Short version: We collect only what is needed to operate ServerCrate. We cannot read your backup files. We do not sell your data.
Backup data is encrypted client-side. We do not have your encryption key. The ciphertext stored on our systems is unreadable without it.
We do not sell your data. We share information only with service providers needed to operate ServerCrate, such as Stripe for billing and relevant infrastructure providers, or when legally required to do so.
Account data is retained while your account is active. Vault data is deleted within 30 days of deprovisioning unless a longer retention period is legally required. Billing records may be retained for up to 7 years for accounting and compliance purposes.
We use HTTP-only session cookies for authentication and security. We do not run third-party advertising trackers. We do not use your data for ads.
We use HTTPS, HTTP-only Secure cookies, CSRF protection, password hashing, rate limiting, TOTP-based 2FA, and isolated customer environments. No system is perfect, but we design around minimizing exposure and protecting account access.
You may request access to, correction of, or deletion of your personal data, subject to legal and operational requirements. Contact privacy@servercrate.net.