ExtraHosting · Service policies
Privacy policy
How account information, project data, and service records are handled.
Last updated
ExtraHosting handles your account and project information to provide hosting, secure access, and diagnose problems. You control your repositories, collaborators, project secrets, and optional integrations.
01About this policy
This policy describes how the ExtraHosting service handles information when you sign in, connect integrations, and host projects. It covers the hosting dashboard and service operations.
Your hosted bot may collect information from its own users. You control that activity and are responsible for explaining it to those users. This policy does not replace your bot’s privacy notice or the policies of Discord, GitHub, or other services your project uses.
02Information we handle
- Account information: your Discord identifier, username, display name, and avatar; profile customisations; account role; and security settings you enable.
- GitHub connections: your GitHub account identifiers, authorised installations and repositories, and credentials needed to access repositories you permit.
- Project information: repository and branch details, deployment settings, source code, build files, environment variables, persistent data, and backups you create or schedule.
- Hosting records: plan access, resource allocations, requests, project ownership, and collaborator permissions.
- Operational and security records: deployment and runtime logs, resource measurements, audit events, session timestamps, IP addresses, and browser or device information supplied with requests.
- Optional integrations: webhook destinations, status-page settings, and Discord Activity connection settings when you enable those features.
03How information is used
Account and session information identify you and control access. GitHub and project information let us import repositories, build releases, run your bot, and provide project controls, logs, and backups.
Resource measurements help enforce plan limits and manage safe hosting capacity. Security and audit records help investigate access, diagnose failures, and prevent abuse. Settings for optional features are used to deliver the features you choose.
Discord identity information is required for the current sign-in flow. Repository access is required to deploy a GitHub project. You can leave optional features disabled, but removing an integration needed by a project may prevent deployments or related features from working.
05Access and connected services
Authorised administrators can access operational records and manage hosting as needed to operate the service. Collaborators can access project information according to the permissions you grant them.
Discord processes sign-in requests, and GitHub processes repository and authorisation requests. Infrastructure services used to run ExtraHosting process the information required for hosting, storage, and network delivery.
Enabling webhooks sends event information to the destination you choose. Sharing a project status-page link makes the published status information accessible to people with that link. Your bot’s own connections send data to the services your code chooses.
Information may also need to be disclosed to comply with applicable legal obligations or respond to a security incident. Ask your hosting administrator about the infrastructure providers and storage locations used for your hosting arrangement.
06Protecting credentials and data
ExtraHosting encrypts stored project environment-variable values and GitHub access credentials. Session tokens are stored as hashes. Access controls limit which accounts can read or change project information.
Project secrets must be made available to the runtime when your bot runs. Your code, dependencies, collaborators, and configured destinations can affect their security. Do not print tokens or sensitive personal data to logs, and rotate credentials if they may have been exposed.
No hosting or transmission method can guarantee complete security. Review account sessions, project permissions, and integration access regularly.
07Retention and deletion
Account, integration, and project records are stored to maintain access and provide hosting. Sessions have an expiry time. Searchable project logs are subject to configured age and line limits, and older entries are removed as those limits are reached. Resource history and project audit history are also bounded.
Snapshot retention depends on your plan and backup configuration. Project deletion triggers workload and file cleanup; it does not promise immediate removal of every historical audit record or copy in infrastructure backups.
There is currently no single automatic deletion period for all account and administrative records. Contact your hosting administrator to request account deletion or ask about the retention settings and any legal or security reasons for retaining particular records.
08Your choices and requests
You can review sessions and sign out devices, manage project collaborators and environment variables, disable optional integrations, and delete projects using the dashboard. You can also revoke ExtraHosting’s authorisation through Discord or GitHub.
Depending on the law that applies to you, you may have rights to access, correct, delete, or receive a copy of your personal information, restrict its use, or object to processing. Where processing relies on consent, you may withdraw it. You may also raise a complaint with your local data protection authority.
Send privacy requests to the ExtraHosting administrator who manages your hosting access through your existing contact channel. Identify your account and what you need; identity verification may be required. Do not include passwords, bot tokens, or other secrets.
09Updates and contact
This policy may change when the service or its data handling changes. The last-updated date identifies the current version.
For privacy questions, including provider locations, retention, or account closure, contact your hosting administrator through the channel used to arrange hosting. See the Terms of service for hosting conditions.