GDPR Compliance
Rubuz manages your servers without taking your data. Your applications, databases and backups stay on hardware and storage you control. We keep only what running your account needs.
What Rubuz keeps
- Your account: name, email, and a one-way hash of your password.
- Your servers: address, SSH port and user, operating system, host key.
- Access keys: one SSH key per server, encrypted before it is stored.
- Settings and metrics: apps, domains, schedules, CPU and disk readings, an activity log.
- Billing: your plan and country. Card details go to our payment provider, never to us.
What stays on your servers
- Your applications and their files and uploads.
- Your databases and everything in them.
- Your apps' secrets: the values of their environment variables.
- Your backups, written from your server straight to storage you choose.
- Your visitors' data. Rubuz never sees the traffic to your sites.
Privacy by design
Data minimisation
We collect what running your account needs, and nothing to sell or profile.
Encrypted access
Server keys are sealed with AES-GCM. Passwords are Argon2id hashes.
No agent
Plain SSH. Remove Rubuz's key and access ends; your apps keep running.
Your storage
Backups go to your own S3-compatible bucket. We can't read them.
Our role
For your account, Rubuz LLC is the controller of the data above. When you manage servers that hold your customers' personal data, you are the controller of that data and Rubuz acts only on your instructions, as a processor, for the tasks you set up.
Why we process it
- To provide the service you signed up for (performance of a contract).
- To keep accounts secure: sign-in records and abuse limits (legitimate interest).
- To meet tax and accounting law for payments (legal obligation).
We do not sell personal data, and we do not use it for advertising. Our website analytics are cookieless and keep no personal data.
Where your data lives
Rubuz runs in Frankfurt, Germany, inside the EU. That is where your account data is processed.
A few carefully chosen providers help us run the service, each only for its one job:
- Hosting and database for the Rubuz service itself.
- Network and security: encryption in transit and protection against attacks.
- Email delivery for account and security emails.
- Payments, handled by our merchant of record. We never see card details.
- Sign-in with Google or GitHub, only if you choose it.
Each is bound by a data processing agreement, and transfers outside the EU are covered by Standard Contractual Clauses. Business customers get the full list of sub-processors with our DPA, and we tell them before adding a new one.
Your rights
Email us and we answer within 30 days.
Retention
We keep your data while your account exists. Removing a server deletes its key and records. Deleting your account deletes its data; billing records are kept only as long as tax law requires.
Need a Data Processing Agreement?
We sign a DPA with any business customer, including the Standard Contractual Clauses. Write to us and we'll send it over.
Read the full Privacy Policy. Last updated 26 September 2026.