xhostddocs
Console ↗
On this page

Privacy Policy

Last updated: 2026-09-13.

xhostd ("we", "us") runs a hosting platform. This policy explains what we do with personal data.

In this policy, our Sites means the websites and console we operate at randomimity.com. The Services means the hosting platform itself. Your Content means the projects, code, databases and files you deploy and store on the Services.

Who this covers

  • Visitors to our Sites.
  • Account holders who use the Services, or whose agent uses them on their behalf.
  • End users who sign in to an app an account holder runs on the Services.

An account holder decides what their app collects and what it does with it. Once data reaches their app, their privacy notice applies rather than ours.

Your Content

Your Content is yours. We store and run it to provide the Services, and back it up so you can recover from a mistake or a failure.

Our staff do not read Your Content in the ordinary course of running the platform. We access it to repair a fault, restore a backup, or help you with something you have raised with us.

Running the Services creates operational records, and those can contain your data. Logs, diagnostics, performance traces and error reports are a normal part of keeping a platform healthy, and they can include fragments of Your Content or of an end user's data — the text of a slow database query, for example, or an error quoting the value that caused it. We create and read these to run, secure, maintain and repair the Services. They are covered by everything else in this section, and they expire as described under How we retain information.

We do not use Your Content for any other purpose. We do not train models on it, analyse it, advertise from it, sell it, or share it, except with the service providers listed below who store or process it for us under contract.

Deleting a project removes it and its files. Backups expire on their own cycle, so a copy can remain in backup storage for a period afterwards.

Information we collect

From visitors to our Sites. With your consent, a third-party analytics service records page views. We also set the cookies described under Cookies.

From account holders. We hold your email address and username; credentials such as sessions, API tokens and SSH public keys, with secrets stored only as one-way digests; metadata about your projects, including names, settings, deployment history and activity; diagnostic records such as build output and notable platform events; and billing records. Where we need to limit abuse, we store a salted, one-way hash of the data rather than the data itself.

We also count traffic to your apps so you can see how they are used. We measure this ourselves and set no cookie on your visitors. To estimate unique visitors we store a salted one-way hash of the visitor's address. Country is derived from a lookup database we hold locally. This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com.

From end users signing in to an app. When you sign in through our managed Google sign-in, we receive your email address, display name, an identifier for your Google account, and your profile picture where Google provides one. We request access to no other Google service and collect this only at sign-in. We pass it to the app you are signing in to, in a signed cookie readable only by that app. We keep no user database of our own for this. We do record that a sign-in happened, which app it was for, and the identifier for your Google account, and we may store that and similar operational records for the maintenance and operation of the Services.

How we use information

To provide, secure and improve the Services; to authenticate you; to bill your plan; to answer you when you contact us; to meet legal obligations; and, with your consent, to measure how our Sites are used.

We do not sell personal data, and we do not use it for advertising without your consent.

Cookies and your choices

Our Sites set cookies that are strictly necessary to sign you in, carry a form between steps, show a status message, and remember the cookie choice you made. These carry no toggle, because the Sites cannot work without them.

Other categories need your consent. A panel asks for it on your first visit and names each category it covers. Accepting and rejecting carry equal weight, and nothing in a category loads or is stored until you allow it. Today those categories are:

  • Analytics — cookies set by our analytics provider.
  • Marketing — cookies remembering which partner's link brought you, so that partner is credited if you sign up.

On those pages, the footer carries a control that allows you to withdraw consent. Withdrawing removes what that category stored. Two things it cannot undo: data already sent to a provider stays with them, and consenting again issues a new identifier, so you are counted as a new visitor.

If your browser runs no JavaScript, no panel appears and neither category loads or stores anything.

The console sets no analytics or marketing cookie in any state.

How we retain information

We keep personal data for as long as we need it for the purpose we collected it, and then delete it. Account records last while the account exists. Diagnostic and operational records are kept for a limited period. Traffic measurements may be stored without a time limit.

When you close your account, we cancel any subscription, tear down running apps, revoke tokens, and remove keys and project memberships at once. Records we are required to keep, such as billing records, remain until you ask us to erase them. Backups expire on their own cycle, so a copy can remain in backup storage for a period afterwards.

How we share information

We use third-party service providers to run our infrastructure, host and back up data, deliver email, provide sign-in, take payment, measure our Sites, and run our partner programme. They act for us under contract and may use what they receive only to provide their service to us.

Our providers are Amazon Web Services, Backblaze, Cloudflare, Contabo, FirstPromoter, Google, Hetzner, MaxMind, Microsoft Azure, netcup, Paddle, PlanetScale, and Postmark.

We also disclose personal data where the law requires it, and to a successor in the event of a merger or acquisition.

Card details go to our payment provider and never to us.

International transfers

Some of our providers process data outside the European Economic Area, relying on the transfer safeguards available to them.

How we secure information

We hold secrets only as one-way digests, restrict staff access to what an operational task requires, and encrypt data in transit. No system is perfectly secure, and we cannot guarantee absolute security.

Your rights

Depending on where you live, you may ask us for a copy of your personal data, ask us to correct or erase it, object to or restrict how we use it, withdraw a consent you gave, or complain to your data protection authority.

Write to support@randomimity.com from the address on the account or sign-in. For data an account holder's app stored about you, contact that account holder directly.

Children

The Services are not directed to children under 16, and we do not knowingly collect their personal data.

Changes

We update this policy when our practices change, and revise the date above when we do.

Contact

support@randomimity.com

Enter a topic, task, or tool name.

Public documentation only · Search stays in your browser.