Privacy Policy
The short version: an email address is the only identity we ask for, we never see your card or your server's contents, our analytics are cookieless, and nothing is sold to anyone. Last updated 10 August 2026.
1. Who is responsible for your data
Nocthost OÜ (registry code 17569744), registered in Estonia, operates NoctHost and is the data controller for the personal data described here.
For any privacy question, or to exercise the rights listed in section 7, write to [email protected].
2. What we collect
Account: your email address, and a hash of your password (never the password itself). If you sign in with Google, we store the account identifier Google returns instead of a password. That is the whole account record — we do not ask for your name, postal address, phone number or any identity document.
Payments: crypto payments are handled by our payment processor, so we never see or store card numbers or wallet credentials. We keep the amount, the coin, the processor's payment reference, and the country your connection resolved to at the moment you created the payment. That country comes from a header our CDN adds; we keep it because an invoice has to state it and because EU VAT rules for digital services depend on it.
Servers: the label you give a server, its region, plan, operating system and the IPv4 address assigned to it. We do not access, monitor or copy what you run or store on your servers.
Support: the messages you send us and any images you attach, kept with your account so the conversation has history.
Security and abuse: request logs that include IP addresses, and the same addresses used for rate limiting. These let us block attacks and answer abuse reports that identify a server by its address and a timestamp.
Analytics: our own, and cookieless. A random identifier is stored in your browser to tell one visit from another — it is not tied to your identity and carries no personal data. With it we record the page path, the referring site, campaign parameters if a link had them, and whether you are on desktop or mobile. There are no third-party analytics or advertising trackers on this site.
3. What we do not collect
No identity documents, no selfies, no phone numbers, no home addresses, no card details. There is no identity verification step in signing up or using the service; see our terms for the narrow cases where the law or our providers could require one.
No advertising cookies, no cross-site tracking, no data sold or shared with advertisers or data brokers. Ever.
4. Why we are allowed to process it
To provide the service you signed up for — running your account, deploying your servers, billing your balance. That is performance of our contract with you.
To meet legal obligations — issuing invoices, keeping accounting records, and complying with sanctions rules.
For our legitimate interests — keeping the platform secure, preventing abuse, and answering abuse reports from our upstream providers.
With your consent — product and marketing emails only. You give that consent with a checkbox when you register and can withdraw it from any such email or by writing to us. Transactional messages (password resets, support replies, billing notices) are not marketing and are sent regardless.
5. Who else sees it
The cloud provider your server runs on — Vultr, DigitalOcean, Hetzner or Linode, depending on what you chose. They receive what is needed to create and run the instance, and they operate their own infrastructure worldwide.
Our payment processor, which handles the crypto payment and returns its status to us.
Our email provider, which delivers transactional and (if you consented) marketing messages.
Our CDN and DNS provider, which sits in front of the site, filters attacks and supplies the country signal described in section 2.
Google, only if you choose to sign in with Google.
Law enforcement or an upstream provider, where we are legally required to respond or where an abuse report identifies a specific server. We respond to specific, documented requests — not to blanket ones.
Because servers and providers are located worldwide, data may be processed outside the European Economic Area.
6. How long we keep it
Account data: while your account exists. Ask us to delete it and we remove it, except records we are legally required to keep.
Analytics events: 90 days, after which they are deleted automatically.
Snapshots of servers archived at a zero balance: 7 days, then removed with the rest of the server.
Invoices and accounting records: for the period Estonian accounting law requires, which is longer than the rest and outside our discretion.
7. Your rights
Under the GDPR you can ask us for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict or stop certain processing, and ask for it in a portable form. Write to us and we will act on it.
You can withdraw marketing consent at any time without affecting anything else.
If you think we have handled your data badly, you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or to the supervisory authority where you live.
8. Changes
This policy was last updated on 10 August 2026. If we change what we collect or who we share it with, we update this page; material changes are announced to account holders by email.
See also our Terms of Service and Acceptable Use Policy.