New B200 spot capacity is live in US East from $1.69 per GPU-hour. See availability
Legal

Privacy policy

What we collect, why we collect it, how long we keep it, and what we deliberately do not do.

Version of 15 September 2026 · ask about a clause

This policy covers spotgpus.com, the console at cloud.spotgpus.com, and the personal data we handle as a controller. Personal data that you put inside your own instances and volumes is yours; we act as a processor for it and the data processing addendum applies.

1. Scope#

We are the controller for the account, billing, support and security data described below. The operator's identification is provided on request through the contact form and in the order form for business accounts.

2. What we collect#

CategoryWhat it containsWhere it comes from
AccountEmail address, password hash, optional name and company, two-factor secret if you enable itYou, at sign-up and in settings
UsageInstances created, GPU model, region, minutes run, volumes and their sizeThe platform, as you use it
BillingTop-ups, charges, balance, on-chain payment referencesThe platform and the public blockchain of the payment
SupportTickets, contact-form messages and what we repliedYou, when you write to us
SecuritySign-in attempts, session records with device and browser, API key usage, IP addressesThe platform, automatically
Website logsRequests to the site and console: address, time, path, user agentThe edge and the origin server

We do not ask for a postal address, a phone number or a document of identity, and we never see a card number — credit is paid in cryptocurrency and confirmed on-chain.

3. Why, and on what basis#

  • To provide the service — creating instances, attaching volumes, showing your balance. Basis: performance of the contract.
  • To bill accurately — usage records and payment history. Basis: performance of the contract, and a legal obligation for accounting records.
  • To answer you — support tickets and contact messages. Basis: performance of the contract, or our legitimate interest in replying to people who write to us.
  • To keep the platform safe — throttling sign-ins, investigating abuse, keeping short-lived access logs. Basis: legitimate interest in security, and legal obligations where they apply.
  • To tell you about changes — service, security and contractual notices sent to the account address. Basis: performance of the contract.

4. What we do not do#

  • No advertising, no ad network, no advertising identifier.
  • No analytics on the marketing site: no tag manager, no beacon, no third-party script. The content security policy of this site would block them.
  • No selling, renting or sharing of personal data with anyone for their own purposes.
  • No inspection of what runs inside your instances, and no use of your content to train models.
  • No marketing emails unless you ask for them. Account emails are operational.

5. Cookies and local storage#

The marketing site sets no cookies. There is nothing to consent to, which is why you are not asked. Your browser may keep one thing locally — whether you dismissed the announcement banner — and that never leaves your device.

The console sets one strictly necessary cookie, sid, which holds your session. It is HttpOnly, SameSite-restricted and marked Secure over HTTPS. Without it you cannot stay signed in. There are no other cookies.

The bot challenge on the authentication and contact forms is provided by a third party and may set its own storage for the duration of the check; it exists to keep automated sign-ups and spam out.

6. Who else sees it#

Category of recipientWhat they getWhy
Facility operators hosting the hardwareNothing about your account; they host the machines your instances run onPhysical infrastructure
Network and edge provider in front of the site and consoleRequest metadata: address, time, path, user agentDelivery, TLS and protection against attacks
Bot-challenge providerSignals from the browser completing the challengeKeeping automated abuse off the forms
Public blockchainsThe payment transaction itself, which is public by natureConfirming a deposit
AuthoritiesOnly what a valid, properly served request requiresLegal obligation

The current list of sub-processors, with names, is provided on request under the data processing addendum.

7. How long we keep it#

DataRetention
Account detailsUntil you close the account
Usage and billing records7 years, for accounting and tax
Support tickets and contact messages2 years after the exchange ends
Sign-in and session records90 days
Website and console access logs30 days
Your volumes and instance contentsUntil you delete them; deletion is immediate and final

8. Your content#

What you store in an instance or a volume is not ours and is not indexed, scanned or read by us in the ordinary course of operating the platform. Volumes are encrypted at rest. If your threat model does not allow an operator to have any theoretical access, encrypt inside the instance with a key we never receive.

9. Your rights#

Subject to the law that applies to you, you can ask for access to your personal data, correction of it, deletion of it, a copy in a portable format, restriction of processing, or object to processing based on our legitimate interest. Most of it is already in the console: your profile, your usage, your payments and your sessions.

Write through the contact form or open a ticket. We answer within 30 days. If you are not satisfied, you may complain to the data protection authority of your country.

10. Transfers#

The platform runs in the regions listed on the site, which today include the United States and Germany. Where personal data moves between jurisdictions, we rely on the legal mechanism that applies to that transfer — standard contractual clauses where they are required. You choose the region your instances and volumes live in.

11. Security#

Passwords are hashed with Argon2id; two-factor authentication is available; sessions are listed per device and revocable; volumes are encrypted at rest; the site and console are served over TLS with a strict content security policy. The mechanisms, and the gaps we have not closed yet, are described on the trust page. Report a vulnerability through the abuse form.

If a breach affects your personal data and is likely to present a risk, we will tell you without undue delay, with what happened, what is affected and what we did.

12. Changes and contact#

The revision date at the top of this page is always current. Material changes are announced to account holders by email at least 30 days in advance. For anything in this policy, write through the contact form.


The other documents#