Infrly
Home Terms of Use
Sign in Get started
Legal

Privacy Policy

Effective date: September 8, 2026  ·  Last updated: September 8, 2026

This Privacy Policy explains how Infrly ("Infrly," "we," "us," or "our") collects, uses, discloses, and protects information when you visit infrlyapp.com (the "Site"), use the Infrly dashboard and API at app.infrlyapp.com, or otherwise use our platform for deploying and running web services, static sites, cron jobs, and managed PostgreSQL databases (together, the "Service"). It applies to visitors, registered account holders, and, where relevant, end users of applications that our customers deploy through the Service.

Template notice. This document is drafted specifically for how Infrly's product works today. Infrly is operated by Infrly Inc. The registered address and governing-law jurisdiction below are still placeholders — [Registered Address] and [Governing Law Jurisdiction] — pending confirmation. Replace these (and have the final text reviewed by qualified counsel) before relying on it as a binding policy.
On this page
  1. Who We Are
  2. Scope of This Policy
  3. Information We Collect
  4. How We Use Information
  5. Legal Bases for Processing
  6. Cookies & Similar Technologies
  7. How We Share Information
  8. Data Retention
  9. Data Security
  10. International Data Transfers
  11. Your Privacy Rights
  12. Children's Privacy
  13. Content You Deploy & End-User Data
  14. Third-Party Links & Services
  15. Changes to This Policy
  16. Contact Us

1. Who We Are

Infrly is a platform-as-a-service product operated by Infrly Inc. ([Registered Address]). We run the infrastructure that builds, deploys, and hosts your applications, static sites, scheduled jobs, and managed databases from a git push. For the purposes of applicable data protection law, Infrly Inc. is the data controller of the personal data described in Sections 3–8 of this Policy, except where Section 13 says otherwise.

2. Scope of This Policy

This Policy covers personal data we process as the operator of the Site and the Service. It does not cover:

  • Content or data that a customer's own deployed application collects from that application's end users — see Section 13, which explains our role as a processor for that data.
  • Third-party websites or services we link to or integrate with, which are governed by their own privacy policies.

3. Information We Collect

3.1 Account & authentication information

Infrly uses GitHub as the sole sign-in method — we do not operate a separate username/password system. When you sign in with GitHub, we receive your GitHub user ID, username, public profile information (such as your name and avatar), and your email address if your GitHub privacy settings and the permission scope you grant make it available. We also receive a repository access token scoped to the permissions you authorize (used to clone repositories and register push webhooks for the projects you connect). This token is encrypted at rest and decrypted only transiently, server-side, to perform the specific action you've requested — it is never logged, displayed, or returned to any client, including your own browser.

3.2 Deployment & infrastructure data

To operate the Service, we process data about the services and projects you create, including: project and service names and configuration; the source repository and branch you connect and its build/start commands; environment variables and secrets you configure (encrypted at rest); build logs and runtime logs generated when your code is built and run; resource usage metrics (CPU, memory, disk, network, and — for Cron Jobs — execution duration) that we use to operate the platform and calculate usage-based charges; custom domain and DNS configuration you provide; and connection metadata for any Managed PostgreSQL database you provision. We do not read or analyze the contents of your database's tables except as strictly necessary to perform an automated backup or restore, or at your explicit request for support.

3.3 Billing & payment information

Payments are processed by Stripe, Inc. Infrly does not collect or store your full card number. Stripe collects your payment details directly and shares with us only what's necessary to operate your account — a masked card summary (e.g., brand and last four digits), billing name and address if you provide one, subscription and invoice history, and your account balance or credit. Stripe's own handling of your payment details is governed by Stripe's privacy policy.

3.4 Session & device information

When you sign in, we create a session identified by a securely generated, random token stored in an httpOnly cookie in your browser. We do not store that token in readable form — only a one-way cryptographic hash of it — alongside metadata such as an approximate device/browser identifier (user agent), the IP address at sign-in, and session creation and last-seen timestamps. We use this to keep you signed in, to let you view and revoke your active sessions, and to detect suspicious activity such as sign-ins from unfamiliar contexts.

3.5 Communications

If you contact us for support, we retain that correspondence to respond to you and to maintain a record of the interaction. If we send you a transactional email — such as a new-login notification, a deployment-failure alert, a service health alert, or a billing notice — we retain delivery metadata (e.g., whether the message was sent and delivered) to operate the notification system. These emails are sent via our transactional email provider from an infrlyapp.com sending address.

3.6 Analytics & usage data

We use a product analytics tool (Google's Firebase/Google Analytics) on both the Site and the app to understand how they're used: page views, feature-interaction events (for example, that a project was created or a deployment succeeded), approximate device and browser type, and a pseudonymous client identifier stored via cookie. We use this in aggregate to improve the product; we do not use it to build advertising profiles about you, and we do not sell it.

3.7 Log & technical data

Our servers and edge network automatically log standard technical information for security and operational purposes, such as request timestamps, source IP address, requested URL, and response status — for both the Site/app and for traffic reaching applications you deploy through the Service (see Section 13 for the latter).

4. How We Use Information

We use the information described above to:

  • Provide, operate, and maintain the Service, including building, deploying, and running your services, sites, cron jobs, and databases;
  • Authenticate you and keep your account secure;
  • Process payments, calculate usage-based charges, and manage billing;
  • Send service, security, and billing communications, including the notifications described in Section 3.5;
  • Provide customer support and respond to your requests;
  • Monitor, debug, and improve the reliability, performance, and security of our infrastructure;
  • Detect, prevent, and investigate fraud, abuse, and security incidents;
  • Understand how the Service is used, in aggregate, to guide what we build next; and
  • Comply with our legal obligations and enforce our Terms of Use.

5. Legal Bases for Processing

If you are located in the European Economic Area, the United Kingdom, or another jurisdiction requiring a legal basis for processing personal data, we rely on the following:

  • Performance of a contract — to create your account, provision and operate the services you configure, and process billing for a plan you've selected;
  • Legitimate interests — to secure the platform, prevent fraud and abuse, maintain and improve the Service, and communicate with you about your account, weighed against your interests and rights;
  • Consent — for non-essential cookies/analytics where required by local law, and for optional marketing communications, both of which you may withdraw at any time; and
  • Legal obligation — to comply with tax, accounting, and other applicable law, and to respond to lawful requests from public authorities.

6. Cookies & Similar Technologies

We use a small number of cookies:

  • Essential/session cookie — an httpOnly cookie that identifies your signed-in session. This is required for the app to function and cannot be disabled without signing you out.
  • Analytics cookies — set by our analytics provider to distinguish visitors and measure usage of the Site and app, as described in Section 3.6.

You can control non-essential cookies through your browser's settings, including blocking or deleting them; doing so may affect the accuracy of our usage analytics but will not prevent you from signing in or using the Service. We do not use cookies for third-party advertising.

7. How We Share Information

We do not sell your personal data. We share information only in the following circumstances:

7.1 Service providers (subprocessors)

We use a small number of third-party providers to operate the Service, each processing only what's necessary for their function:

  • GitHub — authentication, repository access, and webhook delivery;
  • Stripe — payment processing and billing;
  • Brevo — delivery of transactional email (notifications and alerts);
  • Google (Firebase/Google Analytics) — product analytics;
  • Hetzner — the underlying servers and infrastructure our platform runs on; and
  • Cloudflare — DNS management and automated TLS certificate issuance for the Site, the app, and your custom domains.

7.2 Legal & safety disclosures

We may disclose information if required by law, subpoena, or other legal process, or where we believe in good faith it's necessary to protect the rights, property, or safety of Infrly, our users, or the public, or to detect, prevent, or address fraud, security, or technical issues.

7.3 Business transfers

If Infrly is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction; we'll provide notice before your information becomes subject to a different privacy policy.

8. Data Retention

We retain information for as long as necessary to provide the Service and for the purposes described in this Policy:

  • Account information is retained while your account is active and for a reasonable period afterward to allow for reactivation and to comply with legal obligations.
  • Build and runtime logs are retained on a rolling basis (currently around 30–90 days, depending on log type) to support debugging and platform operations, then deleted.
  • Billing and invoice records are retained for as long as required by applicable tax and accounting law.
  • Session records are deleted once a session expires or is revoked.
  • Database backups are retained per your plan's configured retention window and deleted, along with the underlying database, after the grace period described in our Terms of Use.

9. Data Security

We use technical and organizational measures designed to protect your information, including:

  • Encryption in transit (TLS/HTTPS) across the Site, the app, and every deployed service and custom domain, with certificates issued and renewed automatically;
  • Encryption at rest for GitHub access tokens and for the environment variables and secrets you configure, with the encryption key managed separately from the encrypted data;
  • Password-less authentication — since sign-in is exclusively via GitHub OAuth, we never store a password for your account;
  • Session tokens stored only as a cryptographic hash, never in plaintext;
  • Network isolation between customer projects, with enforced resource limits for each project.

No method of transmission or storage is 100% secure. If you believe you've found a security vulnerability in the Service, please report it responsibly to [security@infrlyapp.com].

10. International Data Transfers

Infrly's infrastructure is hosted with our infrastructure provider, Hetzner ([data center region(s) — to be confirmed]). Some of our service providers (including GitHub, Stripe, and Google) may process data in the United States or other countries outside your own. Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards recognized under applicable law, such as Standard Contractual Clauses.

11. Your Privacy Rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you;
  • Correct inaccurate or incomplete data (most account data is sourced from your GitHub profile and can be updated there);
  • Delete your personal data, subject to our legitimate need to retain certain records (e.g., billing) as described in Section 8;
  • Export your data in a portable format;
  • Restrict or object to certain processing, including processing based on legitimate interests; and
  • Withdraw consent at any time where processing is based on consent, without affecting processing that occurred before withdrawal.

To exercise any of these rights, contact us at [privacy@infrlyapp.com]. We may need to verify your identity before acting on a request. If you're in the EEA or UK, you also have the right to lodge a complaint with your local data protection supervisory authority. If you're a California resident, you have rights under the CCPA/CPRA to know what personal information we collect, request its deletion, and opt out of its "sale" or "sharing" — we do not sell or share personal information as those terms are defined by California law, and we will not discriminate against you for exercising any of these rights.

12. Children's Privacy

The Service is not directed to children, and GitHub itself requires account holders to meet its own minimum age (currently 13). We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us at [privacy@infrlyapp.com] and we will take appropriate steps to remove it.

13. Content You Deploy & End-User Data

If you use Infrly to deploy your own application, and that application itself collects personal data from its own end users (for example, your SaaS product's customers), you are the data controller for that data, and Infrly acts only as a data processor / service provider, processing it solely on your behalf and per your instructions, to the extent necessary to provide the underlying hosting infrastructure (running your code, storing your database, delivering your network traffic). You remain responsible for your own compliance obligations toward your end users, including providing appropriate privacy notices and establishing a lawful basis for your own processing.

Infrly personnel do not access, use, or analyze the substantive content running through your deployed applications or stored in your databases, except as strictly necessary to: (a) operate, secure, or troubleshoot the platform; (b) respond to a support request you initiate; or (c) comply with a legal obligation. If you require a Data Processing Addendum to support your own compliance program, contact us at [privacy@infrlyapp.com].

14. Third-Party Links & Services

The Site and app may link to or integrate with third-party services — for example, GitHub, or Stripe's hosted checkout and billing portal. Those services are governed by their own privacy policies, and we encourage you to review them; we are not responsible for the privacy practices of third parties.

15. Changes to This Policy

We may update this Privacy Policy from time to time. We'll revise the "last updated" date above, and for material changes we'll provide reasonable notice — such as an email to the address associated with your account, or a notice on the Site or in the app. Your continued use of the Service after a change takes effect constitutes your acceptance of the updated Policy.

16. Contact Us

If you have questions about this Privacy Policy or how we handle your information, contact us at:

Infrly Inc.
[Registered Address]
Email: [privacy@infrlyapp.com]

↑ Back to top
Infrly
Sign in Services How it works References
© 2026 Infrly Inc. You commit. We ship.
Privacy Policy · Terms of Use