Privacy Policy

Draft for review.

This Privacy Policy explains how Ionify Cloud collects, uses, and protects account, project, and operational data when customers use the dashboard, APIs, and onboarding flows.

1. What We Collect

  • Account data:
    • name
    • email address
    • authentication provider
    • workspace ownership and membership data
  • Product data:
    • workspace, org, project, namespace, manifest, and token metadata
    • usage and quota telemetry needed to operate the service
  • Support and security data:
    • login events
    • audit activity
    • abuse prevention and incident investigation records

2. OAuth Providers

If you sign in with Google or GitHub, Ionify Cloud may receive:

  • your verified email address
  • your public profile name
  • a provider account identifier needed for account linking

We only auto-link identities when the provider confirms that the email address is verified.

3. How We Use Data

We use customer data to:

  • create and secure user accounts
  • provision workspaces and projects
  • enforce quotas, plans, and account permissions
  • support onboarding, recovery, and product operations
  • investigate incidents, fraud, and abuse

4. Payments

Paid plans and payment processing will be integrated later. Until then, payment fields shown during onboarding may be visible in test mode but are not required to complete signup.

5. Security

Ionify Cloud is designed to minimize unnecessary exposure of customer data. We intend to use:

  • short-lived access sessions
  • refresh-token rotation
  • hashed server-side token storage
  • audit trails for sensitive account operations

6. Sharing

We do not sell customer data. We may share data only when necessary with:

  • infrastructure providers
  • authentication providers
  • payment providers once billing is live
  • legal or regulatory authorities when required by law

7. Retention

We retain account, usage, billing, and audit records only as long as reasonably necessary for security, support, legal compliance, and service operations.

8. Your Controls

Customers should be able to:

  • update account details
  • rotate credentials
  • sign out the current session
  • later sign out all devices

9. Contact

For privacy questions, contact Ionify support through the official Ionify Cloud contact channel.

10. Status

This page is a draft prepared for product launch planning and legal review. Final production language should be approved before public launch.