vcpu.sh — Privacy Policy
Version 2 · 7 August 2026

1. Who is responsible

   The controller of personal data described here is Aurora Infrastructure
   EU sp. z o.o., ul. Wadowicka 6/88, 30-415 Kraków, Poland
   (KRS 0001166368). Privacy contact: legal@aurorainfra.ai

   This policy covers data we process to run the vcpu.sh demo service. The
   Aurora Privacy Policy covers Aurora's wider platform, and the Aurora
   Terms (https://docs.aur.lu/docs/legal/terms) govern the underlying infrastructure.

   Anything YOU put inside a demo instance is yours, not ours to use — see
   section 4 on how it is destroyed.

2. What we collect

   Identity
     - Your SSH public key and its fingerprint. This is your identity here;
       we hold no name, email, or password, because we never ask for one.
     - The IP address you connect from.

   Session records
     - Which demo you started, and timestamps: created, ready, ended, and
       how it ended.
     - Activity timestamps and byte counters for forwarded ports and demo
       links — volumes only, never content.
     - Terms acceptance: key fingerprint, terms version, the demo, the time
       of acceptance, and the address it came from.

   Operational and security logs
     - Connection, error, and operator-action logs, which contain IP
       addresses.

3. What we do NOT collect

     - The contents of your terminal session. Input and output are relayed
       between you and the instance, never recorded.
     - The contents of HTTP requests passing through a demo link.
     - Anything inside a demo instance once it is destroyed.
     - We run no advertising, cross-site tracking, or behavioural analytics,
       and we do not sell personal data.

4. Why, and on what legal basis (GDPR Article 6)

     - To provide the service you asked for — creating your instance,
       routing you to it, expiring it: Article 6(1)(b), performance of a
       contract, and 6(1)(f) where you are not the contracting party.
     - To keep the platform secure and fair — enforcing quotas, detecting
       and investigating abuse, verification checks: Article 6(1)(f), our
       legitimate interest in protecting the platform, our customers and
       third parties.
     - To keep a record that terms were accepted: Article 6(1)(f), and
       6(1)(c) where retention is legally required.
     - To respond to illegal-content reports and lawful orders:
       Article 6(1)(c) and 6(1)(f).

5. Where it is processed

   On Aurora infrastructure in the European Union. Aurora's compute region
   is currently France (Albi), with the corporate seat in Poland. Physical
   hosting is provided by Aurora's data-centre partners listed in the
   Aurora documentation. We do not transfer this data outside the EEA.

6. How long we keep it

   Data on a demo instance is destroyed with the instance — the instance
   and its disk are expunged immediately and irreversibly when the session
   ends. We keep no copy and cannot recover it.

   Platform records outlive the instance:
     - Session records, usage ledgers and acceptance records: about 30
       days, which is the window our abuse and quota controls work over.
       Acceptance records may be kept longer as evidence of agreement.
     - Operational and security logs containing IP addresses: kept for a
       limited period for infrastructure and security purposes — as a rule
       no longer than a few months, and up to 12 months where needed for a
       specific investigation, incident, or legal claim.
     - Aggregate statistics with no per-visitor identifiers: kept
       indefinitely.

7. Who else sees it

   Aurora's data-centre providers host the infrastructure. We may disclose
   data where required by law or a valid order from a competent authority,
   and to address abuse. We share it with no one else.

8. Your rights

   Under the GDPR you may request access to your personal data, correction,
   erasure, restriction, portability, and you may object to processing
   based on our legitimate interests. Write to legal@aurorainfra.ai,
   quoting your SSH key fingerprint so we can find the records — it is the
   only identifier we hold.

   Because identity here is just an SSH key, connecting with a different
   key gives us no way to link the two.

   You may lodge a complaint with a supervisory authority — in Poland, the
   President of the Personal Data Protection Office (Prezes Urzędu Ochrony
   Danych Osobowych, ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl) — or with
   the authority where you live or work.

9. Automated decisions

   We do not make decisions about you based solely on automated processing
   that produce legal or similarly significant effects. Automated
   anti-abuse measures (rate limits, the proof-of-work check) are security
   measures; if one blocks you unfairly, contact us.

10. Changes

   We may update this policy. The version is shown above, and material
   changes are reflected in the terms you are asked to accept.


← vcpu.sh