Legal
Privacy Policy
What we collect, what we deliberately do not collect, how long we keep it, and what you can ask us to do with it.
Effective date: 5 September 2026
01The short version
We collect what is needed to run your account and your applications, and nothing else. We do not sell your data. We do not read the applications you deploy. We do not use your code or your data to train machine learning models.
The rest of this document is the detail behind those four sentences.
02Who we are
Pulsara LLC operates SmolClouds, a platform for deploying and running small applications. In this document "we" and "SmolClouds" mean that company, and "you" means the person or organisation using the service.
Pulsara LLC is incorporated in the State of Wyoming, United States. Registered address: 30 N Gould St, Ste N, Sheridan, WY 82801, Sheridan County, United States. State filing number: 2026-002000332.
Where the GDPR or the UK GDPR applies, we are the controller of the account data described below.
Privacy questions: privacy@smolclouds.com. Security reports: security@smolclouds.com.
03Two kinds of data
The distinction runs through this whole document, so it is worth stating first.
- Account data — we are the controller
- Who you are, what plan you are on, which applications exist, and how much of your allowance you have used. We decide how this is handled, and this policy governs it.
- Customer content — we are the processor
- Your source code, your environment variables, and whatever data your applications hold or emit. You decide what goes in it. We process it only to run your applications, on your instructions. Our data processing agreement governs it.
04What we collect
- Account data
- When you sign in with GitHub or Google we receive your name, email address and profile picture from that provider. We never receive your password for either service.
- Repository access
- If you connect a repository, we receive the access scope you grant and the source needed to build your application. We do not read repositories you have not connected.
- Application and platform data
- Deployment metadata, build output, application logs, request counts, active runtime, storage and bandwidth used, and the environment variables and secrets you choose to store.
- Support communication
- Messages you send us, and our replies.
05What we do not collect
Stating this plainly is more useful than a longer list of what we do collect.
- We do not ask for a payment card on the Free plan
- We do not collect special category data — health, biometrics, political or religious views, or anything similar
- We do not buy personal data from data brokers, and we do not enrich your profile from third-party sources
- We do not track you across other websites, and we run no advertising or profiling trackers
- We do not sell or rent personal data to anyone, under any definition of sale, including the broad one in California law
06We do not read your applications
The contents of your deployed applications, your source code, your environment variables and your secrets are yours. Our staff do not access them in the ordinary course of running the platform.
There are three narrow exceptions, and each one is deliberate: when you ask us to, in order to resolve a support request; when we must, to investigate a security incident or a violation of the acceptable use policy; and when the law compels us.
We do not use your code, your data or your applications to train machine learning models, and we do not let anyone else do so.
07How we use your data
We also derive aggregate, non-identifying statistics about how the platform performs — how long applications take to wake, how much memory is shared between them — and use them to improve it. These cannot be traced back to you or to any individual.
- To create and operate your account and workspace
- To build, deploy, route and run the applications you deploy
- To measure usage against your plan's allowances and to bill you
- To detect abuse, runaway automation and security incidents
- To answer your support requests
- To send service messages about incidents, changes and billing
08Legal bases
Where the GDPR or UK GDPR applies, we rely on the following.
- Performance of a contract
- Running your account and your applications, and billing you for them.
- Legitimate interests
- Securing the platform, preventing abuse, and improving the service — balanced against your rights, and never in a way you would not expect.
- Legal obligation
- Tax, accounting and lawful requests from authorities.
- Consent
- Anything optional, such as product email. You can withdraw it at any time without affecting the service.
11How long we keep it
- Account data
- For as long as your account exists, and for a short period afterwards so the account can be recovered if you change your mind.
- Application logs
- According to your plan's retention window — 1 day on Free, up to 60 days on Team, custom on Scale. Logs are deleted when the window passes.
- Deployed applications and their data
- Until you delete the application, or your account is closed.
- Backups
- Deleted on their ordinary rotation after the primary data is deleted.
- Billing records
- For the period required by tax and accounting law in our jurisdiction.
12International transfers
You choose the region an application is deployed to, and its application data stays in that region. Applications on Hetzner run in Germany or Finland; applications on Oracle Cloud Infrastructure run in the region you select.
We are established in the United States, so account, support and billing data is processed there. Where that involves a transfer of personal data out of the EEA, the UK or Switzerland, it takes place under the appropriate safeguard — the European Commission's Standard Contractual Clauses together with the UK Addendum, plus supplementary measures where they are needed. A copy of the clauses we rely on is available from privacy@smolclouds.com.
13Your rights
Depending on where you live you have some or all of the following rights. To exercise any of them, write to privacy@smolclouds.com from the address on your account. We respond within 30 days, and we do not charge for a reasonable request.
- Access — a copy of the personal data we hold about you
- Rectification — correction of data that is wrong or incomplete
- Erasure — deletion of your data, subject to records we must keep by law
- Portability — your data in a machine-readable format
- Restriction and objection — limiting how we process your data
- Withdrawal of consent — at any time, where processing is based on consent
- No discrimination — exercising a right never changes the service or the price you get
14If you are in California
The categories of personal information we collect are identifiers, commercial information about your subscription, and internet activity relating to your use of the platform. The purposes are described above.
We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined by the CCPA and CPRA. Because we do not, there is nothing to opt out of — but the rights to know, delete, correct and to non-discrimination all apply, and are exercised at the address above.
15Compelled disclosure
If a government or a court compels us to disclose data, we will require a valid legal instrument, disclose no more than that instrument demands, and tell the affected customer before we comply — unless the law forbids us from telling them, in which case we will tell them as soon as we lawfully can.
16US state privacy rights
If you live in California, Colorado, Connecticut, Virginia or another US state with a comprehensive privacy law, you have the right to know what personal information we collect and why, to request a copy of it, to correct it, to delete it, and not to be discriminated against for exercising any of those rights. Some states also give you the right to appeal a decision we make on your request.
We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it for targeted advertising or for profiling that produces legal or similarly significant effects. We collect no sensitive personal information beyond what an account requires.
To exercise a right, or to appeal, write to privacy@smolclouds.com from the address on your account. You may use an authorised agent; we will ask for proof of authorisation. If we deny an appeal you may complain to your state attorney general.
17Security
Applications run in isolated Firecracker microVMs with their own guest kernels and network namespaces, secrets are encrypted at rest, and traffic is served over TLS. Our security page describes the isolation model in more detail and gives our security contact.
No system is perfectly secure. If we become aware of a breach affecting your personal data we will notify you and the relevant supervisory authority within the period the law requires, with the information you need to meet your own obligations.
18Complaints
If you are unhappy with how we have handled your data, write to privacy@smolclouds.com and we will respond within 30 days. If our answer does not satisfy you, you can complain to your local data protection authority — and we would rather you did that than stayed unhappy.
19Children
SmolClouds is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child has given us personal data, write to us and we will delete it.
20Changes to this policy
We update this document when the way we handle data changes. If a change is material we tell account owners by email before it takes effect, and the effective date at the top changes. We do not make a material change quietly.
Questions about this document: legal@smolclouds.com
Security reports go to our security page.