Privacy policy
Last updated 28 August 2026. The data controller for account and usage data is Roman Voronin, operating from Portugal; write to axela@system5.dev about anything on this page.
Two roles, stated plainly
For your account, your organisations and this site's own logs, we are the controller: we decide what is held and why, and this page describes it.
For the events your organisation's machines file — which may name machines, hostnames and, through them, the people who use them — your organisation is the controller and we are its processor: we store and serve that data on the organisation's instructions and use it for nothing else. The terms of service contain the processing commitments that make this binding.
What we hold, why, and on what legal basis
- Your account
- An email address and an identifier, from the sign-in you chose. If you sign in with
Google, Google tells us your email address and an account identifier and nothing else —
no name, no picture, no contacts. If you sign up with an email and password, the password
is held by Amazon Cognito and never reaches us.
Basis: performing our contract with you (GDPR art. 6(1)(b)). - Your organisations
- The name you registered, the GitHub repository you allowed to publish, the public
keys you pinned, and which account owns it. Your API tokens are not held: only a SHA-256
digest of each, which is why a lost token is rotated rather than recovered.
Basis: performing our contract with you (art. 6(1)(b)). - What you publish
- The catalogs you sign — the names, versions and content digests of your plugins, with
your signature and ours.
To check a catalog before signing it, we also download your repository at the commit you published from and read the files in it. That copy is held only for the seconds the check takes and is not stored: what remains is the catalog, the signatures, the digests and the result of the check.
Basis: performing our contract with you (art. 6(1)(b)). - What your machines report
- The events your machines choose to file: a machine name, an optional hostname, the
marketplace and plugin concerned, digests, and a timestamp. Nothing is collected from a
machine that does not send it, and the reporting is something your organisation switches
on.
Held as your organisation's processor, on its instructions. - Server logs
- Ordinary request logs, which include IP addresses, kept for 14 days and then deleted
automatically. They exist to debug failures and to protect the service from abuse, and
nothing else.
Basis: our legitimate interest in running a secure, working service (art. 6(1)(f)). - Email we send you
- Notices about your account and material changes to the service or these documents.
No marketing, no newsletter.
Basis: performing our contract and our legal obligations to notify you (art. 6(1)(b), (c)).
What we never hold
Private signing keys, plugin contents, payment details, and anything gathered for advertising. There are no advertising or analytics trackers on this site. No decision about you is automated in a way that has legal or similarly significant effect.
Cookies
Two, both strictly necessary, which is why there is no consent banner: the cookie that keeps you signed in, and a short-lived one that protects the sign-in itself from being hijacked. Neither tracks you, and there are no third-party cookies.
Who processes it for us
Two sub-processors, and no others:
- Amazon Web Services
- Stores and runs everything above, in the us-east-1 (N. Virginia) region. Because that is in the United States, this is a transfer outside the EEA; it is covered by the EU–U.S. Data Privacy Framework, which AWS is certified under, and by the standard contractual clauses in AWS's GDPR data processing addendum.
- Only if you choose to sign in with Google, and only to the extent of that sign-in.
Nobody else: we do not sell, rent or share any of it, and there is no third party we send it to for analysis. We would disclose data if a valid legal order compelled it. That has never happened; if it does and the order allows it, we will tell you.
How long
Account and organisation records last as long as your account. Published catalogs stay until you replace or delete them, because your machines fetch them. Machine events stay until your organisation deletes them or itself. Logs go after 14 days. Ask us to delete your account and we delete all of it — after which machines pinned to your catalog stop receiving updates, and, being offline-first, keep refusing changes rather than accepting them.
Your rights
Under the GDPR you can ask us for access to what we hold about you, for a copy you can take elsewhere, for correction, for deletion, for restriction of processing, and you can object to processing based on our legitimate interests. Write to axela@system5.dev; we will answer within 30 days, and we will not charge for it.
You also have the right to complain to a supervisory authority. Ours is the Portuguese one, the CNPD (cnpd.pt); you may equally complain to the authority of the country where you live or work. Axela is operated from the European Union, so the GDPR applies to it whoever you are and wherever you are.
Changes
If this page changes in a way that affects what we collect or who sees it, we will email the address on your account before the change takes effect.