Overview
Rubuz is a server management and deployment platform run from the web. You connect servers that you own or rent, and Rubuz manages them over SSH. Your applications, their files and their databases run on your servers, not on ours.
Data we collect
- Account data: your name, email address, and a one-way hash of your password (never the password itself), plus the same for people you invite to your account.
- Server data: the address, SSH port and user of each server you connect, its operating system, and the host key it presented when you connected it.
- Server access keys: an SSH key made for each server you connect. Its private half is encrypted before it is stored, and is never shown to anyone.
- Operational data: the apps, domains, backup schedules and settings you configure; resource metrics (CPU, memory, disk, network) read from your servers; and a log of actions taken in your account.
- Integration credentials: credentials you provide for services such as S3-compatible storage or GitHub, used only to do what you set them up for.
- Usage and security data: sign-in times, IP addresses and device information, used to keep your account secure.
- Where you came from: the country your sign-up came from, the campaign or site that referred you, and the country you give our payment provider when you pay.
- Contact data: your name, email and message when you write to us.
What stays on your servers
Your application files, databases, uploads and the values of your apps’ environment variables live on your servers. Rubuz reads them over SSH when you ask it to act on them and does not keep a copy. Backups are written from your server to the storage you choose.
How we use server access
We use the SSH key for a server only to carry out what you ask for and the tasks you have set up, such as deployments, backups, updates and resource monitoring. You can withdraw that access at any time by removing the server from Rubuz or by deleting Rubuz’s key from the server’s authorized_keys. Your apps keep running either way.
How we use your data
We use your data only to:
- Provide and operate the Rubuz service for your account.
- Send you account and security emails, such as password reset links.
- Answer your questions and support requests.
- Keep the platform secure.
- Understand which channels bring people to Rubuz.
We do not sell your data, and we do not use it for advertising.
Cookies
The Rubuz panel uses a sign-in cookie to keep you signed in, and a cookie that remembers, for 30 days, which campaign or site first brought you to the sign-up page. Neither follows you to other sites. The rubuz.com website uses cookieless analytics that keep no personal data.
Service providers
We rely on a small number of providers to run Rubuz: hosting and a managed database, network and security services, email delivery, and a merchant of record for payments. They process data only on our behalf and only as needed to provide the service. See GDPR Compliance for where your data is processed.
Payments
Payments are handled by our merchant of record. Card details go to them directly and are never stored by Rubuz.
Data security
Traffic to Rubuz is encrypted, passwords are stored only as hashes, and server access keys are encrypted at rest. Accounts can use two-factor authentication and passkeys.
Retention and deletion
We keep your data for as long as your account exists. When you remove a server, its access key and records are deleted. When you ask us to delete your account, its data is deleted with it; billing records are kept only as long as tax law requires.
Your rights
You can access, correct, export and delete your personal data, and object to or restrict how we use it. You can also complain to your data protection authority. See GDPR Compliance for details. To use any of these rights, email us.
Contact us
Questions about this policy: [email protected].