DxCore Privacy Policy

Version: 1.1 Last updated: June 2026

DxCore SaaS is operated by Eyal Lapid, Israel. For privacy requests, contact privacy@dxcore.dev. For security reports, contact security@dxcore.dev.

This policy explains how DxCore handles personal data for the hosted CI/CD task orchestration service. It does not cover the separately licensed open-source DxCore project.


Data We Collect

DxCore collects the data needed to provide, secure, support, and improve the hosted service. We do not sell your personal data.

Category Examples
Account Name, email address, hashed password, account status
Organization Organization name, URL slug, membership, role, invitation, and owner records
Project Project names, identifiers, organization links, and service settings
Task and run metadata Task names, package names, run status, timestamps, durations, exit codes, shard data
Profile and scheduling data Task timing profiles, cached task counts, scheduler inputs, agent capacity metadata
API tokens Hashed API tokens, short token prefix, creation, use, revocation, and expiration records
Support requests Messages, contact details, troubleshooting context, and related correspondence
Security logs IP address, user-agent, request logs, authentication events, abuse-prevention signals
Analytics First-party, privacy-friendly, cookieless Umami page and product usage events
Observability and error monitoring Sentry error events and Grafana Cloud observability telemetry needed to operate DxCore
Billing Subscription plan and billing status; payment details are handled by Polar

Passwords and API tokens are cryptographically hashed before storage and are not stored in plaintext.


Data We Do Not Collect

DxCore is designed to avoid collecting build-time content. Unless you choose to include it in a support request, DxCore does not collect or store:

  • Source code
  • Build logs
  • Build artifacts
  • Secrets, credentials, environment variables, certificates, or private keys
  • Payment card numbers, which are handled by Polar
  • Protected health information, payment card data, GLBA-covered financial records, or special category data

How We Use Data

We use personal data for these purposes:

  • Provide and operate the hosted service, including login, organization management, project configuration, API token authentication, task scheduling, run status, and dashboards.
  • Optimize task scheduling by using task and run metadata, profile and scheduling data, and agent capacity metadata.
  • Send transactional email through Postmark, including account confirmation, password reset, invitation, and service notices.
  • Provide support, investigate reported issues, and respond to account or privacy requests.
  • Protect the service with security logs, abuse-prevention checks, access controls, and incident response.
  • Understand service usage with first-party, privacy-friendly, cookieless Umami analytics.
  • Monitor reliability with Sentry error monitoring and Grafana Cloud observability telemetry.
  • Maintain billing status and subscription records connected to Polar.

Our legal bases include contract necessity for account, organization, project, authentication, subscription, and service-operation data; legitimate interests for security, reliability, support, analytics, and service improvement; and legal obligations where we must keep limited records.

DxCore does not use Customer Data to train, fine-tune, or improve artificial intelligence or machine learning models. DxCore does not currently transmit user data to AI providers.


Sub-processors and Recipients

We use a limited set of providers to operate DxCore:

Provider Purpose
DigitalOcean EU infrastructure hosting, database, storage, and network
Wildbit, LLC (Postmark) Transactional email delivery
Polar Merchant of Record, subscription, tax, invoice, and refund
Functional Software, Inc. d/b/a Sentry Error monitoring and issue diagnostics
Grafana Labs Observability telemetry and service reliability monitoring

Umami is self-hosted first-party analytics software used as DxCore analytics infrastructure, not a separate third-party sub-processor. The current public sub-processor list provides provider, purpose, data category, location, and safeguard details for external providers.


International Transfers

Primary hosting is in DigitalOcean's AMS3 region in the Netherlands. Some providers process data in the United States or other locations, including Postmark, Polar, Sentry, and Grafana Labs.

For international transfers, we use lawful transfer safeguards appropriate to the provider and data involved, including Data Processing Agreements, Standard Contractual Clauses, EU adequacy decisions where available, and vendor transfer commitments. Copies of applicable safeguards are available on request at privacy@dxcore.dev.


Retention

We keep personal data only as long as needed for the purposes described in this policy or as required by law.

Data category Retention
Account data Active account lifetime, plus 30 days after deletion for recovery and closure
Organization and project data Active organization lifetime, then deleted or anonymized after termination
Task and run metadata 12 months from creation or run completion, then deleted or anonymized
Profile and scheduling data 12 months, then deleted or anonymized
API tokens Deleted when revoked or expired; audit records may remain in security logs
Support requests 24 months after request closure, unless legal, security, or dispute needs require longer
Security logs 90-day rolling retention unless needed for security investigation or legal claims
Analytics 24 months for first-party aggregate analytics, then deleted or aggregated further
Observability and error events 90 days for routine diagnostics unless incident response, security, or legal needs require longer
Billing records Retained by Polar according to its terms and applicable tax requirements

After account deletion, we delete or anonymize personal data within 30 days except where retention is required for legal, security, billing, or dispute-resolution reasons.


Your Rights

Depending on where you live, you may have rights to:

  • Access your personal data.
  • Correction of inaccurate or incomplete data.
  • Deletion of personal data, subject to lawful retention limits.
  • Data portability in a structured, machine-readable format.
  • Restrict processing in certain cases.
  • Object to processing based on legitimate interests.
  • Withdraw consent where processing depends on consent.
  • Lodge a complaint with a data protection authority.

To exercise rights, contact privacy@dxcore.dev. We aim to respond within 30 days and may verify your identity before acting on a request.

DxCore does not make solely automated decisions that produce legal or similarly significant effects.


Cookies and Analytics Choices

DxCore uses essential first-party session and CSRF storage. Production deployments may also use first-party, privacy-friendly, cookieless Umami analytics. The Cookie Policy explains cookie and analytics choices, including Global Privacy Control and localStorage opt-out behavior where supported.


Security

We use technical and organizational security measures appropriate to the hosted service, including TLS for data in transit, cryptographic hashing for passwords and API tokens, access controls, least-privilege operations, security logging, vulnerability management, and incident response procedures.

No service can guarantee absolute security. Please report vulnerabilities to security@dxcore.dev.


Security Breach Notification

If a personal data breach occurs, we will assess the risk, document the incident, notify authorities where required, and notify affected individuals where required by applicable law.


Children's Privacy

DxCore is a professional developer service and is not directed to children. You must be at least 18 years old, or the age of majority in your jurisdiction if higher, to create an account.


Changes

We may update this policy as the service, providers, or legal requirements change. Material changes will be notified by email or in-product notice where appropriate. The current version is available at https://dxcore.dev/legal/privacy.