1. Who this policy covers
This policy applies to yellowhost's website, Discord sign-in, dashboard and bot-hosting functions. It does not govern Discord, external APIs, databases or other services your bot connects to. Those services have their own privacy practices.
2. Information we collect
Discord account information
When you sign in, we receive your Discord user ID, username, display name and avatar. To protect staff-only dashboard routes, we also request Discord's guilds.members.read permission and check whether you hold configured yellowhost server roles. The signed browser session stores only the recognized yellowhost Admin role when applicable, rather than your full Discord role list.
Account and hosting information
We store your yellowhost account ID, plan/status, bot-slot allowance, bot names and runtimes, container/deployment identifiers, deployment history, build outcomes, runtime status, crash/exit information and administrative/audit events.
Files, logs and bot data
Deployment ZIP files are received for building. Extracted source for current/previous releases is stored on the worker so your bot can run and roll back. Runtime and build logs may contain information printed by your own code. Persistent files your bot writes to its allocated data directory remain on the worker until the bot is removed or the storage is otherwise cleared.
Technical information
Our web server, reverse proxy, hosting provider or security tooling may process IP addresses, request timestamps, user-agent information and similar technical logs needed to operate and protect the service.
3. Why we use information
We process this information to provide the dashboard and hosting service; authenticate users; enforce plan and bot-slot limits; build and run workloads; diagnose crashes; provide rollback and logs; secure the service; investigate abuse; enforce the AUP; communicate service changes; and comply with legal obligations.
Depending on applicable law and the context, these activities may rely on performance of our agreement with you, our legitimate interests in operating and securing the service, consent where required, or compliance with legal obligations.
4. Environment variables and secrets
Environment-variable values are encrypted before they are stored in PostgreSQL. Their plaintext values are not returned to the dashboard after saving. When a deploy or rollback requires them, the web server decrypts the values server-side and sends them to the authenticated worker so they can be injected into the bot container.
No system can promise absolute security. Treat bot tokens and API keys as sensitive, rotate them if you suspect exposure, and avoid printing them to your logs.
5. Cookies and sessions
yellowhost uses an essential signed, HTTP-only session cookie to keep you logged in. We do not currently use advertising cookies or sell browsing profiles for advertising. If analytics or additional cookies are introduced later, this policy and any required consent controls will be updated.
7. Retention and deletion
We keep account and hosting records for as long as needed to provide and secure yellowhost. Deleting a bot removes its worker container and bot directory, including worker-side release snapshots and persistent bot data. Database records may be retained as deleted/tombstoned records, together with deployment and audit history, where needed for security, abuse prevention and operational records.
During beta, some deletion requests may require manual action. You can request deletion of your yellowhost account and associated personal information by emailing support@yellowhost.cc. We may retain limited records where required by law or reasonably necessary for security and abuse prevention.
8. Your rights and choices
Depending on where you live, privacy law may give you rights to request access, correction, deletion, restriction or portability of personal information, or to object to certain processing. You may also have a right to complain to your local data-protection authority. Contact support@yellowhost.cc to make a request. We may need to verify your identity before completing it.
9. Security
Current safeguards include signed HTTP-only sessions, server-side authorization, encrypted environment values, authenticated worker requests, non-root containers, dropped Linux capabilities, read-only application mounts, resource limits and audit logging. Security is an ongoing process, and the beta service should not be used as the only copy of critical data.
10. International processing
Infrastructure and service providers may process information in countries different from your own. Where required, we will use appropriate safeguards for international transfers as the production provider stack is finalized.
11. Children's privacy
yellowhost is not intended for anyone who is not old enough to use Discord or to consent to the relevant online service under applicable law. If we learn that an account was created in violation of those requirements, we may suspend or delete it.
12. Changes and contact
We may update this policy as yellowhost's infrastructure and features change. Material updates will be announced where reasonably practical. Privacy questions and requests can be sent to support@yellowhost.cc.