Privacy

What personal data ISOGrid keeps, why, who else sees it, how long it is kept, and how to delete your account.

Last updated: 2026-10-01

This page covers the ISOGrid console, its API and command-line tool, and the ISOGrid app for Android, which opens the same console. Cookies have their own policy, in the console under Profile → Privacy and cookies.

Who is responsible

SkyVault, which operates ISOGrid, is the controller of your personal data under Law No. 18-07 of 10 June 2018 on the protection of natural persons in the processing of personal data.

For any question or request about your data, write to aziz.taleb@skyvault.pro.

What we keep about you

Your account. Your email address, your name, a username and, if you give it, a phone number. Your password is held by our sign-in service and is never stored in readable form. If you turn on two-step sign-in, we keep what it needs: the secret for your authenticator app, or the public key of your passkey. Fingerprints and faces never leave your device; your device only confirms that it checked them.

Signing in with Google, GitHub or LinkedIn. If you choose one of these, it sends us your name and email address. We do not post anything to those accounts.

Your profile. Your preferred language, whether you want announcement emails, and, if you give them, your Poste d'Algérie account details (CCP, key, RIP and account holder's name).

Documents you upload. Identity papers (national identity card, passport, driving licence) and business papers (trade register, tax and statistical numbers, company statutes) that we need to verify an account. They are kept in private storage. Only you, and the team members who review them, can open them.

Your organization. Its name, and the legal details invoices are made out to: legal name and form, registration numbers, address, phone and contact email. Which members belong to it, and what each one may do.

Billing. Your credit balance, every debit and credit to it, and what each one was for.

What you do in the console. An audit log records actions taken in an organization: who did what, to which resource, when, whether it worked, and the IP address it came from. You also get notifications about your own actions and your resources.

AI conversations. When you use an AI feature (the coding agent, the Dockerfile helper, the store builder), we keep the conversation, the files and images you attach, and the number of tokens used, so we can bill them.

Connected services. If you connect GitHub or GitLab, we keep the account name and picture they report, and the access token in an encrypted secret store. If you build a cluster in your own cloud account, the credentials you give are deleted once the cluster is active, or 24 hours after a failed attempt.

Domains. If you buy a domain through ISOGrid, the registrant contact you enter (name, email, phone, postal address).

Your consent choices. Each choice you make about cookies and measurement is recorded, with the date, the policy version, your language and your browser's user agent. That record is the proof of your consent.

Usage statistics and session recordings. Only if you accept them. They are described in the cookie policy.

Why we use it

  • To run your account and the services you use, and to sign you in securely.
  • To verify an account, using the documents you upload.
  • To bill you, issue invoices and keep accounting records.
  • To send you emails about your account, security, billing and alerts on your resources. These are part of the service. Announcements are separate, and you can turn them off in your profile.
  • To keep the platform secure and investigate misuse, with the audit log.
  • To answer you when you contact us.
  • To understand how the console is used and improve it, only if you accept usage statistics.

We do not sell your data, and we do not use it for advertising.

Who else receives it

We share personal data only with the services below, and only what each one needs to do its job.

Recipient What it receives Why
Brevo Your email address, your name, and the email's content Sending account, security, billing and alert emails
DeepSeek, Moonshot AI (Kimi), Google (Gemini) What you send to an AI feature: your messages, your code, files and images you attach Answering your request. Each provider's own terms apply to what it receives
Google, GitHub, LinkedIn Only if you sign in with them; they tell us who you are Signing you in
GitHub, GitLab Requests made with the token you connected Reading your repositories and deploying them
Namecheap The registrant contact you enter Registering a domain you buy
Google, Azure, AWS, DigitalOcean, IBM Cloud, Alibaba Cloud, OpenStack Requests made with the credentials you give Building a cluster in your own account
Google Fonts Your IP address and browser details, when the console loads its fonts Displaying the console's typefaces

The usage statistics and recordings are measured by ISOGrid itself, with Umami running on our own servers. No analytics company receives them.

We also disclose data when Algerian law requires it.

Where it is stored

ISOGrid's own servers hold your account and the console's data. Today they are located in Germany, which is also what the cookie policy states. The applications, databases and files you deploy run on the cluster you choose.

How long we keep it

  • Your account and profile: while your account exists.
  • Audit log: 365 days, then deleted automatically.
  • Read notifications: 90 days. Unread ones are kept until you read them.
  • Cloud credentials: until the cluster is active, or 24 hours after a failed attempt.
  • Usage statistics: 395 days. Session recordings and heatmaps: 90 days. Withdrawing your consent deletes them sooner.
  • Invoices, billing and payment records: as long as Algerian accounting and tax law requires, even after your account is deleted.

Your rights

Under Law 18-07 you have the right to be informed (art. 32), to access your data (art. 34), to have it corrected or erased (art. 35), and to object to its processing (art. 36).

You can see and correct most of your data yourself, in Profile. For anything else, write to aziz.taleb@skyvault.pro. You can also complain to the National Authority for the Protection of Personal Data (ANPDP).

Deleting your account

From the console. When signed in, go to Profile, section Delete account, and confirm by typing your email address. The page is the same in the web console and in the Android app. It is also reachable directly at https://isogrid.skyvault.pro/profile.

If you can no longer sign in, write to aziz.taleb@skyvault.pro from the email address on the account.

Changing your mind. Until the request is processed, you can cancel it from the same place.

What is deleted. Your account and the personal data attached to it are deleted within 30 days: your sign-in, profile, documents and memberships. Organizations you solely own are deleted with it, together with their resources: applications, databases, volumes and backups. Export anything you want to keep before you ask. Organizations that have other owners stay; only your membership is removed.

What is kept.

  • Invoices, billing and payment records, as long as Algerian accounting and tax law requires.
  • Audit log entries, until they reach the end of their 365 days, for security.
  • Backups, until they reach the end of their normal retention. Volume archives are never kept longer than 3 days.

Data you put on the platform

The applications, databases, files and stores you run on ISOGrid are yours, and so is the data of their users. For that data you are the controller, and ISOGrid processes it on your behalf. ISOGrid does not measure the visitors of the applications and websites you publish.

One exception you choose: if you advertise a store through ISOGrid, each order is reported to Meta through our advertising partner Zernio, with the customer's name, phone, city, IP address and browser, so Meta can measure your ads.

Changes

When this policy changes, the date at the top changes too.