smol machines
cloud registry docs github
terms of serviceacceptable useprivacybilling & refunds

Privacy Policy

Last updated: July 17, 2026

This policy describes what smol machines, inc. ("we") collects when you use smolmachines.com and the hosted platform, and what we do with it. The short version: we collect the minimum needed to run and bill the service, we don't sell your data, and the contents of your machines are yours. smol machines, inc. is the data controller for the personal data described here.

What we collect

  • Account data — your email address and name, received from your sign-in provider (Google or email login via Auth0) when you create an account.
  • Billing data — payment card details are collected and stored by Stripe, our payment processor; we never see full card numbers. We keep records of top-ups, credit balances, and metered usage.
  • Usage and machine metadata — machine names, images, resource sizes, state transitions, and metered consumption (CPU, memory, disk, egress) — the data needed to operate, meter, and bill machines.
  • Operational logs — API request logs (timestamps, endpoints, status codes, IP addresses) and machine lifecycle logs, kept for security, abuse prevention, debugging, and reliability.
  • Website basics — the site uses a session cookie for console login. We do not run third-party advertising trackers.

Your machine contents

The code and data inside your machines, volumes, and exported artifacts are your content. We access it only as needed to operate the service at your direction (running the machine, storing an export you requested), to investigate abuse of the Acceptable Use Policy when we have specific reason to, or when legally required. We do not mine, read, or sell your machine contents.

What we use data for

  • Operating, metering, and billing the service.
  • Transactional email — welcome, waitlist, activation, receipts, and low-balance warnings via Resend. These are service emails, not marketing; account holders receive them as part of the service.
  • Security, abuse prevention (including detection of prohibited workloads like cryptomining), and legal compliance.
  • Aggregated, non-identifying statistics about platform usage.

Who processes data for us

We share data only with the processors that run the service:

  • Google Cloud — compute infrastructure, databases, and logs (US regions).
  • Cloudflare — artifact/registry storage and networking.
  • Auth0 (Okta) — authentication.
  • Stripe — payments.
  • Resend — transactional email delivery.
  • Fly.io — website hosting.

We do not sell personal data, and we do not share it with advertisers.

Retention and deletion

  • Machine data is deleted when you delete the machine; registry artifacts when you delete them.
  • When you close your account, we delete your machines and personal data within 30 days, except records we must keep for billing, tax, or legal reasons (kept only as long as required).
  • Operational logs are retained on a rolling basis and then discarded.

Your rights

You can access, correct, export, or delete your personal data. Depending on where you live (including the EEA/UK under GDPR and California under CCPA), you may have specific statutory rights to the same effect. For any of these, email [email protected] — we will respond within 30 days. Data is processed in the United States; by using the service you consent to that transfer.

Security

Machines run in hardware-isolated micro-VMs with per-machine privilege separation; data is encrypted in transit; access to production systems is restricted. No system is perfectly secure — report suspected vulnerabilities to [email protected].

Changes

We may update this policy; material changes will be announced by email or in the console at least 14 days before taking effect.

© smol machines, inc. · Apache-2.0 · made by @binsquare · twitter · github · engineering · faq · status · terms · privacy