← Back

Privacy Policy

Last updated 10 August 2026

This explains what [LEGAL_ENTITY_NAME]("BlizzStudios") collects when you use 1ClickOps, why, and who else can see it. It is written to be read rather than skimmed.

The short version: your source code, your database contents and your backups stay on your own server. We store the information needed to manage those servers for you — including some things that can contain secrets, which are listed explicitly below.

What we store

Your account. Your email address, display name and profile picture, as provided by whichever sign-in method you use, plus which workspaces you belong to and your role in them.

Access tokens for your git provider. When you connect GitHub, GitLab or Bitbucket, we store an access token so we can register deploy keys and set up webhooks for you. These are encrypted at restand used only server-side. Your browser never receives them.

Your servers. Name, IP addresses, operating system, agent version, when it last checked in, and its routing configuration.

Your applications. Name, type, status, public address, and the generated configuration used to run them. Configuration files and environment variables are encrypted at rest.

Operational records. Deployment history, scheduled jobs and the commands they run, resource usage samples (processor and memory, kept 48 hours), outage records, and a record of each backup — its filename, size and whether it succeeded.

Command output, which can contain secrets

To show you what happened during a deployment, we store the output of the commands the agent runs — build logs and error messages. That output is whatever your application prints. If your build prints an API key, a connection string or a token, it will be stored here.

This is worth knowing when you decide what to log. We do not inspect this output, and it is only visible to members of your workspace, but we would rather tell you than let you discover it.

What we never store

Your source code. It is cloned directly from your git provider onto your server. It never passes through us.

Your database contents. We never connect to your databases. Backups are produced by the agent inside the database container, using credentials that live on your server. Those credentials are never sent to us and never appear in an instruction.

Your backups. They are written to your server, and to your own storage bucket if you configure one. We keep only the index described above.

Deploy key private halves. Generated on your server; only the public half is ever sent anywhere.

Passwords. There are none. Sign-in is delegated to your provider or an emailed link.

Why we store it

To provide the service you asked for (performing our contract with you), to keep it secure and detect abuse, and to comply with the law. We do not sell your information, and we do not use it for advertising or to train machine-learning models.

Who else processes it

We use a small number of providers to run 1ClickOps. Each sees only what it needs:

  • Vercel — hosts the dashboard and API.
  • Neon — the database holding everything described above.
  • Resend — sends sign-in links, invitations and outage alerts. Sees your email address.
  • Cloudflare — DNS and secure tunnels, where you use them. Sees your applications' addresses.
  • Let's Encrypt — issues certificates for custom domains. Sees the domain name.
  • GitHub, Google, GitLab, Bitbucket — whichever you sign in with.

If you configure off-site backups, your backups go directly from your server to the storage provider you chose, using your credentials. That relationship is between you and them; we are not involved.

Where it is stored

Our providers operate internationally, so your information may be processed outside India. We rely on those providers' contractual safeguards for such transfers.

How long we keep it

Account and infrastructure records are kept while your account is open. Resource usage samples are deleted after 48 hours. Deployment and command records are kept while the related application exists. When you delete your account we delete or anonymise your data within 30 days, except where we must keep something to comply with the law.

Deleting your account does not delete anything on your own servers. That remains yours to remove.

Your rights

You can ask us for a copy of your information, to correct it, to delete it, or to restrict how we use it. If you are in India, these rights arise under the Digital Personal Data Protection Act, 2023; if you are in the UK or EU, under the UK GDPR or GDPR. Email [SUPPORT_EMAIL] and we will respond within 30 days. You may also complain to your data protection authority.

Security

Access tokens, environment variables and application configuration are encrypted at rest. Session tokens are stored hashed. Every instruction sent to an agent is cryptographically signed and verified before it runs, and agent updates are signed with a key held offline rather than on our servers.

If we become aware of a breach affecting your information, we will notify you and the relevant authority as the law requires.

Children

1ClickOps is not intended for anyone under 18, and we do not knowingly collect their information.

Changes

If we change this policy materially we will notify you by email or in the dashboard before the change takes effect.

Contact

[LEGAL_ENTITY_NAME], [REGISTERED_ADDRESS].
Email [SUPPORT_EMAIL].

Questions about this page? Email [SUPPORT_EMAIL].