Legal
Privacy policy
How Boson collects, uses, and shares information when you use our control plane, website, and agent.
Last updated September 15, 2026
Overview
This Privacy Policy describes how Boson (“we”, “us”, or “our”) handles information in connection with getboson.com, app.getboson.com, our APIs, and the Boson agent you install on your own servers (together, the “Services”).
Boson is a control plane for deploying and observing containers on infrastructure you operate. We design the product so application code, container images, and primary runtime data stay on your machines whenever possible.
Information we collect
Account and workspace data
When you create an account or workspace we collect identifiers such as your name, email address, authentication credentials (stored hashed), workspace names, membership roles, and billing-related contact details if you provide them.
Product usage and operations data
To run the control plane we process deployment metadata (for example project names, repository references you configure, deploy status, and timestamps), agent pairing and heartbeat status, server inventory you register, configuration you set in the dashboard, and support correspondence you send us.
Gateway and observability data
When you enable gateway-backed observability, we may receive aggregated or sampled request metrics derived from gateway access logs on your VPS (for example route, status class, and latency percentiles). We do not need your application source code to produce these metrics. Retention windows depend on your plan and product settings.
Website and technical logs
Our websites and APIs automatically receive standard technical data such as IP address, user agent, approximate location derived from IP, referrer, and timestamps. We use this for security, abuse prevention, debugging, and reliability.
Cookies and similar technologies
We use cookies and local storage that are necessary to keep you signed in, remember preferences (such as theme), and protect sessions. We do not sell personal information and we do not use third-party advertising cookies on the marketing site.
How we use information
We use information to provide, operate, and improve the Services; authenticate users and enforce access controls; detect fraud, abuse, and security incidents; communicate about product updates, incidents, and support; comply with law; and, with your consent where required, send optional product news.
What stays on your infrastructure
Your application source, build artifacts, container images, environment secrets you keep on the VPS, and primary application databases remain on systems you control unless you deliberately send them to us (for example by pasting content into support tickets).
The Boson agent connects outbound to our control plane. We do not require inbound SSH access to your VPS for normal operation.
Sharing
We share information with subprocessors that help us host and operate the Services (for example cloud infrastructure, email delivery, error monitoring, and payment processors), only as needed to provide those functions under appropriate agreements.
We may disclose information if required by law, to protect rights and safety, or in connection with a merger, acquisition, or asset sale, in which case we will take reasonable steps to keep the information protected.
We do not sell your personal information.
Retention
We retain account and workspace data for as long as your account remains active and as needed for legitimate business and legal purposes. Observability retention follows the windows exposed in the product. When you delete an account or request deletion, we delete or anonymize personal data within a reasonable period unless we must keep it for legal, security, or dispute-resolution reasons.
Security
We use industry-standard measures appropriate to the nature of the data, including encryption in transit, access controls, and least-privilege operational practices. No method of transmission or storage is completely secure; you are responsible for safeguarding credentials, join tokens, and access to your VPS.
International transfers
We may process data in countries where we or our subprocessors operate. Where required, we use appropriate transfer mechanisms.
Your rights
Depending on where you live, you may have rights to access, correct, delete, or export personal data, or to object to or restrict certain processing. Contact us using the details below to exercise these rights. You may also have the right to lodge a complaint with a supervisory authority.
Children
The Services are not directed to children under 16, and we do not knowingly collect personal information from them.
Changes
We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the “Last updated” date. Material changes may also be communicated in-product or by email when appropriate.
Contact
For privacy questions or requests, contact privacy@getboson.com.