This policy covers spotgpus.com, the console at cloud.spotgpus.com, and the personal data we handle as a controller. Personal data that you put inside your own instances and volumes is yours; we act as a processor for it and the data processing addendum applies.
1. Scope#
We are the controller for the account, billing, support and security data described below. The operator's identification is provided on request through the contact form and in the order form for business accounts.
2. What we collect#
| Category | What it contains | Where it comes from |
|---|---|---|
| Account | Email address, password hash, optional name and company, two-factor secret if you enable it | You, at sign-up and in settings |
| Usage | Instances created, GPU model, region, minutes run, volumes and their size | The platform, as you use it |
| Billing | Top-ups, charges, balance, on-chain payment references | The platform and the public blockchain of the payment |
| Support | Tickets, contact-form messages and what we replied | You, when you write to us |
| Security | Sign-in attempts, session records with device and browser, API key usage, IP addresses | The platform, automatically |
| Website logs | Requests to the site and console: address, time, path, user agent | The edge and the origin server |
We do not ask for a postal address, a phone number or a document of identity, and we never see a card number — credit is paid in cryptocurrency and confirmed on-chain.
3. Why, and on what basis#
- To provide the service — creating instances, attaching volumes, showing your balance. Basis: performance of the contract.
- To bill accurately — usage records and payment history. Basis: performance of the contract, and a legal obligation for accounting records.
- To answer you — support tickets and contact messages. Basis: performance of the contract, or our legitimate interest in replying to people who write to us.
- To keep the platform safe — throttling sign-ins, investigating abuse, keeping short-lived access logs. Basis: legitimate interest in security, and legal obligations where they apply.
- To tell you about changes — service, security and contractual notices sent to the account address. Basis: performance of the contract.
4. What we do not do#
- No advertising, no ad network, no advertising identifier.
- No analytics on the marketing site: no tag manager, no beacon, no third-party script. The content security policy of this site would block them.
- No selling, renting or sharing of personal data with anyone for their own purposes.
- No inspection of what runs inside your instances, and no use of your content to train models.
- No marketing emails unless you ask for them. Account emails are operational.
5. Cookies and local storage#
The marketing site sets no cookies. There is nothing to consent to, which is why you are not asked. Your browser may keep one thing locally — whether you dismissed the announcement banner — and that never leaves your device.
The console sets one strictly necessary cookie, sid, which holds your session. It is HttpOnly, SameSite-restricted and marked Secure over HTTPS. Without it you cannot stay signed in. There are no other cookies.
The bot challenge on the authentication and contact forms is provided by a third party and may set its own storage for the duration of the check; it exists to keep automated sign-ups and spam out.
6. Who else sees it#
| Category of recipient | What they get | Why |
|---|---|---|
| Facility operators hosting the hardware | Nothing about your account; they host the machines your instances run on | Physical infrastructure |
| Network and edge provider in front of the site and console | Request metadata: address, time, path, user agent | Delivery, TLS and protection against attacks |
| Bot-challenge provider | Signals from the browser completing the challenge | Keeping automated abuse off the forms |
| Public blockchains | The payment transaction itself, which is public by nature | Confirming a deposit |
| Authorities | Only what a valid, properly served request requires | Legal obligation |
The current list of sub-processors, with names, is provided on request under the data processing addendum.
7. How long we keep it#
| Data | Retention |
|---|---|
| Account details | Until you close the account |
| Usage and billing records | 7 years, for accounting and tax |
| Support tickets and contact messages | 2 years after the exchange ends |
| Sign-in and session records | 90 days |
| Website and console access logs | 30 days |
| Your volumes and instance contents | Until you delete them; deletion is immediate and final |
8. Your content#
What you store in an instance or a volume is not ours and is not indexed, scanned or read by us in the ordinary course of operating the platform. Volumes are encrypted at rest. If your threat model does not allow an operator to have any theoretical access, encrypt inside the instance with a key we never receive.
9. Your rights#
Subject to the law that applies to you, you can ask for access to your personal data, correction of it, deletion of it, a copy in a portable format, restriction of processing, or object to processing based on our legitimate interest. Most of it is already in the console: your profile, your usage, your payments and your sessions.
Write through the contact form or open a ticket. We answer within 30 days. If you are not satisfied, you may complain to the data protection authority of your country.
10. Transfers#
The platform runs in the regions listed on the site, which today include the United States and Germany. Where personal data moves between jurisdictions, we rely on the legal mechanism that applies to that transfer — standard contractual clauses where they are required. You choose the region your instances and volumes live in.
11. Security#
Passwords are hashed with Argon2id; two-factor authentication is available; sessions are listed per device and revocable; volumes are encrypted at rest; the site and console are served over TLS with a strict content security policy. The mechanisms, and the gaps we have not closed yet, are described on the trust page. Report a vulnerability through the abuse form.
If a breach affects your personal data and is likely to present a risk, we will tell you without undue delay, with what happened, what is affected and what we did.
12. Changes and contact#
The revision date at the top of this page is always current. Material changes are announced to account holders by email at least 30 days in advance. For anything in this policy, write through the contact form.