> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ohmyho.st/llms.txt
> Use this file to discover all available pages before exploring further.

# Privacy notice

Effective date: September 13, 2026.

## 1. Responsibility and contact

amerged B.V., Netherlands, operates ohmyho.st. We are the controller for personal data used to operate our website, manage accounts, answer enquiries, administer billing and protect the service. Use our [contact form](https://ohmyho.st/contact) for all privacy questions and requests to exercise your rights.

When a customer uses ohmyho.st to process personal data in an application, the customer determines its purposes and lawful basis. We process that customer data on documented instructions under our [Data Processing Agreement](https://ohmyho.st/dpa). If your question concerns an application hosted by a customer, contact that application's operator; we assist our customer with requests concerning data processed for them.

## 2. What we process and why

| Activity                      | Data                                                                                                                  | Purpose and legal basis                                                                                                                                   |
| ----------------------------- | --------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Website delivery and security | Network address, request time, requested resource, browser/protocol information and necessary security events         | Deliver pages, prevent abuse and diagnose faults; our legitimate interests in a secure, available service, Article 6(1)(f) GDPR                           |
| Beta-interest registration    | Email address, submission time and the consent version you accepted                                                   | Record your interest in the beta; consent, Article 6(1)(a)                                                                                                |
| Referral entry                | The r value supplied in the entry link, aggregate request count and last observation time                             | Remember the selected entry source and understand entry campaigns; legitimate interests, Article 6(1)(f)                                                  |
| Feature-interest requests     | Selected feature, random request identifier and submission/update times                                               | Record requested product improvements and prevent duplicate retries; legitimate interests, Article 6(1)(f)                                                |
| Contact and privacy requests  | Name, email, optional company, message, request identifier and timestamps                                             | Answer your request; Article 6(1)(b) for contract-related enquiries, Article 6(1)(f) for other correspondence, and Article 6(1)(c) for statutory requests |
| Accounts and access           | Account/organisation identifiers, login and membership information, authorisations and security records               | Provide and secure the account; Article 6(1)(b), or Article 6(1)(f) when you represent a business customer                                                |
| Hosting operations            | Authorised repository/commit metadata, project configuration, deployment events, diagnostics and measured consumption | Deliver, support and account for requested services; contract performance or our legitimate interests in administering a business customer relationship   |
| Billing                       | Customer and invoice details, transaction references, purchased credits and subscription/entitlement records          | When billing is enabled for your account, administer authorised purchases and fulfil accounting obligations; Articles 6(1)(b) and 6(1)(c)                 |

Providing contact details is necessary for us to respond. Company is optional for individuals. Do not include passwords, access tokens or unnecessary sensitive information in a message. We do not use the beta-interest form to create a hosting account or enrol you in a marketing newsletter.

## 3. Customer applications and agents

Customers control the personal data their applications collect, including their own authentication, application content and uploaded files. The DPA describes our processing of that data. Customers must provide their own notices and obtain any permissions required for their applications.

You choose the agent or harness used with the CLI, API or MCP. Data you provide to that agent, and data you authorise it to retrieve, is also handled under your arrangements with its provider. A hosting login is separate from an application's end-user login. We do not use customer application content to train a general-purpose AI model.

## 4. Recipients

We limit access to authorised personnel and service providers whose access is needed for their role. Cloudflare provides website/edge delivery, security, application execution and storage; AWS provides build, execution, export and enabled mail infrastructure; Neon provides managed Postgres. WorkOS provides our account authentication and authorisation services. GitHub supplies repository access authorised by the customer. When payments are enabled, Stripe handles them and related billing services; payment credentials entered in Stripe's checkout are handled by Stripe.

The [provider register](https://ohmyho.st/dpa/subprocessors) distinguishes workload subprocessors from providers used for our own account and business administration. Customer-selected authentication, agent and integration providers are governed by the customer's own arrangements. We do not sell personal data or use advertising pixels or cross-site marketing trackers on our own website.

We disclose data where required by applicable law or a binding request, and assess the validity, scope and available means of challenge before disclosure where permitted. We may disclose relevant records to professional advisers bound by confidentiality when necessary for a legal claim or obligation.

## 5. International processing

amerged B.V. is established in the Netherlands. Customer workloads currently default to US East; control-service storage and global edge delivery have distinct locations. We therefore do not describe the service as EU-only storage. Access and processing outside the EEA can occur through the providers used for the selected services.

Restricted transfers require an applicable adequacy decision or another valid Chapter V safeguard, including the European Commission's Standard Contractual Clauses where needed. An adequacy mechanism, such as the EU–US Data Privacy Framework, is relied on only when the recipient's current certification and the particular transfer are covered. Our [transfer annex](https://ohmyho.st/dpa/transfers) explains the applicable roles and safeguards. You can request information about the safeguards through the contact form.

## 6. Retention

Aggregate referral counts expire after thirty days without a new observation. At successful signup, the selected entry source is also associated with the authenticated user for acquisition analysis and eligibility for configured referral credits; later sign-ins do not overwrite that attribution. This account attribution is retained with the account and necessary grant records. Beta-interest records are deleted twelve months after submission, or earlier on withdrawal. Repeated submissions do not silently extend that period. Contact-form records are retained for no longer than twelve months from submission as contact-request records and may be deleted earlier when no longer needed. Records separately required to fulfil a statutory obligation or establish, exercise or defend a claim are limited to that purpose and the applicable period.

Account and operational records are retained while needed to provide and secure the account, reconcile usage and resolve outstanding matters. Billing records are retained for the applicable statutory accounting period. Retention of customer application data follows documented customer instructions and the DPA. On-demand encrypted SQL export archives have a seven-day retention period; issued download links are valid for 24 hours. A downloaded customer copy is under the customer's control. Deletion from active resources and expiry of restricted backup copies are distinct steps; backup copies expire under the retention lifecycle of the provider holding them.

## 7. Cookies and similar technologies

Our own website and platform use only technical cookies and storage needed for access, security and requested functionality. They are not used for advertising or cross-site profiling. The [cookie notice](https://ohmyho.st/cookies) lists their purposes and durations. Fonts are hosted by ohmyho.st rather than loaded from Google Fonts. Independently visited identity/payment services and customer applications have their own notices.

## 8. Your rights

Subject to the applicable conditions, you may request access, correction, erasure, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent at any time without affecting processing lawfully carried out before withdrawal. You may complain to the [Autoriteit Persoonsgegevens](https://autoriteitpersoonsgegevens.nl/en) or another competent supervisory authority.

Use the contact form to identify your request. We may request proportionate information to verify identity or authority; do not submit an identity-document copy unless we specifically explain why it is needed. We respond within the applicable statutory period, ordinarily one month, and explain any permitted extension. We do not make decisions producing legal or similarly significant effects about individuals solely by automated means through the website or contact form.

## 9. Changes

We publish the current version and effective date here and communicate material changes through an appropriate service channel where required. [Contact us](https://ohmyho.st/contact) · [Cookie notice](https://ohmyho.st/cookies) · [DPA](https://ohmyho.st/dpa)
