nitro.vn Acceptable use Privacy

Privacy and data retention

Effective 2026-08-05 · nitro.vn / nitrolet.com · preview

What we hold, why, where it lives, and when it goes away. Written from the actual implementation rather than from a template — every claim below corresponds to something in the repository, and where the honest answer is "not yet", it says that.

What we hold about you

whatwhywhere
Email address, password hash, session recordsso you can sign inPostgreSQL on the host in Ho Chi Minh City
Your handle (the part before @, normalised)it is half of every box hostname you ownsame
SSH public keys you register, with a label and the dateso ssh into your box worksa root-only file on the host
Box records: name, owner, IP, public/private, created-atto run and route your boxesa root-only file on the host
Volume records: name, size, which box it is attached toto attach your diskssame
Invite redemption: which code, which email, whenso we know how each account came to exista root-only file on the host
Server logs: request path, status, source IP, timestampsto run the service and investigate abusethe host's journal

We do not hold your password (only a hash), your SSH private key (we never see it), payment details (there is nothing to pay), or any analytics, advertising or third-party tracking. The landing page and the dashboard load no third-party scripts and set no cookies other than your session.

What is inside your box

Your box's contents are yours and we do not read them. In practice:

Who else sees it

Where it lives

Ho Chi Minh City, Vietnam — one machine, plus CloudFly object storage in the same country for volume data and backups. Nothing is replicated to another region. If you are subject to a rule about where your data may reside, this is the fact you need.

How long we keep it

whatretained
A box you deletedestroyed immediately, along with its disk and its snapshots
A volume you deletethe record goes immediately; the stored chunks are collected by the hourly GC, which keeps the last 5 generations
Server logsthe host journal's rotation, currently a few weeks
Encrypted service backups14 rolling hourly copies, then deleted
Your account, after you ask us to delete itremoved within 30 days, including SSH keys, box and volume records
Invite redemption recordskept while the account exists — it is the only record of how an account came to be

⚠️ A backup can outlive a deletion by up to 14 hours. If you delete your account, it disappears from the service immediately and from the newest backup within an hour, but older encrypted copies still contain it until they rotate out. Saying "deleted everywhere instantly" would be false.

Your choices

Security

TLS everywhere with HSTS, private-by-default sandboxes, ownership checks on every action, short-lived tokens with revocation, encrypted snapshots and volumes, SSH key-only host access, and per-account quotas. The full engineering detail is public in the repository, including the parts that are not finished.

Breach: if we believe your data has been exposed, we will email you within 72 hours of establishing that, with what happened and what to do. We would rather send an early, incomplete notice than a late, tidy one.

Contact

Changes

Posted here with a new effective date. A change that materially widens what we collect or how long we keep it will be emailed to account holders before it takes effect.