Privacy Policy
Last updated
We collect as little as we can, we never sell it, and we use no advertising or tracking cookies. Here is exactly what ZENME Cloud stores, why, and for how long.
Who we are and what this covers
ZENME Cloud (“ZENME”, “we”, “us”) is a web dashboard that monitors your ZENME Backup installations and alerts you when a backup fails, goes stale or a machine goes silent. We are the controller of the personal data described here.
This policy covers this website, the waitlist, your ZENME Cloud account and the status data your ZENME Backup installations send us. It does not cover ZENME Backup itself, which runs on your own machines and keeps working whether or not it is connected to us.
The data we collect
We collect only what the service needs. This is the complete list.
| Data | When | Why |
|---|---|---|
| Email address and sign-up country | You join the waitlist | To send you one email when ZENME Cloud launches. The country is worked out from your IP address, which we do not store with your entry. |
| Account name, your name, email address, password | You create an account | To run your account and let you sign in. Passwords are stored only as a one-way hash. |
| Profile photo (optional) | You upload one in settings | To show your avatar. It is cropped and shrunk to a small square and the original is not kept. |
| Session ID, IP address and browser details | You visit any page, signed in or not | To keep you signed in, to protect forms from forged requests and to keep your account secure. See the section on cookies. |
| Country, device type, browser, referring site, campaign tags and engagement | You visit the home page | To understand how people find and use the landing page. See the section on visitor analytics. |
| Backup status data | You connect a ZENME Backup installation | To show your dashboard and send alerts. See the section on machine monitoring. |
We do not run advertising, we do not use third-party analytics or tracking pixels, and we do not buy or sell personal data.
Visitor analytics on the home page
We measure visits to the home page ourselves, without cookies and without storing anything in your browser. For each visit we record:
- A daily visitor code: a keyed hash of your IP address, browser identifier and the date. The code changes every day, so we cannot follow you from one day to the next, and we cannot turn it back into your IP address.
- Your country, looked up from your IP address in a database stored on our own server. Your IP address is never sent to anyone for this.
- The website you came from and any campaign tags in the link (utm_source, utm_medium, utm_campaign).
- Your device type (such as desktop or mobile) and browser name.
- How you used the page: how far you scrolled, which sections you reached, which buttons or links you used and how long the page was in view.
- Whether the visit ended with a waitlist sign-up.
These analytics records contain no IP address, no email address and nothing else that identifies you directly, and visits from known bots and from our own administrators are left out. We delete them after 180 days.
Cookies and browser storage
The visitor analytics above use no cookies. The site itself uses the cookies below, all of which are strictly necessary for it to work:
- A session cookie that keeps you signed in. It is set on every visit, and the matching session record on our server (a random ID, your IP address and your browser identifier) expires after two hours without activity and is then cleaned up automatically.
- A security (XSRF) cookie that protects forms, such as the waitlist form, from forged requests.
- A “remember me” cookie, only if you tick that box when signing in, so you stay signed in for longer.
Your browser also stores your light or dark theme choice and a cache of interface icons, so the site loads faster and does not flicker. These stay on your device and are never used to identify you.
We set no advertising, analytics or other tracking cookies, so there is no cookie banner to accept.
Machine monitoring data
When you connect a ZENME Backup installation, it makes outbound HTTPS requests to us. We never connect into your machine. It sends:
- The machine name you chose and the ZENME, PHP and operating system versions.
- For each database: its backup health, schedule, retention setting, and the latest backup’s status, size, timing and any error message (cut to 500 characters, with file paths and database hosts removed).
- Database and linked project names, and backup file names. By default these are sent as hashes, so we only see a short fingerprint until you give each one a label in ZENME Cloud. You can switch hashing off in ZENME Backup.
- The storage type, name and space used, and whether the scheduler, queue and realtime server are healthy.
- Counts of connected apps.
We never receive your database credentials, your backup files, the contents of your .env file, storage credentials, absolute file paths or the API tokens of your client apps.
We keep the latest snapshot of each machine and a history of health changes for 90 days. Even with hashed names, sizes, timings and schedules still show how active a machine is, so share only what you are comfortable with. Removing a machine or an account deletes its data.
How and why we use your data
- To provide the service (it is necessary to perform our contract with you): running your account, showing your dashboard, sending alerts and keeping you signed in.
- To tell you about the launch (your consent): emailing waitlist members once when ZENME Cloud opens. You can withdraw consent at any time.
- To keep the service safe and improve it (our legitimate interests): preventing abuse and fraud, limiting login attempts, fixing errors and understanding how the landing page performs.
- To meet legal obligations when the law requires us to.
We do not make decisions about you by automated means that have legal or similarly significant effects.
Who we share data with
We never sell your data. We share it only with:
- Service providers that help us run ZENME Cloud, such as hosting and email delivery. They process data only on our instructions and under confidentiality and security obligations.
- Iconify, whose public icon service delivers the small icons you see in the interface. Your browser asks it for icons directly, so it receives your IP address and the names of the icons requested, but nothing about your account.
- The other members of your account, who can see the machines and data in it according to their role.
- Authorities, when the law requires it or to protect our rights, users or the public.
- A successor, if ZENME Cloud is merged with or acquired by another company. We would tell you first and this policy would keep applying.
MaxMind’s GeoLite2 database, which we use to find your country, is downloaded to our server. Lookups happen there, and your IP address is not sent to MaxMind.
How long we keep data
| Data | Kept for |
|---|---|
| Waitlist email and country | Until we have sent the launch email, or until you ask us to remove it |
| Account and profile data | While your account exists, then deleted when it is closed |
| Sessions (cookie, IP address and browser identifier) | Two hours after your last activity, or until you sign out |
| Home page analytics | 180 days |
| Machine health history | 90 days |
| Latest machine snapshot | Until the machine or account is removed |
How we protect your data
Data is encrypted in transit with HTTPS. Passwords are hashed and never stored in readable form. Machines authenticate with tokens that can only report their own status, and enrollment codes are stored hashed, work once and expire after 15 minutes. We rate-limit sign-ins, sign-ups and other public forms to slow down abuse.
No system is perfectly secure. If a breach affects your personal data, we will tell you and the relevant authorities as the law requires.
Your rights and choices
Depending on where you live (for example under the GDPR, the UK GDPR or the CCPA), you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, move it to another service, or withdraw consent you gave us. You will not be treated differently for using these rights.
You can update your name, email, password and photo yourself in your account settings. For anything else, including removing a waitlist email or closing your account, write to [email protected]. We answer within 30 days.
If you think we have handled your data unlawfully, you can complain to your local data protection authority. We would appreciate the chance to put it right first.
International transfers
Our service providers may process data in countries other than your own. When we send personal data out of the European Economic Area or the United Kingdom, we rely on safeguards the law recognises, such as adequacy decisions or standard contractual clauses.
Children
ZENME Cloud is built for people who run servers and backups, and is not directed at anyone under 16. We do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.
Changes to this policy
When we change this policy we update the date at the top. If the change is significant we will also tell account holders and waitlist members by email before it takes effect. Please read our Terms of Service too.
Contact us
Questions about this policy or your data? Write to [email protected].