Privacy Policy
Last Updated: September 25, 2026
1. Information We Collect
Castlehat collects the following types of information:
- Authentication Data: GitHub OAuth tokens and user profile information (username, email)
- Usage Data: VM session logs, file upload records, and system performance metrics
- Technical Data: IP addresses, browser information, and device identifiers
2. How We Use Your Information
We use your information to:
- Provide and maintain our VM sandbox service
- Authenticate users and manage access permissions
- Monitor system performance and security
- Improve our services and develop new features
- Communicate with you about service updates and security alerts
3. Data Storage and Security
We implement industry-standard security measures to protect your data:
- All data is encrypted in transit using HTTPS/TLS
- Authentication tokens are stored securely using industry best practices
- Regular security audits and penetration testing
- Isolated VM environments ensure user data remains compartmentalized
4. File Upload and Storage
When you upload files through our service:
- Files are processed through Uploadcare's secure CDN infrastructure
- File metadata and access tokens are stored in our database
- You retain ownership of your uploaded content
- Files are automatically deleted according to our data retention policies
5. Third-Party Services
We use the following third-party services:
- Supabase: Authentication, database, and real-time services
- Uploadcare: File upload and CDN delivery services
- GitHub: OAuth authentication provider
These services have their own privacy policies which we encourage you to review.
6. Data Retention
We retain user data for the following periods:
- Authentication Data: Retained while your account is active
- Session Data: Retained for 30 days after session completion
- Uploaded Files: Retained for 90 days from upload date unless deleted earlier
- System Logs: Retained for 90 days for security and debugging purposes
7. Your Rights
You have the right to:
- Access your personal data
- Request deletion of your account and associated data
- Export your data in a machine-readable format
- Opt out of non-essential data processing
- Update your account information and preferences
8. Cookies and Tracking
We use cookies and similar technologies to:
- Maintain your authentication session
- Remember your preferences
- Analyze service usage and performance
You can manage cookie preferences through your browser settings.
9. Children's Privacy
Castlehat is not intended for use by children under the age of 18. We do not knowingly collect personal information from children.
10. International Data Transfers
Your data may be transferred to and processed in countries other than your own. We ensure adequate protection of your data in accordance with applicable data protection laws.
11. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of significant changes by posting the new policy on our website and updating the "Last Updated" date.
12. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us through our GitHub repository or other official communication channels.