Privacy

Privacy Policy

How DunOps handles personal and workspace data - written so you can actually read it.

Last updated · April 2026

Information we process

Your account info, the DNS/cloud data you connect, and the boring usage logs that keep the service running.

  • Account data: name, email, and authentication identifiers from your identity provider (Google, GitHub, etc.).
  • Workspace data: DNS records, domain names, deployment metadata, provider connections, chat messages, and workflow state that you create or import into the Service.
  • Technical data: request logs, error traces, and aggregate usage metrics needed to operate, debug, and secure the Service.
  • Billing data: processed by our payment provider — we never see your raw card details.

How we use information

To run the product, sync your providers when you ask, send you account emails, and stop bad actors. That's the list.

We use this information to provide the Service, authenticate users, sync with third-party providers you connect, send transactional communications, enforce security, and comply with law. We do not use your workspace data to train AI models — the agent reads your records on demand to answer your questions and proposes changes you explicitly approve.

Sharing

We don't sell your data. We share with the providers you connect (because you asked us to) and a small list of subprocessors.

We do not sell your personal information. We use a small list of subprocessors for hosting, payments, and email delivery. When you connect a provider (Cloudflare, Vercel, Azure, etc.), we exchange data with that provider under your authorization and the scope you grant.

Retention

We keep your data while your account is active. Delete your workspace and most of it goes within 30 days; backups age out within 90.

We retain workspace data while your account is active and as needed for backups, security investigations, and legal obligations. You may request account deletion at any time — production data is removed within 30 days, encrypted backups age out within 90 days.

Your rights

You can ask to see, fix, export, or delete your data. We'll respond within 30 days.

Depending on your region (GDPR, CCPA, and similar), you may have rights to access, correct, export, or delete personal data. Contact us through in-app support or your workspace admin and we'll respond within 30 days.

Security

Encrypted in transit and at rest. Provider credentials are stored encrypted with per-workspace scoping.

We encrypt data in transit (TLS) and at rest. Provider credentials and OAuth tokens are stored encrypted and scoped to a single workspace. For full details see the Security overview.

Changes to this policy

We update this when something meaningful changes — see the log below.

We may update this policy from time to time. Material changes will be announced via in-app notice or email. The change history below tracks every meaningful edit.

Changes log

A short history of meaningful edits to this document.

  • 2026-04-02Clarified that workspace data is not used for AI model training.
  • 2026-02-15Added subprocessor list reference and DPA process.
  • 2025-11-08Initial publication.