Data retention
What pols keeps about your sandboxes and account, where, for how long, and what deleting removes.
Everything pols stores is kept on our servers at Hetzner in Germany. This page lists what is kept and for how long. The Datenschutzerklärung is the legally binding text for personal data.
Sandboxes
| Data | Kept until |
|---|---|
| A sandbox’s disk | you delete the sandbox. Stopping keeps it. |
| Snapshots taken when a sandbox stops | the newest three are kept; all are removed with the sandbox |
Environment variables set with --env |
you delete the sandbox; they are erased with the status change |
| Vault values a sandbox received | you delete the sandbox |
| The sandbox record (ID, name, size, status, timestamps) | kept after deletion, so pols ls --all and your usage history stay complete |
| Running intervals (usage) | kept for billing |
| CPU, memory and disk samples | one hour, in memory only; they start over when the control plane restarts |
| Templates | you delete them |
Deleting a sandbox cannot be undone: there is no recycle bin.
Sandbox disks are not backed up and are not copied to another host. They live on one host’s mirrored NVMe drives, which survive the failure of one drive, but not the loss of the host. Keep code and results you cannot lose in git or another store outside pols.
Commands, files and the desktop
pols does not store the commands you run, their output, the files you transfer, screenshots or what happens on the desktop. They pass through the control plane to the sandbox and back and are kept only inside the sandbox.
The API logs one line per request with its method, URL path (which names the sandbox, but not the query string or body), response status, duration and org. These lines go to the server’s system log and are rotated with it.
Your account
| Data | Kept until |
|---|---|
| Email address, org and quotas | you ask us to delete your account |
| API keys: name, the first characters, creation, last use, expiry, revocation, and a SHA-256 hash of the secret | you ask us to delete your account |
| Vault entries: name, kind, timestamps, encrypted value | you delete them on the account page, or your account is deleted |
| Website login links (hashed) | 24 hours |
| Website sessions (hashed) | logout, or shortly after they expire after 7 days |
| Client IP addresses for abuse limits | at most 25 hours, in memory only |
| Operator actions on your account (audit log) | as long as your account |
To have your account deleted, or to get a copy of your data, write to team@peweo.com.