Privacy Policy
Last updated: August 1, 2026
Privacy is the product. People rent machines from Locally precisely so their AI workloads and data stay under their own control, so this policy is written to be read, not skimmed. Short version: we collect the minimum needed to bill you and keep the platform healthy, we never inspect what you run, and we never sell data.
1.What we collect
- Account data: name, email, password hash, and optionally a 2FA secret.
- Billing data: invoices, payment method type and transaction references. Card numbers are handled by our payment processor and never touch our servers. Crypto payments record only the transaction hash and sending address.
- Service metadata: which plans you have, their region, IP assignments, power state, and hypervisor-level metrics (CPU %, RAM %, bandwidth volume, hardware health).
- Support data: tickets and emails you send us.
- Panel logs: login timestamps, IP of login, and actions taken in the control panel, kept for security auditing.
2.What we deliberately do not collect
- We do not read, scan or index the contents of your server's disk, memory or snapshots.
- We do not inspect the content of your network traffic. Bandwidth is measured by volume only.
- We do not log DNS queries from your servers.
- We do not use tracking pixels or third-party advertising trackers on locally.host.
3.How we use data
- Provisioning and operating your Services.
- Billing, invoicing and fraud prevention.
- Support and service communications (renewal reminders, incident notices, maintenance windows).
- Aggregate, anonymized platform statistics (for example, overall regional load) that cannot identify you.
We send marketing email only if you opt in, and every such email has a one-click unsubscribe.
4.Sharing
We share data only with: (a) payment processors, to process your payment; (b) datacenter partners, limited to what is technically necessary to route your traffic; and (c) authorities, when we receive a legally valid and binding order, in which case we disclose the minimum required and notify you unless legally barred from doing so. We have never sold personal data and never will.
5.Retention
- Server contents: destroyed within 7 days of service termination.
- Account and billing records: kept while your account exists and thereafter as required by tax and accounting law.
- Panel security logs: 12 months.
- Support tickets: 24 months.
6.Security
All panel and API traffic is TLS-encrypted. Passwords are stored as modern salted hashes. Internal access to customer metadata is role-restricted and audited. Optional full-disk encryption is available as a one-click template feature on VPS and GPU plans, with keys that only you hold.
7.Your rights
You can access, correct, export or delete your personal data at any time from the panel or by emailing privacy@locally.host. Deleting your account removes personal data within 30 days except records we must keep by law. If you believe we have mishandled your data, contact us first; you also have the right to complain to your local data protection authority.
8.Cookies
locally.host uses only functional cookies: your session, your language preference and your theme. No advertising or cross-site tracking cookies exist on this site, which is why there is no cookie banner.
9.Changes
Material changes to this policy are announced by email at least 14 days in advance. The "last updated" date at the top always reflects the current version.