confirming your password. This removes its workspace, connected-server credentials, metrics, incidents, snapshots, and alert settings from the active database. If encrypted backups are enabled, a copy may remain in a backup until that backup is rotated out. Removing a server also deletes its Cloud history and revokes its Cloud credential; local vpsmon continues to work.
Cookies, rights, and contact
The site uses a strictly necessary, protected session cookie when you sign in. The current site does not include advertising or analytics cookies. There is no separate cookie banner because the preview has no optional tracking cookies; this must be reassessed if that changes.
Depending on the law that applies, you may have rights to request access, correction, deletion, restriction, portability, or to object to certain uses of your information. You can delete your account in the product. The operator's privacy-request contact has not been designated yet; add it here before opening public signup. You may also complain to your relevant data-protection authority.
vpsmon Cloud