The Deployer
Product How it works Security Pricing Docs
Sign in Check a repo Start free ▸
Check a repo Product How it works Security Pricing Docs
Sign in Start free

Legal

Privacy Policy

Effective 19 September 2026 · Last updated 19 September 2026 · Privacy contact hello@thedploy.com

What we collect when you use The Deployer, why we need it, who else handles it, how long we keep it, and how to ask us for a copy or to delete it.

On this page

  1. The short version
  2. 1. Who operates the service
  3. 2. When we are controller and when we are processor
  4. 3. What we collect
  5. 4. How we use it
  6. 5. AI processing
  7. 6. The public repository check
  8. 7. Businesses we contact
  9. 8. Subprocessors and other recipients
  10. 9. International transfers
  11. 10. How long we keep it
  12. 11. Browser storage
  13. 12. Your rights
  14. 13. Security
  15. 14. Children
  16. 15. Changes to this policy
  17. 16. Contact

The short version

  • We collect what we need to deploy and run your apps: your account details, the repositories and cloud accounts you connect, and records of what we did.
  • Your cloud and code-host credentials are encrypted before they are stored. They are not placed in AI prompts.
  • We use OpenAI to analyse code, logs and chat messages. We do not sell your data, and we do not use advertising trackers.
  • Results of the free public repository check can be seen by anyone who has the link.
  • You can ask us to see, correct or delete your data by writing to hello@thedploy.com.

1. Who operates the service

The Deployer ("The Deployer", "we", "us") is a deployment service operated from India.

This policy covers thedploy.com, the app at app.thedploy.com and portal.thedploy.com, our documentation, the free public repository check, and the services we sell, including Launch and Move.

Privacy contact: hello@thedploy.com.

2. When we are controller and when we are processor

We act as a controller for information used to run your The Deployer account, bill you, secure the service, communicate with you, and understand how the service is used.

For repository content, deployment logs, configuration and other data you submit so we can carry out deployment work on your instructions, our legal role may depend on the context. We do not publish a standard Data Processing Addendum yet. Business customers who need processor terms can write to hello@thedploy.com.

Your deployed application runs in your cloud account. We do not become the controller of your application's end-user data just because we created or manage the infrastructure it runs on. If deployment logs or troubleshooting data contain personal data, we may still process that data as described in this policy.

3. What we collect

We list only what we actually collect today.

CategoryExamplesWhy we collect it
AccountName, email address, account ID, answers you choose to give (such as how you heard about us)To run your account
AuthenticationA salted hash of your password (never the password itself), your sign-in session, email verification and password-reset recordsTo sign you in and keep your account secure
API keysThe name you give each key, when it was created and last used, and a one-way hash of the key (we do not store the key itself)To let tools such as our MCP server act on your account
Code-host connectionAccess tokens for GitHub, GitLab or Bitbucket, encrypted before storage, and your username on that hostTo read repositories you choose and commit deploy-readiness changes you approve
Cloud connectionCredentials for AWS, Google Cloud, Microsoft Azure or DigitalOcean, encrypted before storage, and account or project identifiersTo create and manage resources in the cloud account you connect
RepositoryA working copy of the repositories you connect, repository metadata and commit IDsTo analyse your app, propose an architecture and deploy it
Application configurationEnvironment variable names, secret values (encrypted before storage), domain namesTo deploy and run your app
Deployment recordsThe architecture you chose, the steps we ran and their logs, resource IDs in your cloud account, health checks on your appTo carry out and operate deployments and show you what happened
Activity logSecurity-relevant actions on your account, such as revealing or replacing a credentialSecurity and investigating problems
Product usageMilestones such as signing up, connecting a cloud account, starting a scan and your first live deployment; IP address and basic request detailsTo see where people get stuck, for rate limiting and to prevent abuse
AttributionThe website that referred you and campaign tags (UTM parameters) in the link you followed, recorded when you sign upTo understand which channels bring people to us
BillingYour plan, orders, amounts, payment status and tax details. Card and bank details go to our payment processor; we do not receive your full card numberTo take payment and keep records required by tax and accounting law
OrdersFor Launch and Move, what you enter in the order form, such as the repository and cloud provider, and for Move, your current database's connection string (encrypted)To deliver the order
Support and messagesWhat you send through the contact form or by email, bug reports, and your conversations with the in-app assistantsTo answer you and provide the assistant
Email choicesEach time you turn a kind of email on or off: when, where in the app, and the words you were shownTo send only the email you agreed to, and prove it
Public repository checkThe repository URL, the result, masked previews of possible committed credentials, a salted hash of your IP addressTo provide the free check (see section 6)
Business contactsPublished company contact addresses and the evidence for them (see section 7)Business-to-business outreach

4. How we use it

  • To provide the service: scanning, planning, deploying, monitoring, the assistants, and delivering Launch and Move orders.
  • To keep things secure: authentication, rate limiting, abuse prevention and audit records.
  • To bill you and keep records that tax and accounting law requires.
  • To email you about your account: verification, password resets, deployment results, receipts and important changes. You cannot turn these off while you have an account, because the service depends on them.
  • To email you about your projects, such as what a scan found or why a deployment failed. These are on when you sign up (the sign-up form says so, and you can untick them there), and every one has a one-click unsubscribe link.
  • To send offers and plan news, only if you tick the box for them when you sign up or turn them on later on your Profile page. Every one has a one-click unsubscribe link.
  • To improve The Deployer: we keep records of deployment failures and the fixes that worked, with secrets and identifying details removed, and use them to make later deployments more reliable.

If you are in the European Economic Area or the United Kingdom, the legal basis depends on the purpose: performing our contract with you (running your account and deployments), legitimate interests (security, abuse prevention and limited product analytics), consent (optional marketing email), and legal obligation (invoices and tax records).

5. AI processing

The Deployer uses OpenAI API services to help with repository analysis, architecture reasoning, deployment diagnostics, code-change suggestions and in-app chat. We send the information needed for the task, such as file listings, configuration, relevant code, deployment logs and your messages to the assistant.

  • Cloud provider credentials are not placed in AI prompts. Deployment plans refer to them by reference, and the component that uses them to act in your cloud account passes the real values only to your provider.
  • When our environment assistant decides where your settings belong, it sees setting names only, not their values.
  • Application secret values are not intended to be included in prompts. Deployment logs are redacted for secret values we know about before they are shown or analysed, but a log line or file can contain data we do not recognise as secret.
  • The project assistant can run commands on your app's server over SSH when you use it. The output it sees is redacted for known secret values and credential-shaped text, but it may contain other data from your server.

OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer opts in. If we ever opt in to sharing API data for training, we will update this policy and tell you first.

If we add another AI model provider, we will list it on our Subprocessors page before using it.

AI processing may happen outside India. See International transfers and Subprocessors.

6. The public repository check

The free check at thedploy.com/check works without an account. It is intended for public repositories you own or are authorised to analyse.

  • We download the repository you name into a temporary folder, analyse it, and delete the folder when the check ends. Relevant parts may be processed by our AI provider.
  • Results are public to anyone with the link. A result shows the services we found, what is missing and the verdict. Results do not expire today. To have one removed, write to hello@thedploy.com with the link.
  • If the check finds what looks like a committed credential, we keep only a masked preview. It is shown only in the browser that ran the check, and deleted after 7 days.
  • For rate limiting we keep a salted hash of your IP address, not the address itself.

Do not submit a repository you do not want analysed, or one you are not authorised to analyse.

7. Businesses we contact

Where the law allows, we may contact businesses using business contact information they have made public. We use it only for relevant business-to-business outreach, identify ourselves in each message, explain how to opt out, and keep a suppression list so we do not contact anyone who objects. The legal basis and electronic-marketing rules vary by country, and we apply the rules for the recipient's country.

What we do today:

  • We write to companies whose app runs on Heroku, about moving it, using the contact address the company publishes on its own website (such as hello@ or contact@).
  • We do this only for registered companies in the United States, the United Kingdom, France and the Netherlands. We do not use personal addresses, and we do not read a site whose robots.txt asks us not to.
  • We keep the company's domain, the published address and the page we found it on, what shows the company is registered and hosted on Heroku, and the emails we exchange.
  • Every email says where we found the address. Reply "no" or use the unsubscribe link and we will not write to that address or anyone else at the company again.

8. Subprocessors and other recipients

We share data with service providers that help us run The Deployer, with the services you tell us to connect, and where the law requires it. The current list, with what each provider does and where, is on our Subprocessors page. In short:

  • Hosting: Amazon Web Services, where our servers and database run.
  • AI processing: OpenAI, as described in section 5.
  • Email delivery: SendPulse, for account and product emails.
  • Payments: Razorpay, and any other payment processor or reseller shown at checkout.

Your code host and cloud provider receive the requests we make on your behalf. You choose them and have your own agreement with them, so they are not our subprocessors.

We do not sell personal data, and we do not share it with advertisers.

9. International transfers

Our servers and database are in India (Amazon Web Services, Mumbai region). Some of our providers, including our AI and email providers, may process data in other countries such as the United States.

Where the law requires a transfer mechanism, for example for personal data transferred from the European Economic Area or the United Kingdom to a country without an adequacy decision, we will put an appropriate one in place.

10. How long we keep it

These are the periods that actually apply today.

DataHow long
Account data and your email choicesFor as long as you have an account
Repository working copies for your projectsUntil you delete the project
Deployment logs and project recordsUntil you delete the project. There is no automatic expiry today.
Public check: downloaded repositoryDeleted when the check ends
Public check: resultNo expiry today; removed on request
Public check: masked credential previews7 days
Sign-in state for connecting GitHub1 day
Businesses we contactedThe address, the evidence and the emails are deleted a year after our last contact. If you asked us to stop, we keep only your domain and address on a do-not-contact list so we do not write again.
Billing recordsFor as long as tax and accounting law requires
Anonymised deployment learningsKept after a project is deleted, because they no longer identify you or your project

When you ask us to close your account, we delete your personal data unless we must keep part of it by law.

11. Browser storage

We do not use advertising or third-party tracking cookies. The website and app keep these items in your browser's local storage:

  • Your sign-in session token, so you stay signed in. It is kept in local storage, not in a cookie.
  • Interface preferences, such as your theme and whether the sidebar is collapsed.
  • A plan you picked before signing up, so the sign-up page remembers it.
  • Where you first came from: the referring page and campaign tags of your first visit, so we can record them if you sign up. This is for our own measurement, not needed to run the service.
  • The public check keeps a random identifier and a viewer key that lets the browser that ran a check see what it found.

You can clear these at any time in your browser settings. Clearing the session token signs you out.

12. Your rights

Wherever you live, you can ask us to:

  • tell you what personal data we hold about you and give you a copy;
  • correct data that is wrong or incomplete;
  • delete your data and close your account;
  • stop sending you product emails, or withdraw any consent you gave.

Additional statutory rights may apply depending on where you live, for example under the EU or UK GDPR. India's Digital Personal Data Protection Act and Rules are coming into force in phases; the rights they give apply as their provisions take effect.

There is no self-serve account deletion in the app today. Send requests to hello@thedploy.com (or use the contact form) from the email address on your account. We aim to respond within 30 days. If you are not satisfied with our answer, you can complain to your data protection authority.

13. Security

We use technical and organisational measures designed to protect personal data, including encryption of sensitive connection values, access controls, logging of sensitive account actions, and separation between AI analysis and credential use. No internet service can guarantee absolute security. See Security for the current architecture and controls, including their limits.

If we learn of a breach that affects your data, we will tell you and the relevant authorities as the law requires.

14. Children

The Deployer is not meant for anyone under 18, and we do not knowingly collect data from children.

15. Changes to this policy

If we change this policy in a way that matters, we will tell you by email or in the app before the change takes effect. The date at the top shows when it last changed.

16. Contact

Privacy questions and requests: hello@thedploy.com. You can also use the contact form.

Terms of Service Refund Policy Acceptable Use Subprocessors Vulnerability disclosure Contact us
The Deployer

Deploy and operate your app in your own cloud account, without building a DevOps platform yourself.

The Deployer is operated from India.

hello@thedploy.com

Product

Product How it works Cloud providers Migrations Launch Pricing Changelog

Resources

Documentation Free repo check Security Vulnerability disclosure Support Contact

Company

About Partner program Contact

Legal

Terms Privacy Refunds Acceptable Use Subprocessors
© 2026 The Deployer. All rights reserved. AWS, Google Cloud, Microsoft Azure, DigitalOcean, GitHub and other product names are trademarks of their respective owners. The Deployer is not affiliated with or endorsed by them.