Privacy.
Last updated: 23 April 2026.
This is a placeholder privacy policy. The final version will be drafted with a GDPR-competent lawyer before commercial launch. The principles below are final.
What we collect
Email address, encrypted vault blobs, and coarse audit metadata (who performed which action at what time). We never see your master password, your server passwords, your SSH keys, or the output of any command.
How we use it
To provide the service โ authenticate you, sync your encrypted vault across your devices, and diagnose incidents if they happen. We do not sell data. We do not run ad-based tracking.
Where it lives
European Union data centres (Neon Postgres, Vercel Frankfurt). Backups are encrypted and stored in the same region.
How long we keep it
For as long as your account exists, plus up to 30 days after deletion for legal retention (invoices, audit exports you triggered). After that, wiped.
Your rights under GDPR
Access, rectification, deletion, portability, restriction of processing, and objection. Email dpo@sshcontrolcenter.com and we respond within 30 days.
Sub-processors
- Vercel โ hosting of the cloud API.
- Neon โ Postgres database (EU region).
- Cloudflare โ DNS and edge.
- Resend โ transactional email.
Contact
Data Protection Officer: dpo@sshcontrolcenter.com. For everything else: hello@sshcontrolcenter.com.