Privacy Policy

Last updated: 30 September 2026.

1. Who we are

This policy explains what personal data is processed when you visit deplo.build, including the documentation at deplo.build/docs, and when a Deplo installation talks to our services. The controller is Kevin Paratore, an individual domiciled in Italy, who runs the Deplo project under the name DeploCloud ("DeploCloud", "we", "us"). For anything about privacy, write to privacy@deplo.build. We are not required to appoint a Data Protection Officer and have not done so.

2. The short version

- There are no accounts, newsletters or ads on this site, and it sets no cookies. - The one field you can type into, on the Deploy on Deplo page, keeps what you write in your browser. - Fonts, images and videos are served by deplo.build itself. Your browser loads nothing from Google, YouTube or any other third party. - We count visits with Rybbit, an open source analytics tool that we run ourselves on our own server in the EU. It uses no cookies and does not store your IP address. - You can switch the statistics off for your browser at the bottom of this page. - We never sell personal data and never share it for advertising.

3. Server and network logs

Every request to deplo.build passes through Cloudflare and then through the reverse proxy on our server. Both record technical data about the request: IP address, date and time, requested URL, referrer, user agent and response status. Why: to deliver the site, protect it from attacks and abuse, and find faults. Legal basis: our legitimate interest in running a secure website (Art. 6(1)(f) GDPR). Retention: at most 30 days, unless a specific log is needed to investigate a security incident, in which case it is kept until that investigation ends. The get-started page asks our server which country you are browsing from, to show prices in your currency first. The answer comes from the country Cloudflare attaches to the request; it is used for that response and not stored.

4. Visit statistics (Rybbit)

We use Rybbit (rybbit.com), self-hosted at stats.deplo.build on our own server in the Netherlands. No data goes to Rybbit the company or to anyone else. What it records for each page view: the page address, including its query parameters; the referring page; the country, region and city derived from your IP address at the moment of the visit; browser, operating system, device type, screen size and language. It also records a few interactions: the label of a button you click, the address of a link that leaves the site, the first 500 characters of text you copy from a page, and on the get-started page the answers you pick (goal, country, currency) and which hosting offer you open. None of this contains your name, your email or anything you type. The analytics script does not run on deplo.build/deploy, the page behind the Deploy on Deplo button: that page records a single event of its own (section 7). Your IP address is used to derive the location and a pseudonymous visitor identifier, and is not stored. The statistics cannot tell us who you are, and we do not try to find out. Why: to understand which pages are useful and where people get stuck, in aggregate. Legal basis: our legitimate interest in improving the site (Art. 6(1)(f) GDPR). Retention: 24 months, then deleted. You can object at any time: use the switch at the bottom of this page, or block stats.deplo.build with any content blocker.

5. Cookies and local storage

The public site sets no cookies. Two cookies exist only for our own editors, when they sign in to the content management panel and open its preview: payload-token (the login session) and deplo-preview (shows unpublished drafts). A visitor never receives them. A few values are kept in your browser's local storage, which never leaves your device on its own: - rybbit-visitor-id: a random identifier the analytics script creates. With our configuration it is not sent with the statistics. - disable-rybbit: only if you use the opt-out switch below; it remembers your choice. - deplo.instance: the address of your Deplo, only if you use a Deploy on Deplo button (section 7). - theme: on deplo.build/docs, your light or dark mode choice. Because nothing here tracks you across websites or profiles you for advertising, and the statistics are first-party and aggregate, the site does not show a consent banner (Art. 122 of the Italian Privacy Code and the Italian Data Protection Authority's cookie guidelines of 10 June 2021). You can clear local storage from your browser settings at any time.

6. When you email us

If you write to an address at deplo.build (for example privacy@, hello@ or security@), we receive your email address, your message and anything you attach. We use them only to answer you and handle your request. Legal basis: steps you asked us to take, or our legitimate interest in answering (Art. 6(1)(b) and (f) GDPR). Retention: as long as the conversation needs, and no longer than 24 months after the last message, unless we must keep it to establish or defend a legal claim. Incoming mail is received and forwarded by Cloudflare Email Routing.

7. The Deploy on Deplo button

Open source projects can put a "Deploy on Deplo" button in their README. This is what happens when you use one: - The button image comes from deplo.build/button.svg. On GitHub, images are fetched by GitHub's own image proxy, so we usually see GitHub's request rather than yours. Either way it is logged like any other request (section 3). - Clicking it opens deplo.build/deploy with the address of the project's compose file in the link. That address is public, and it appears in the request logs of section 3. - The first time, the page asks where your Deplo is. The address you enter is saved in this browser's local storage (deplo.instance) and is never sent to us: not in a request, a cookie or a statistic. You can change it or forget it from the same page. - The page then sends your browser straight to your own Deplo, with the compose file address, and tells it not to pass on where you came from. From there, your installation handles it (section 10). - It records one event in our statistics (section 4): the project the button belongs to (for example owner/repo on GitHub), whether you had just entered your Deplo address, your browser language and screen size. Never the address of your Deplo. The event is not sent if you turned statistics off at the bottom of this page.

8. Hosting offers and links to other sites

The get-started page lists hosting offers from third-party providers. When you open an offer, you leave deplo.build and go to the provider's website. The link carries only a referral tag (ref=deplo) and the plan code, never any personal data. We may receive a commission from the provider. From that point, the provider's own privacy policy applies. The same goes for every other external link on this site, such as GitHub, Discord or X.

9. Who else handles the data

- Cloudflare, Inc. (United States): content delivery, DNS, protection from attacks, email routing. It processes the network data of every request as our processor. Transfers to the United States rely on the EU-US Data Privacy Framework, to which Cloudflare is certified, and on the European Commission's Standard Contractual Clauses. - DELUXHOST: the server provider. The website, its database, its media files and the analytics all run on a server in a data centre in Amsterdam, the Netherlands. Outside these two, nobody receives personal data from this site. We may disclose data to public authorities only when the law requires it.

10. The Deplo software

Deplo is software you install on your own servers. Whatever you run and store with it stays on those servers: we have no access to it. You are the controller of any personal data your installation processes. A Deplo installation contacts our services in three ways: - Anonymous usage statistics: once a day it sends usage.deplo.build a report with Deplo versions, host architecture, counts and which features are turned on, under a random instance identifier. It never contains a hostname, IP address, domain, email, username, app name, repository URL or error message. The receiving service does not write IP addresses down. Raw reports are kept for 90 days; the daily totals built from them are anonymous and kept indefinitely. Any instance admin can turn this off in Settings > Deplo, and DO_NOT_TRACK=1 turns it off for the whole installation. - Template catalog: when you browse one-click templates, your installation fetches them from templates.deplo.build. These requests are logged like any other request (section 3). - Install script: deplo.build/install.sh is fetched from GitHub by our server and handed to you; the request is logged like any other (section 3). Deplo also checks GitHub for new releases. That request goes straight to GitHub and never reaches us.

11. Your rights

Under the GDPR you can ask us for access to your data, its correction or erasure, the restriction of its processing, and a portable copy of it. Where we rely on legitimate interest, you can object to the processing at any time. Write to privacy@deplo.build. We answer within one month. We may need to ask you for information to find your data: the statistics and logs are not linked to names, so without, for example, your IP address and the time of your visit we may be unable to identify you (Art. 11 GDPR). You also have the right to lodge a complaint with a supervisory authority: in Italy the Garante per la protezione dei dati personali (garanteprivacy.it), or the authority of the EU country where you live or work.

12. Security

The site is served only over HTTPS. The server, database and analytics sit on infrastructure we administer, reachable only by the maintainer, and the content panel requires a personal login. No system is perfectly secure; if you find a vulnerability, please report it to security@deplo.build.

13. Children

This site is meant for developers and businesses. It is not directed at children under 14, and we do not knowingly process their data.

14. Changes to this policy

When the site starts processing data in a new way, this page changes first. The date at the top always shows the latest version, and a significant change is announced on this page.

Visit statistics on this browser

The switch saves your choice in this browser's local storage and applies from the next page you open. It lasts until you clear your browser data, and you need to set it again on each browser or device you use.