Legal
Privacy
Last updated: 21 July 2026 · Applies to Sistemo Cloud (sistemo.io, cloud.sistemo.io, api.sistemo.io)
Who we are
Sistemo Cloud is a prepaid microVM sandbox service. This notice describes what we collect and why. For product questions use the dashboard or email [email protected].
What we collect
- Waitlist: if you request an invite, the email address you give us and the optional note about what you're building. We keep nothing else — no IP address, no browser details. The basis is your consent, we use it only to email you when the cloud opens, we never share or sell it, and you can have it erased at any time by emailing us (a real delete, not a flag).
- Account: email, display name, auth provider data (e.g. GitHub/Google if you use OAuth), password hash if you use email/password.
- Billing: wallet balance, top-up history, usage aggregates. Card details are handled by Stripe — we do not store full card numbers.
- Product use: machines/volumes/snapshots metadata, API key prefixes (not full secrets after creation), activity such as create/stop/exec events (action, actor, timestamps — not your script text or command output by default).
- Technical: IP address, user agent, request IDs, and operational logs needed to run and secure the service.
What we process when you run code
To provide exec and terminal features, your commands and their output transit our control plane and hosts so we can return results to you. We do not use that content to train models, and we do not treat full script/output bodies as a durable audit archive. Operational logs may briefly include diagnostics; we aim to keep retention short and access limited to running the service.
Why we process data
- Provide and secure the cloud service (contract / legitimate interest).
- Bill prepaid usage and prevent abuse (contract / legitimate interest).
- Respond to support and legal requests where required.
Where data lives
Sistemo Cloud infrastructure is operated in the EU. Subprocessors (e.g. Stripe for payments, email delivery) may process limited data under their own terms; we use them only to run the product.
Retention
Account and billing records are kept while your account exists and as needed for accounting/legal obligations. Resource and activity metadata may be retained for operations and abuse prevention. If your balance stays at €0 past the published grace window, we may delete associated compute resources after notice — see pricing.
Waitlist entries are deleted as soon as they have served their purpose: when you create an account and confirm your email, or when you delete your account, or on request. Consent to be emailed once when the cloud opens does not outlive that, so an entry we have not invited is deleted no later than 12 months after you asked.
Your rights (EEA/UK)
You may request access, correction, deletion, or export of account personal data, and object to certain processing, subject to legal limits. Contact [email protected]. You can also close your account from the dashboard where available.
Cookies & analytics
We use essential cookies/local storage for session and theme. If product analytics (e.g. Matomo) is enabled, it is configured without marketing cookies where possible (cookie-less / privacy-friendly tracking).
Changes
We may update this notice as the product matures. Material changes will be reflected by the “Last updated” date on this page.