CC-ON-DEMAND SHEET 001 ↗

SHEET 003 · LEGAL

Privacy Policy

EFFECTIVE: 20 AUGUST 2026 · ONE SESSION COOKIE · NO TRACKERS · EU RESIDENCY

This policy is written the way the sheets are drawn: it lists what is actually collected, by name, and nothing that is not.

§ 1WHO IS RESPONSIBLE

cc-on-demand ("we") operates the service at cc-on-demand.com and its subdomains and is the data controller for the personal data described here. For anything in this policy — questions, complaints, or exercising your rights — write to support@cc-on-demand.com.

§ 2WHAT WE COLLECT

counted, by name — this is the complete list.

  • Google profile data — when you sign in with Google we receive and store your Google account identifier, email address, and display name. We request no other Google scopes and never see your Google password.
  • Credentials you save — git access tokens, model-provider keys (Anthropic, Claude subscription tokens, OpenRouter and similar), and dotfiles repository URLs you enter in the portal. Tokens and keys are stored encrypted at rest with AES-256-GCM; the portal displays only a short hint (last characters), never the value.
  • Workspace metadata — workspace names, sizes, machine and volume identifiers, lifecycle state, timestamps (including last-seen activity used for idle parking), and error information from the machine runtime.
  • Audit log — a record of security-relevant actions on your account: sign-ins, admin actions, workspace lifecycle events, credential changes (names of what changed — never the values), and API-key creation or revocation.
  • Mail log — a record of transactional emails we sent you (recipient, template, timestamp, delivery outcome).

The contents of your workspace volumes (your code and files) are stored to run the service but are not read, indexed or analyzed by us; administrators access a workspace's contents only for debugging with your consent or when investigating suspected abuse under our Terms.

§ 3WHAT WE DO NOT COLLECT

the absence is deliberate.

The websites set one cookie: a session cookie, HttpOnly and restricted to our API host, that exists only to keep you signed in. There are no analytics trackers, no advertising pixels, no fingerprinting, and no third-party cookies. This promo site sets no cookies at all. We do not sell or share personal data for advertising — there is nothing of the kind to sell.

§ 4WHERE DATA LIVES

Workspaces, volumes, the control-plane database and its backups run in Frankfurt, Germany (EU) on Fly.io infrastructure. Web traffic passes through Cloudflare's global edge network on its way there. Email you receive from us is sent through Cloudflare's email service.

§ 5SUBPROCESSORS

counted: 3.

  • Fly.io, Inc. — compute, volumes, and the control-plane database (Frankfurt, EU).
  • Cloudflare, Inc. — DNS, static-site hosting, and transactional email delivery.
  • Google LLC — sign-in only (Google OAuth). Google acts here as your identity provider under its own privacy policy.

Model providers (Anthropic, OpenRouter, and others) are not our subprocessors: agent traffic from your workspace to a model provider is made with your own credentials, under your own agreement with that provider.

§ 6HOW LONG WE KEEP IT

Account data, saved credentials, and workspace volumes persist while your account exists. Destroying a workspace deletes its machine and volume (final snapshots expire on the infrastructure provider's schedule, at most 14 days). Deleting your account — self-serve from the portal — destroys your workspaces and volumes, purges credential ciphertexts, revokes API keys, and anonymizes your audit- and mail-log entries; a deletion confirmation is the last email we send you.

§ 7YOUR RIGHTS

gdpr rights, exercised by email — no forms, no dark patterns.

Where the GDPR or a similar law applies to you, you have the right to access the personal data we hold about you, to have it corrected or erased, to receive a portable copy, to restrict or object to processing, and to lodge a complaint with your local supervisory authority. Erasure is available self-serve as account deletion (§ 6); for everything else, email support@cc-on-demand.com and we will answer within 30 days.

Our legal bases are: performance of a contract (running your account and workspaces), legitimate interest (security, audit logging, abuse prevention), and legal obligation where applicable.

§ 8SECURITY

Credentials are encrypted at rest with AES-256-GCM and injected only into machines belonging to your account. Sessions use HttpOnly, Secure cookies. Workspaces run on an isolated private network with no public IP addresses and no network path back to the control plane. No measure is perfect; if we learn of a breach affecting your data, we will notify you without undue delay.

§ 9CHANGES

We may update this policy. Material changes are announced by email and by updating the effective date above. The current version always lives at cc-on-demand.com/privacy/.