*[DediGPU](https://dedigpu.com/) — Markdown mirror of [https://dedigpu.com/legal/privacy](https://dedigpu.com/legal/privacy) · updated 2026-09-02 · index for LLMs: [llms.txt](https://dedigpu.com/llms.txt) · everything: [llms-full.txt](https://dedigpu.com/llms-full.txt)*

# DediGPU — Privacy policy

> What DediGPU stores about you (an email, hashes, invoice references, a login IP), what it never asks for, how long it is kept, and who can see it.

*Effective 2 September 2026, last updated 2 September 2026*

## The short version

- We hold an email address, a password hash, a balance, invoice references and the IP addresses of your logins and orders. Nothing else.
- We never ask for a name, an address, a phone number, documents or a card. There are no analytics scripts and no advertising pixels on this site.
- We do not access the contents of your server. Its storage is securely erased 14 days after suspension, or immediately on cancellation.
- Data leaves us only under a legally binding order in the jurisdiction where the server sits, and only what we hold.

## 1. What we collect

**Account.** Your email address and a bcrypt hash of your password. We never store the password itself.

**Billing.** Each top-up: the invoice reference, the coin and network, the amount in USD, the address generated for you, the amount received and the transaction reference as reported by the payment processor. The balance and the ledger of every charge and credit.

**Technical.** The IP address and browser identifier at sign-in and at each order, kept in the account event log for twelve months. Session rows (a hash of the session token, IP, browser) for 30 days or until you sign out. Rate-limit counters (a key and a timestamp) for one hour.

**Support.** The text of your tickets.

## 2. What we do not collect

No legal name, postal address, phone number, date of birth, identity document, company registration or payment card. No behavioural analytics, no advertising identifiers, no third-party tracking scripts, no fingerprinting. The only third-party code on this site is Cloudflare Turnstile, loaded on the sign-up and sign-in forms to stop robots; it sees your IP address and browser characteristics under Cloudflare's own privacy terms.

## 3. Your server and its data

We do not log in to your server and we do not read its storage. We see what a data centre operator has to see: power draw, port traffic counters, link state, IPMI health and the SSH port answering our availability probe. When a server is cancelled its NVMe devices are erased with the drive's own secure-erase command before the hardware is reused; when it is suspended, the erase happens 14 days later unless you resume it.

## 4. Cookies

Three first-party cookies, none of them used for tracking: `dgs` (your session, 30 days), `dgc` (a form token for anonymous forms, one day) and `dgf` (a one-time message after an action, two minutes). Turnstile may set its own cookie on the forms where it is loaded.

## 5. How long we keep things

Account data: until you close the account. Ledger and invoices: for as long as accounting law requires us to keep records of payments, then deleted. Event log (logins, orders, IP addresses): twelve months. Sessions: 30 days. Tickets: 90 days after they are closed. Server data: as described above.

## 6. Who else sees what

**Payment processor.** Receives the invoice reference, the amount, the coin and the IP address that created the invoice, for fraud control. It never receives your email address.

**Cloudflare.** Terminates TLS for dedigpu.com and runs Turnstile on the forms named above.

**Data-centre operators.** Know which rack a server is in. Nothing about who rents it.

We do not sell, rent or share data with anyone else, and we do not use it for advertising.

## 7. Legal requests

We answer only legally binding orders issued under the law of the country where the server concerned is located. We check that the order is valid and no broader than the law allows, we hand over only the data we actually hold, and we tell you unless the order forbids it. We do not respond to informal requests.

## 8. Your rights

You can read everything we hold about your account through the API (`/api/v1/me`, `/api/v1/servers`) and the billing page. You can change your email address and password in Settings. You can ask us to close the account and delete its data from a ticket; we do so within 30 days, keeping only the payment records the law requires. Where a data-protection law gives you further rights (access, rectification, portability, objection), you exercise them the same way.

## 9. Security

Passwords are hashed with bcrypt; session and API tokens are stored as SHA-256 hashes; every form carries an anti-forgery token; the site sends a strict content-security policy and is served only over TLS. The measures we take around the hardware are described on the [trust and security page](https://dedigpu.com/security). If we learn of a breach affecting your data we tell you in the console within 72 hours.

## 10. Changes

We may update this policy; the date at the top changes when we do, and material changes are announced in the console 14 days ahead.

