Draft: these pages have not been reviewed by a lawyer. Have them reviewed before the service is offered generally.
Privacy
This page says what this Octopus service stores about you and your workspace, where, for how long, and how to erase it. The operator named above runs the service.
For what a workspace holds, its owner decides what goes in and the operator processes it on the owner's behalf.
What is stored
- Account: your email, display name, the identifier your identity provider assigns you, and your role in each workspace. No password: you sign in at the identity provider.
- Workspace content: clones of the repositories you connect, the working copies agents edit, tasks, comments, chats, attachments and what agents write during a run.
- Credentials: your AI provider key and Git tokens, each encrypted with AES-256-GCM. API keys are kept only as a hash.
- Usage: tokens and estimated cost per agent run, to show spend and apply limits.
- Security log: who did what and when, with the IP address and browser of the request.
Your AI provider key
Agents send prompts and code to the AI provider whose key you added, under your own agreement with that provider. The operator does not route that traffic through an account of its own, so that provider works for you, not for the operator. You can replace or delete the key at any time from Settings.
Where it is kept
On servers rented from Hetzner Online GmbH in the European Union. Workspaces share one database and every request is limited to the workspace it acts in. Octopus encrypts the credentials listed above one by one; the rest of the database and the working copies rely on the encryption of the server's disks.
How long it is kept
- Agent run logs and outputs: 30 days by default.
- Usage records per run: 90 days by default; a daily total per project stays.
- Webhook delivery logs: 30 days by default.
- Expired sessions: removed automatically.
- Security log: until the operator's retention setting removes it.
- Everything else: until you delete it, the workspace or your account.
- Backups: the newest snapshots stay on the server and are replaced as new ones are taken.
Deleting your data
A workspace owner can delete the workspace from Settings, Account by typing its slug. That erases its tasks, projects and clones, chats, credentials, webhooks, API keys and memberships.
You can delete your account from Settings, Account by typing your email. Workspaces you own alone are erased as above; a workspace you own that other people use has to be handed to another member, or deleted, first. Your memberships, sessions and identity provider links are deleted, and API keys you created in other workspaces stop working.
What stays: security log entries about your actions until they age out, your name as the author of comments in workspaces you did not own, and backups taken before the deletion until they are replaced.
Subprocessors
| Company | What for | Data | Where |
|---|---|---|---|
| Hetzner Online GmbH | Servers and storage | Everything the service stores | Germany and Finland (EU) |
| Your identity provider (the provider shown on the sign-in page) | Signing you in | Email, name and the identifier it assigns | Under its own terms |
Your AI provider and your Git host are your own choices, under your own agreements with them. A new subprocessor is listed here before it receives any data.
Your rights
You can ask for a copy of your data, for its correction or for its deletion by writing to the contact below. Workspaces and your account you can delete yourself from the dashboard.
Contact
Write to not configured about your data or this page.