Privacy Policy
Last updated: 22 August 2026
Isomux LLC ("we") runs Hosted Isomux: we rent a server for you, set it
up with isomux, and serve it at yourname.isomux.app. This
policy covers that service and the isomux.com website. It does not cover
isomux the source-available program itself, which collects no data at
all: no telemetry, no statistics, nothing sent to us or anyone else.
What we collect
At signup: your email address and the identifier Google assigns to your account. The office name you pick becomes your web address. Addresses with HTTPS certificates land in public certificate logs, so pick a name you don't mind strangers seeing. Your browser creates a server administrator key. We receive its public half and install it on your server so you can access it with the private half. The private key is not sent to us. We keep the public key only while we set up your server. After that, we keep only its fingerprint, which confirms which key was installed. For safety reasons, Isomux agents and the built-in terminal cannot act as a privileged user. Only you can do so with the administrator key.
Payment: Stripe handles the card. We never see or store card numbers. Stripe keeps your invoices. We keep billing details such as your Stripe customer and subscription identifiers, subscription status, plan, and latest invoice identifier.
Provisioning log: a structured record of setup steps, with the time and outcome. It does not store raw commands or command output.
Support: whatever you send us when you ask for help. Support messages include rescue requests and our record of how we handled them.
What we cannot see
Nothing inside your office passes through us. Your conversations, your files, your agents' work, and the Claude and ChatGPT credentials you sign in with from inside it never reach our systems, and once our setup key is removed we have no way into the running office either. The one exception is the rescue route in the next section, which happens only if you ask for it in writing.
We hold an SSH key to your server while we set it up. If you confirm from your office that you are in, we remove the key, prove the removal by requiring a reconnect attempt to fail, and destroy our copy. If you do not confirm, the server makes the key unusable seven days after signup and removes it during cleanup. You can also confirm the result yourself if you added your own SSH key at signup.
What we can still do, because we rent the server
We hold the account at the server provider, so we keep the controls any renter keeps: reboot, power off, reinstall (which erases the disk), and the provider's rescue console, which can reach the disk. We do not open the rescue console unless you ask us to in writing about a specific problem; we record what we do, and the access ends with the problem. The terms of service state this in full.
Who else handles your data
| Company | What for |
|---|---|
| At sign-in, we keep only the email and account identifier Google returns. We don't keep your name. On the Hosted Isomux signup page, Google Analytics counts page visits and receives the page name, rough location, and device type, but not the office name, signup errors, or referring page. | |
| Stripe | Payments and invoices. |
| Contabo | The VPS provider your server is rented from. It can reach the machine; its own privacy policy governs what it may do with that access. |
| Cloudflare | DNS for your address. |
| Vercel | Serves the isomux.com website and your account dashboard, so it sees your visits. |
| Neon | Stores the hosted account, subscription, setup status, and operational records. It does not receive your office content. |
| Anthropic | Answers from the chat widget on isomux.com. |
| Discord | Conversations with the isomux.com chat widget are relayed there - never your office's chats. |
If we change any of these, this list changes with it, with the same notice as any other change to this policy.
How long we keep it
Your server: it runs through the period you paid for. At the end of that period, it is powered off and access stops. After 14 days, we ask the provider to delete it as soon as the provider permits. The provider controls the exact deletion time.
If payment fails: Stripe retries first. If the retries run out, we power the server off, but we do not automatically delete it on a fixed schedule. Service resumes if payment succeeds.
Billing records: kept as long as tax and accounting law requires.
Backups
Isomux keeps seven daily backups on your server. You can keep external copies for additional protection.
The isomux.com website and Hosted Isomux signup page
The isomux.com website and the Hosted Isomux signup page count page visits with Google Analytics. The isomux.com website also uses Vercel Web Analytics. These services record the page, your rough location, and your device type; on isomux.com, they also record where you came from. The Hosted Isomux signup page sends no office name, signup error, or referring page. Vercel's documentation states that it sets no third-party cookies and that the data cannot identify individual visitors. The chat widget sends your messages to Anthropic to write the answer, and also relays the conversation, your IP address, your browser string, and the page you were on to a private channel we read, so we can see what people are asking. Do not type anything private into it.
Your data
Write to llc@isomux.com to ask what data we currently hold about you or ask us to delete it. The data that has no scheduled deletion is: your account record, the provisioning log, support messages, and chatbot transcripts.
Changes
If we change this policy we will say so on this page before the change takes effect.