DxCore Privacy Policy
Version: 1.1 Last updated: June 2026
DxCore SaaS is operated by Eyal Lapid, Israel. For privacy requests, contact privacy@dxcore.dev. For security reports, contact security@dxcore.dev.
This policy explains how DxCore handles personal data for the hosted CI/CD task orchestration service. It does not cover the separately licensed open-source DxCore project.
Data We Collect
DxCore collects the data needed to provide, secure, support, and improve the hosted service. We do not sell your personal data.
| Category | Examples |
|---|---|
| Account | Name, email address, hashed password, account status |
| Organization | Organization name, URL slug, membership, role, invitation, and owner records |
| Project | Project names, identifiers, organization links, and service settings |
| Task and run metadata | Task names, package names, run status, timestamps, durations, exit codes, shard data |
| Profile and scheduling data | Task timing profiles, cached task counts, scheduler inputs, agent capacity metadata |
| API tokens | Hashed API tokens, short token prefix, creation, use, revocation, and expiration records |
| Support requests | Messages, contact details, troubleshooting context, and related correspondence |
| Security logs | IP address, user-agent, request logs, authentication events, abuse-prevention signals |
| Analytics | First-party, privacy-friendly, cookieless Umami page and product usage events |
| Observability and error monitoring | Sentry error events and Grafana Cloud observability telemetry needed to operate DxCore |
| Billing | Subscription plan and billing status; payment details are handled by Polar |
Passwords and API tokens are cryptographically hashed before storage and are not stored in plaintext.
Data We Do Not Collect
DxCore is designed to avoid collecting build-time content. Unless you choose to include it in a support request, DxCore does not collect or store:
- Source code
- Build logs
- Build artifacts
- Secrets, credentials, environment variables, certificates, or private keys
- Payment card numbers, which are handled by Polar
- Protected health information, payment card data, GLBA-covered financial records, or special category data
How We Use Data
We use personal data for these purposes:
- Provide and operate the hosted service, including login, organization management, project configuration, API token authentication, task scheduling, run status, and dashboards.
- Optimize task scheduling by using task and run metadata, profile and scheduling data, and agent capacity metadata.
- Send transactional email through Postmark, including account confirmation, password reset, invitation, and service notices.
- Provide support, investigate reported issues, and respond to account or privacy requests.
- Protect the service with security logs, abuse-prevention checks, access controls, and incident response.
- Understand service usage with first-party, privacy-friendly, cookieless Umami analytics.
- Monitor reliability with Sentry error monitoring and Grafana Cloud observability telemetry.
- Maintain billing status and subscription records connected to Polar.
Our legal bases include contract necessity for account, organization, project, authentication, subscription, and service-operation data; legitimate interests for security, reliability, support, analytics, and service improvement; and legal obligations where we must keep limited records.
DxCore does not use Customer Data to train, fine-tune, or improve artificial intelligence or machine learning models. DxCore does not currently transmit user data to AI providers.
Sub-processors and Recipients
We use a limited set of providers to operate DxCore:
| Provider | Purpose |
|---|---|
| DigitalOcean | EU infrastructure hosting, database, storage, and network |
| Wildbit, LLC (Postmark) | Transactional email delivery |
| Polar | Merchant of Record, subscription, tax, invoice, and refund |
| Functional Software, Inc. d/b/a Sentry | Error monitoring and issue diagnostics |
| Grafana Labs | Observability telemetry and service reliability monitoring |
Umami is self-hosted first-party analytics software used as DxCore analytics infrastructure, not a separate third-party sub-processor. The current public sub-processor list provides provider, purpose, data category, location, and safeguard details for external providers.
International Transfers
Primary hosting is in DigitalOcean's AMS3 region in the Netherlands. Some providers process data in the United States or other locations, including Postmark, Polar, Sentry, and Grafana Labs.
For international transfers, we use lawful transfer safeguards appropriate to the provider and data involved, including Data Processing Agreements, Standard Contractual Clauses, EU adequacy decisions where available, and vendor transfer commitments. Copies of applicable safeguards are available on request at privacy@dxcore.dev.
Retention
We keep personal data only as long as needed for the purposes described in this policy or as required by law.
| Data category | Retention |
|---|---|
| Account data | Active account lifetime, plus 30 days after deletion for recovery and closure |
| Organization and project data | Active organization lifetime, then deleted or anonymized after termination |
| Task and run metadata | 12 months from creation or run completion, then deleted or anonymized |
| Profile and scheduling data | 12 months, then deleted or anonymized |
| API tokens | Deleted when revoked or expired; audit records may remain in security logs |
| Support requests | 24 months after request closure, unless legal, security, or dispute needs require longer |
| Security logs | 90-day rolling retention unless needed for security investigation or legal claims |
| Analytics | 24 months for first-party aggregate analytics, then deleted or aggregated further |
| Observability and error events | 90 days for routine diagnostics unless incident response, security, or legal needs require longer |
| Billing records | Retained by Polar according to its terms and applicable tax requirements |
After account deletion, we delete or anonymize personal data within 30 days except where retention is required for legal, security, billing, or dispute-resolution reasons.
Your Rights
Depending on where you live, you may have rights to:
- Access your personal data.
- Correction of inaccurate or incomplete data.
- Deletion of personal data, subject to lawful retention limits.
- Data portability in a structured, machine-readable format.
- Restrict processing in certain cases.
- Object to processing based on legitimate interests.
- Withdraw consent where processing depends on consent.
- Lodge a complaint with a data protection authority.
To exercise rights, contact privacy@dxcore.dev. We aim to respond within 30 days and may verify your identity before acting on a request.
DxCore does not make solely automated decisions that produce legal or similarly significant effects.
Cookies and Analytics Choices
DxCore uses essential first-party session and CSRF storage. Production deployments may also use first-party, privacy-friendly, cookieless Umami analytics. The Cookie Policy explains cookie and analytics choices, including Global Privacy Control and localStorage opt-out behavior where supported.
Security
We use technical and organizational security measures appropriate to the hosted service, including TLS for data in transit, cryptographic hashing for passwords and API tokens, access controls, least-privilege operations, security logging, vulnerability management, and incident response procedures.
No service can guarantee absolute security. Please report vulnerabilities to security@dxcore.dev.
Security Breach Notification
If a personal data breach occurs, we will assess the risk, document the incident, notify authorities where required, and notify affected individuals where required by applicable law.
Children's Privacy
DxCore is a professional developer service and is not directed to children. You must be at least 18 years old, or the age of majority in your jurisdiction if higher, to create an account.
Changes
We may update this policy as the service, providers, or legal requirements change. Material changes will be notified by email or in-product notice where appropriate. The current version is available at https://dxcore.dev/legal/privacy.