Privacy policy.
A short list, because there is not much. Everything we hold is something the service itself created; nothing is collected because it might be useful one day.
- 0identity documents ever collected
- 0third-party trackers on this site
- 0copies we keep of your disks
- 5kinds of data we hold, listed below
1. The short version
Everything we hold is something the service itself created. Nothing is collected because it might be useful one day, and nothing is collected to build a profile of you.
That is not a slogan, it is an operating principle with a cost: data we do not have is data nobody can compel us to produce, and it is also data we cannot use to help you when you lose something. Both halves of that trade are real, and clauses 2 and 8 spell them out.
2. What we hold
The complete list. If something is not here, we do not have it.
| What | Why it exists | Kept for |
|---|---|---|
| An email address | To send you the machine's credentials, invoices and term reminders. There is nowhere else to send them. | While you have an active term, then 12 months |
| A password hash | So you can come back to your own orders. Hashed with a modern algorithm; we cannot read it and cannot tell you what it was. | While the account exists |
| A billing address | An invoice has to carry one. We never verify it and we do not check it against anything. | As long as tax law requires the invoice to exist |
| Invoices and payments | Accounting, and so that a payment dispute can be resolved at all. | As required by tax law |
| The IP addresses assigned to your machine | To answer abuse reports about a specific address at a specific time — see the abuse page. | 12 months after the term ends |
3. What we never ask for
Not at signup, not at renewal, and not at any level of spend. There is no verification tier: the largest node opens on exactly the same terms as the cheapest card.
- An ID document
- A selfie
- A phone number
- A company registration
- A credit card
- A verification tier
- Proof of address
We also do not ask what you intend to run, and we do not ask you to justify a configuration.
4. What is on your machine
Your data. We do not have it.
- We do not hold a login inside your operating system and we do not create one.
- We do not inspect disks and we keep no record of what runs on the machine.
- We take no backups. Snapshots exist only if you bought them, live in another building, and are deleted with the term.
- Disks are erased between tenants — cryptographic erase then a full overwrite — without anyone asking, and within the hour of a term ending.
Encryption at rest is yours to configure, for the reason given in clause 8 of the terms: a key we hold is a key we can be compelled to hand over. We hold none, and the hardware itself remains physically reachable by us and, in principle, by anyone who can compel us.
5. This website
- No third-party scripts. No analytics service, no advertising pixel, no font loaded from someone else's server, no chat widget. The page you are reading loads nothing from any other host — enforced by a Content Security Policy, not just by intention.
- One cookie, a session cookie, set only when you use a form. It carries a random identifier and nothing else, and it expires when you close the browser.
- Server logs. Our web server records requests, including the source address, to operate and secure the site. They are kept for 14 days and then deleted.
- Nothing is sold, shared or used for advertising. There is no advertising, so there is no mechanism through which it could be.
6. Who else sees it
A short list, and each entry is there because the service could not function without it.
- The payment processor that issues addresses and watches for confirmations. It sees the invoice amount and the coin. It does not see your email address, your billing address or what you ordered.
- The data centres that provide space, power and cooling. They see hardware in a rack. They have no access to your machine and no customer records.
- Our transit providers, who carry your traffic in the ordinary way any network carries traffic.
That is the whole list. There is no CRM, no marketing platform, no support desk vendor and no analytics provider, because we do not use any.
7. How long we keep it
The table in clause 2 gives the period for each kind of data. Two general rules apply on top of it:
- Anything we are not legally required to keep is deleted when the reason it existed has gone.
- Invoices are the exception: tax law requires them to survive, and it does not care what we would prefer.
8. Legal requests
- We answer valid orders from a court with jurisdiction over us. We do not answer informal requests however officially they are phrased, and an email signature is not an order.
- We can only hand over what we hold, which is the list in clause 2. There is no identity document to produce because we never asked for one — and that is precisely why we do not ask.
- We cannot produce what is on your disks. We have no login inside your machine. What can be compelled is the hardware itself, which is the point clause 4 makes about encryption.
- We tell you, unless we are forbidden to. If a request comes with a gag we comply with it. If it does not, we tell you what was asked and by whom.
9. Your rights
Depending on where you live, you may have the right to ask what we hold about you, to correct it, to have it deleted, or to receive a copy. Write to us and we will answer.
Two practical notes. First, since we hold so little, the answer is usually the list in clause 2 filled in with your own values, and it arrives quickly. Second, we cannot delete an invoice that tax law requires us to keep, and we will say so plainly rather than pretend otherwise.
Because we do not verify identity, we cannot verify a request either. We answer through the contact handle already on the account — which protects you from someone else asking about you, and means that losing access to that handle also means losing the ability to ask.
Related pages
- Terms of serviceThe contract between you and gpuserver.io: what we provide, what you pay, how a term ends, refunds, suspension, liability — written to be read, not skimmed.
- Acceptable useWhat you may and may not run on a gpuserver.io machine, what is explicitly allowed, what to ask about first, and the procedure when a machine crosses the line.
- Report abuseWhat is prohibited on gpuserver.io, how to report something coming from one of our addresses, what we do with a report, and how long each step takes.
- About usWho runs gpuserver.io, why we buy the hardware instead of reselling it, and the four rules we do not bend — including the ones that cost us sales.