Privacy Policy

Last updated: 27 August 2026

1. Who We Are

JustDeploy is operated by CUPPASOFT LTD (Company No. 16060739), registered in England and Wales at 13 Approach Road, London, SW20 8BA, United Kingdom.

2. Scope of This Policy

This policy covers personal data relating to you as a JustDeploy user — for example your name, email address, and billing records. For that data we are the data controller, and this policy describes what we do with it.

It does not cover data that your own application collects from the people who use it. If you deploy an app on JustDeploy and it stores your users' personal data in your database, your file storage, or your application logs, you are the controller for that data and we act as your processor. Our obligations for it are set out in Section 10 of our Terms of Service, and you are responsible for providing your own privacy notice to those people.

3. Information We Collect

Account Information

When you create an account, we collect:

  • Email address — used as your username, for one-time verification codes, and for account communications
  • Name — displayed in your profile and to team members

We do not collect or store passwords. Sign-in is via a one-time code we email you, or via Google Sign-In.

Google Sign-In

If you sign in with Google, we receive your name and email address from your Google account. We do not access your Google contacts, calendar, or any other Google services. Google Sign-In is subject to Google's Privacy Policy.

Organization and Project Data

When you use the Service, we store:

  • Organization names and membership details
  • Project names, configurations, and deployment settings
  • Run schedules for scheduled tasks
  • Build artifacts (your uploaded source code)
  • Database contents you create through the Service
  • Files uploaded to storage
  • API credentials and connected-application access tokens
  • Firewall rules and custom domain configurations
  • Sending domains you verify for email, and the DNS records that verify them
  • Team invitations

Email You Send Through the Service

When your application sends email, we transmit the message on your instruction. The recipient address and the message content pass through our systems in order to send it. We keep a record of each message so that you can see what was sent and what happened to it.

That record contains:

  • The sending address, and the sending domain it belongs to
  • The recipient address in masked form, showing only the first characters and the domain, together with a one-way hash of the full address that lets us match delivery reports to the message without keeping the address itself
  • Any label you attach to the message
  • The outcome, which is whether it was delivered, could not be delivered, was reported as unwanted, or failed, and when the message was opened if we are told
  • The times the message was sent, delivered, and opened

We do not store the subject line or the body of your messages. Once a message has been handed over for delivery, we no longer hold its content.

Messages include a small invisible image that tells us when a message is opened. It records the time only. Many mail applications block it or load it without anyone reading the message, so this is an approximate signal rather than a measurement.

Where the recipient of a message is an individual, you decide who is contacted and why, so you are the controller of that person's data and we act as your processor. Section 2 explains that split, and Section 10 of our Terms of Service sets out what we undertake as a processor.

Payment Information

When you make a payment — a plan subscription, a one-time credit top-up, or an automatic credit recharge — it is processed by Stripe. We do not store your full card number on our servers. We retain only a reference to your Stripe customer account and basic card details (brand, last four digits, expiry) for display purposes.

Automatically Collected Information

  • Server logs — HTTP request logs (IP address, request method, URL, status code, user agent) and diagnostic records are collected for operational and security purposes
  • Usage measurements — the compute and storage your projects consume and the number of email messages you send, used to meter your account and calculate charges
  • IP address — when you use the firewall configuration feature, your public IP may be detected to help you set up access rules
  • Connected-app usage — for AI tools connected through MCP, we keep a summary of the last-used time, IP address, user agent, and cumulative request count so you can review account access and disconnect unfamiliar apps
  • Website and campaign analytics — on our public website and documentation we use Google Analytics in a cookie-free mode to measure which pages are visited, which site or advertising campaign referred you, your approximate country, and your browser and device type. We also send named product milestones, such as first account verification, first project creation, and first successful guide copy, without account, organization, or project identifiers. We ask before storing anything: unless you allow it, no analytics cookie or other analytics identifier is placed on your device. If you allow it, a Google Analytics cookie lets us see those steps as one journey and a local guide-copy history prevents duplicate conversion counts. Pages inside your account do not send page views. Page addresses sent to Google retain only Google advertising click identifiers and UTM campaign fields; all other query parameters, including email addresses, authorization codes, redirect values, and invitation tokens, are removed

4. What We Do Not Collect

  • We do not use advertising cookies, and the Service does not rely on cookies for its own functionality — your session and settings are kept in your browser using local storage instead (see Section 9). The one cookie we may use is the Google Analytics cookie described in Section 3, and only if you allow it.
  • We do not use remarketing or cross-site profiling tools, and we do not build advertising profiles of individuals. Google advertising click identifiers are used only to measure the campaign responses described in Section 3.
  • We do not perform device fingerprinting
  • We do not use your device's location services and do not collect precise location. Website analytics infers an approximate country from your IP address and nothing more.
  • We do not sell or share your personal data with advertisers
  • We do not use your code, database contents, or storage files to train AI or machine learning models (see Section 7)

5. Legal Basis for Processing

Under the UK General Data Protection Regulation (UK GDPR), we process your personal data on the following legal bases:

  • Contract performance — Processing necessary to provide the Service, manage your account, process deployments, and handle payments (Article 6(1)(b))
  • Legitimate interests — Processing necessary for security monitoring, fraud and abuse prevention, diagnosing faults, understanding in aggregate how our public website and documentation are used, improving the reliability and quality of the Service, and enforcement of our Terms of Service (Article 6(1)(f))
  • Legal obligation — Processing required to comply with applicable tax, accounting, and regulatory requirements (Article 6(1)(c))
  • Consent — Where you have given it for a specific optional feature, such as saving your email address for sign-in, or allowing the analytics storage described in Section 3. You can withdraw consent at any time, and Section 9 has the control for analytics storage (Article 6(1)(a))

6. How We Use Your Information

  • To provide and maintain the Service
  • To authenticate you and manage your account
  • To send you account-related communications (e.g., one-time sign-in codes, team invitations, billing notices)
  • To process your deployments and manage your infrastructure
  • To meter usage, process payments, and manage your subscription
  • To monitor, secure, debug, and improve the reliability of the Service
  • To enforce our Terms of Service and protect the security of the Service

7. AI-Assisted Processing

Some features of the Service use AI models — for example, to analyse your project when you deploy it, generate its build configuration, and detect its runtime, and to power other AI-assisted features described in our Terms of Service.

This processing takes place inside our own cloud infrastructure. Your content is not sent to the developer of the model, is not shared with any model provider, and is not used to train AI models.

8. How We Store and Protect Your Data

Infrastructure

All data is stored on Amazon Web Services (AWS) infrastructure in the United States.

Encryption

  • Sensitive credentials and secrets are encrypted at rest using strong, industry-standard encryption
  • All data in transit is encrypted via HTTPS/TLS
  • Sign-in codes are short-lived, single-use, and invalidated after use or expiry

Authentication

We use token-based authentication stored in your browser. Tokens expire automatically. Access tokens issued to connected applications also expire, and you can revoke them at any time.

Access Controls

Access to production systems and customer data is restricted to authorised personnel who need it to operate and support the Service, is subject to a duty of confidentiality, and is logged. Resources are isolated per organization, and access within an organization is governed by the role assigned to each member.

9. Browser Storage

We store the following in your browser rather than in cookies:

  • Authentication token — for API authentication (expires automatically)
  • User profile — your name and email
  • Current organization — the organization you last accessed
  • Saved email — your email address, stored only if you enable "Remember my email" at sign-in so we can pre-fill it next time
  • Interface preferences — minor display state, such as the order of your project tabs
  • Sign-in timing — a timestamp used to show the code expiry countdown, discarded when you close the tab
  • Analytics choice — whether you allowed or declined analytics storage, so that we ask you once rather than on every visit
  • Guide-copy history — if you allow analytics storage, a capped list of guide targets already counted as conversions, stored only to prevent duplicate counts and never sent to Google

Your authentication token, profile, and current organization are cleared when you sign out. Your saved email and interface preferences remain until you turn off "Remember my email", change the preference, or clear your browser. You can clear all of it manually through your browser settings at any time.

If you allow analytics storage described in Section 3, Google Analytics also stores a cookie on your device to recognise your visits and we store the local guide-copy history listed above. We ask before storing either, and you can change your answer here at any time. Withdrawing deletes both from your browser immediately.

10. Third-Party Services and Sub-processors

We use the following categories of third-party provider to operate the Service:

  • Amazon Web Services (AWS) — Cloud infrastructure including hosting, compute, storage, content delivery, AI processing, and email delivery. Data is processed in the United States. Subject to AWS Privacy Notice.
  • Managed database provider — Operates the managed database clusters that hold your account and application data, running on AWS infrastructure in the United States.
  • Stripe — Payment processing. When you make a payment — a plan subscription, a one-time credit top-up, or an automatic credit recharge — your payment information is collected and processed directly by Stripe. Subject to Stripe's Privacy Policy.
  • Google Sign-In — Authentication. If you choose to sign in with Google, your name and email are provided by Google. Subject to Google's Privacy Policy.
  • Google Analytics — Measurement of our public website, campaign response, and named product milestones, with advertising personalisation and remarketing signals disabled. It runs without any cookie unless you allow one, and pages inside your account do not send page views. Subject to Google's Privacy Policy.

A current list of our sub-processors is available to customers on request from support@justdeploy.ai. We may update the providers we use from time to time. Material changes will be communicated through the Service or via email.

11. Data Sharing

We do not sell your personal data. We share your information only in these circumstances:

  • With team members within your organization (name, email, and role are visible)
  • With our infrastructure and service providers as necessary to operate the Service (see Section 10)
  • With Stripe for payment processing when you make a payment (plan subscription, credit top-up, or auto-recharge)
  • With a purchaser or successor in the event of a merger, acquisition, or sale of assets, subject to this policy
  • When required by law or to protect the rights and safety of the Service

12. International Data Transfers

Our servers are located in the United States. As a UK-based company, we ensure that transfers of personal data from the UK to the United States are protected by appropriate safeguards in accordance with the UK GDPR, including the use of the UK International Data Transfer Agreement (IDTA) or other approved transfer mechanisms where required. By using the Service, you acknowledge that your data will be transferred to and processed in the United States.

13. Data Retention

We keep personal data only for as long as we need it for the purposes described in this policy. Because the appropriate period depends on the type of data and why we hold it, we apply the criteria below rather than a single fixed schedule, and we review our retention practices periodically.

  • Account and organization data — for as long as your account is active, and for a reasonable period afterwards to complete deletion, resolve disputes, and meet our legal obligations
  • Project content and build artifacts — for the lifetime of the associated project
  • Custom domain configurations — while the associated project and Organization remain active, including while custom-domain routing is paused after paid-plan access ends, unless you remove the domain earlier
  • Operational, diagnostic, and security records — for as long as they remain useful for operating and securing the Service, investigating abuse, diagnosing faults, and improving reliability and quality
  • Connected-app usage summaries — until the connection is removed or the underlying access expires
  • Billing and tax records — for the period required by applicable tax and accounting law
  • Email delivery records — for as long as your account is active, because together they form your sending history and the bounce and complaint record that governs whether you can keep sending
  • Team invitations — until accepted, cancelled, or expired
  • Deleted resources — permanently removed within a reasonable period after deletion

Organizations suspended for non-payment are retained for the period set out in Section 19 of our Terms of Service, after which they are permanently deleted.

14. Account Deletion

You may request deletion of your account at any time. Upon account deletion:

  • Your personal data (name, email, authentication credentials) will be permanently deleted
  • Your membership in all organizations will be removed
  • Content associated with organizations you own may be deleted if you are the sole owner
  • Some data may be retained where required by law (e.g., billing records for tax purposes)
  • Deletion is typically completed within 30 days of the request

To request account deletion, contact us at support@justdeploy.ai or through the account settings in the Service.

15. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.

16. Your Rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your account and associated data
  • Export your data in a portable format
  • Object to or restrict certain processing of your data
  • Withdraw consent where processing is based on consent

To exercise any of these rights, contact us at support@justdeploy.ai. We will respond to your request within one month, as required by applicable data protection law.

You also have the right to lodge a complaint with a data protection supervisory authority. In the UK this is the Information Commissioner's Office (ICO), at ico.org.uk. If you are elsewhere, you may complain to your local supervisory authority. We would welcome the chance to address your concern directly first.

17. Children's Privacy

The Service is not intended for children under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 16, we will take steps to delete it.

18. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or through the Service. The "Last updated" date at the top reflects the most recent revision.

19. Contact

If you have questions about this Privacy Policy or how we handle your data, you may contact us at:

CUPPASOFT LTD
13 Approach Road, London, SW20 8BA, United Kingdom