Data we handle
Account data includes your email address, display name, language, login sessions, personal API token metadata and, when used, your Google account identifier. Payment details are collected by Polar; Datry receives subscription, transaction and credit status and does not store full card numbers.
Project data includes source code and Git history, databases, deployment and application logs, domains, email and attachments, uploaded files, alerts, usage measurements, environment variables, MCP connections and MCP audit records. Environment variable values and connected-channel credentials are encrypted; session, OAuth and personal API tokens are stored as one-way hashes.
How we use it
We use this data to authenticate you, run and deploy your projects, provide databases, backups, files, mail and alerts, meter included and paid usage, prevent abuse, troubleshoot failures, provide support and meet accounting or legal duties. We do not sell personal data.
Service providers
Datry uses Vultr for compute and Kubernetes, Cloudflare R2 for encrypted backups and project files, Amazon Web Services for email, Polar for billing and merchant services, and Google for optional sign-in. Slack and browser push providers receive alert data only when you connect those channels. These providers process data under their own security and privacy terms and may operate in other countries.
Retention
- Login sessions: up to 30 days; expired sessions are removed.
- Expired or revoked personal API token metadata: 30 days.
- Alerts and MCP audit records: 90 days.
- Project email and raw MIME: 365 days.
- Database point-in-time recovery: 14 days.
- Encrypted logical DB and control-plane backups: 30 days.
- Active source backups: rolling history up to 90 days, with the newest recovery copy retained while the project exists.
- Deleted projects: 30 days. Closing an account removes live data immediately; encrypted backup copies expire within 30 days.
Transaction records may be retained longer where tax, fraud-prevention or accounting law requires it.
Your choices
From Account and data, you can create or revoke personal API tokens, download a JSON export and permanently close the account. Source code and database dumps are downloaded per project. You can also revoke MCP, Slack and browser push connections. Contact hello@datry.io to request access, correction, deletion or help with an export.
Security and changes
Databases are not exposed publicly, project workloads are isolated by namespace and database role, backups are encrypted, and access tokens are hashed where they do not need to be recovered. No system is risk-free. Material changes to this policy will be published here with a new date.