Privacy Policy
Last updated: September 2026
Controller: BoringTech Ltd
Address: 60 Tottenham Court Road, Office 726, Fitzrovia, London, W1T 2EW
Contact: hello@boringcache.com
This Privacy Policy describes how we collect, use, and share personal data when you use BoringCache.
1. What we collect
Account and identity data
- Name (optional)
- Email address
- Authentication identifiers (e.g., OAuth provider IDs)
Usage and technical data
- IP address and device information
- Logs and event data (e.g., API requests, restore/save events, errors)
- Workspace and configuration metadata
- Performance metrics and diagnostics
Billing data
- Billing contact details
- Plan information and invoices
- Payment method details are handled by our billing provider (e.g., Stripe); we generally do not store full card details.
Customer Content
Customer Content may include reusable Cache state, immutable Artifacts such as binaries and reports, and private Registry content such as OCI images. It may contain personal data if you place it there; do not upload secrets or sensitive personal data.
2. How we use data
We use personal data to:
- provide and operate the Service (auth, restore/save, workspace access)
- prevent abuse, fraud, and security incidents
- provide support and communicate with you (service emails, onboarding, billing)
- process payments and manage subscriptions
- improve reliability and performance (analytics, debugging)
3. Legal bases (UK/EU)
We process personal data based on:
- Contract: to provide the Service you request
- Legitimate interests: security, fraud prevention, product improvement
- Consent: where required for marketing communications
- Legal obligation: accounting, compliance, lawful requests
4. Sharing and subprocessors
We share data with vendors ("subprocessors") necessary to run the Service. Examples include:
- Cloud hosting and infrastructure (e.g., AWS)
- Object storage (managed storage, or customer BYOC bucket when configured)
- Email delivery (e.g., AWS SES)
- Billing (e.g., Stripe)
- Logging/monitoring
We do not sell personal data.
5. BYOC specifics
If you enable BYOC for a workspace:
- Cache objects and Artifacts are stored in your S3-compatible bucket under separate product prefixes
- we may store metadata and identifiers needed to locate and validate Cache content and Artifacts
- Registry storage remains managed by BoringCache and is not stored in your BYOC bucket
- you control your bucket security, encryption, lifecycle, and access policies
6. Cookies and analytics
We use cookies and similar technologies to:
- Essential cookies: keep you signed in and protect against CSRF attacks (always enabled)
- Analytics cookies: understand how you use BoringCache (requires consent)
Analytics data we collect includes: anonymized IP address, browser/device type, country/region, pages visited, and referrer. We do not use third-party advertising trackers.
With your consent, we record the public page where your visit began and a broad source such as Google or a direct visit. We can link that visit to your signup and whether your account later reuses cached work. This measurement does not store search terms, URL query strings, or full referring URLs.
You can change your analytics preference for this browser here at any time. You do not need an account.
Current preference:
7. Data retention
We retain personal data as needed to:
- provide the Service
- meet legal and accounting obligations
- resolve disputes and enforce agreements
Specific storage periods:
- Billing and usage records: kept as needed for accounting and dispute resolution
- Cache entries: ordinary unused cache follows the plan retention period (7 days on Free and 14 days on Standard and Custom), unless a workspace override applies; capacity pressure can reclaim cache earlier, with protected targets reclaimed last
- Artifacts: each Artifact keeps the retention chosen at upload; the default is 90 days, timed retention may be 1–400 days, and an administrator may explicitly make an Artifact permanent
- Registry content: tagged content remains until deletion; unreferenced data is removed after its recovery windows
Cache removal first makes entries unavailable for restore; backing objects are deleted asynchronously. Artifact deletion makes the Artifact unavailable while its exact stored representation is removed. Permanent Artifacts remain deletable by an administrator. Registry deletion removes the selected tag or manifest, while unreferenced blobs follow the Registry recovery and garbage-collection lifecycle.
You can export or delete your data at any time via Privacy Settings.
8. International transfers
Your data may be processed in countries outside your own. Where required, we use appropriate safeguards (e.g., standard contractual clauses).
9. Security
We use reasonable safeguards to protect personal data, including access controls and encryption where appropriate. No method of transmission or storage is 100% secure.
10. Your rights
Depending on your location, you may have rights to:
- access your data
- correct inaccuracies
- delete your data
- object to or restrict processing
- portability
To exercise these rights, visit your Privacy Settings or contact hello@boringcache.com.
11. Marketing communications
If we send product updates or marketing emails, you can unsubscribe using the link in the email. Transactional emails (security, billing) may still be sent.
12. Children
The Service is not intended for children under 16 (or the applicable age in your jurisdiction).
13. Changes to this policy
We may update this Privacy Policy from time to time. We will post updates here and may notify you of material changes.
14. Contact
Questions or requests: hello@boringcache.com