Privacy Policy
Effective 9 September 2026
Inetgarden gives infrastructure operators bounded, time-limited access to machines they already control. This policy describes what we collect to do that, where it is held, and how you remove it.
Who is responsible
Inetgarden operates this service and decides how the data below is handled. Reach us at hello@inet.garden for any question about this policy or about your data.
What we collect, and why
| Data | Why we hold it |
|---|---|
| Your email address and the identifier your sign-in provider gives us | To recognise your account and decide what you may reach |
| Display name, locale, time zone and theme, if you set them | To present the service the way you asked for |
| Rooms, invites and saved destinations you create | These are the product; without them there is nothing to return to you |
| Session records, including sign-in time and session version | To keep you signed in and to let you revoke sessions |
| Meeting-provider connections you choose to make | To create meetings on your behalf when you ask |
| Subscription state, if you buy a paid plan | To grant the plan you paid for |
| Server logs, including request paths, status codes and timestamps | To operate the service and investigate faults and abuse |
We do not use advertising or analytics trackers, we do not sell personal data, and we do not build
profiles for advertising. The service sets one cookie, __Host-inetgarden-session, which exists
solely to keep you signed in.
Sign-in
Signing in uses Google. We receive the email address and basic profile information associated with the Google account you choose. We never receive your Google password.
Access to your machines
When you connect to a destination, the session carries your terminal traffic between your browser and the machine you named. We do not record the contents of your terminal sessions as part of normal operation. We do record that a session happened, who joined it, and when it closed, because that record is what makes bounded access reviewable.
Meeting providers
If you connect Zoom or Microsoft Teams, we store the authorisation the provider issues so we can create meetings when you ask. Those credentials are encrypted with Google Cloud KMS before they are written, and each one is bound to your account so it cannot be decrypted for anyone else. Disconnecting the provider deletes the stored authorisation. See Using Inetgarden with Zoom for the Zoom detail.
Payments
Paid plans are handled by Stripe on pages Stripe hosts. Card numbers never reach Inetgarden and we never store them. We keep the customer and subscription identifiers Stripe returns, and the plan you hold.
Where your data is held
Account data is stored in Google Cloud Firestore in the United States, in the us-central1
region. The service runs on Google Cloud Run in the same region. If you are outside the United States, using
Inetgarden means your data is transferred there.
Who else processes it
- Google Cloud — hosting, storage, encryption keys, logging
- Google Identity — sign-in
- Stripe — payments, only if you buy a paid plan
- Zoom and Microsoft — only if you connect them yourself
How long we keep it
Account data is kept while your account exists. Deleting your account removes your profile, rooms, saved destinations and provider connections. Server logs are retained for a limited operational period and then expire. Records we must keep for tax or accounting reasons are kept for as long as the law obliges.
What you can do
- See it — your profile page shows the account record we hold.
- Export it — request a machine-readable copy of your account data from your profile.
- Correct it — display name, locale, time zone and theme are editable at any time.
- Delete it — deleting your account removes it. This cannot be undone.
- Revoke sessions — sign every browser out immediately from your profile.
- Disconnect providers — removes the stored authorisation at once.
Depending on where you live you may also have the right to object to or restrict processing, or to complain to a data protection authority. Write to hello@inet.garden and we will act on the request.
Security
Traffic is served over HTTPS. Provider credentials are encrypted with managed keys. Deployments are pinned to exact content digests, so what runs is what was reviewed. No service is perfectly secure; if you believe you have found a vulnerability, please write to us before disclosing it publicly.
Children
Inetgarden is a tool for professional operators and is not directed at children. We do not knowingly collect data from anyone under 16.
Changes
If this policy changes in a way that affects you, we will update the effective date above and, for material changes, tell account holders directly.