isolation.cloudDOCS

Privacy Policy

What personal data Isolation collects, why, where it goes, how long it is kept, and your rights.

Version 1.0 (draft) — 22 September 2026

This policy explains what personal data Isolation Labs S.r.l. ("Isolation", "we") collects when you use Isolation Cloud (the website, the API, the isolation command, our apps for Slack and Microsoft Teams, and the software we distribute to run it), why, where it goes, how long we keep it, and what you can do about it. It is written for the General Data Protection Regulation (GDPR); where your country gives you more rights, those apply too.

Controller. Isolation Labs S.r.l., Italy. Contact: privacy@isolation.cloud.

Two roles. For your account, your sign-in, billing and our operation of the Service we are the controller. For what your organization puts into the Service — code, files, environment values, conversations with agents, what agents produce — the organization is the controller and we are its processor: we handle that content only to provide the Service as configured, under the Terms of Service and, on request, a Data Processing Agreement.

1. What we collect, and why

datawhere it comes fromwhylegal basis
Account: email address, display name, an avatar if you connect GitHub, the organizations you belong to and your role in eachyou, when you sign in and when you are invitedto run your account and your organizationscontract
Sign-in: one-time login codes sent by email, session cookies, a bot check (Cloudflare Turnstile) on the login formthe login flowto sign you in and keep abuse off the login formcontract; legitimate interest (security)
Tokens you create for apps, MCP clients and the isolation command: their label, scopes, organization, dates of creation, last use and revocationyou, when you connect somethingto let those tools act as you, and to let you revoke themcontract
Billing: your organization's balance, ledger, invoices, receipts, plan; a Stripe customer idyou and Stripeto bill and to keep the accounts the law requirescontract; legal obligation
Customer Content (as processor): repositories and files in workspaces, environment values and secrets, credentials you store (AI keys and subscriptions, Git tokens, SSH keys), agents' prompts, conversations and memory, what sessions produceyou, your members and your agentsto run sessions and keep your work between themthe organization's instructions
Usage and metering: session start/stop/pause times, sandbox type and price, bytes of egress, tokens counted for the credentials you use through the Service, server capacity reportsthe Service and your serversto bill per second and to show usagecontract
Activity log: which member (or agent, and which member launched it) did which action, through which door (website, command, MCP, terminal, agent), whenthe Serviceso your organization can audit itself; securitylegitimate interest (the organization's audit and our security)
Chat messages addressed to Isolation in Slack or Teams: the text is routed to the agent or command you addressed; we store a hash of the text, its length, and what was decided — not the textthe chat appto route your message; to evaluate the interpretercontract; legitimate interest
Interpreted text: a sentence you type on the website, in the terminal or in a chat that is not an exact command is sent to our interpreter provider (TypeSafe) to be turned into a commandyouto understand what you askedcontract
Voice (push-to-talk): the audio clip is sent to our transcription provider (Groq) and the text comes back; we keep neither the audio nor the transcript beyond the requestyou, when you hold the microphoneto transcribe your instructionconsent (you press the button)
Connected servers: the machine's name, a machine id, software version, capacity, the tunnel it opens, and — if you open the ssh door — the address you advertise, which we probe from the internet to tell you whether it is reachableisolation-server on your machineto pair, monitor and route to your servercontract
Technical logs: request logs at our hosting provider (IP address, user agent, timestamps, the path called), error reportsyour browser and toolsto keep the Service running and securelegitimate interest
Emails we send: login codes, invitations, receipts and invoices, plan changes, alertsthe Serviceto sign you in and to tell you what your organization needs to knowcontract

We do not collect data for advertising, we do not sell personal data, and we do not train AI models on your data.

2. Where your data is processed — our sub-processors

The Service runs on the providers below. The current list, with each provider's location, is kept at isolation.cloud/legal/subprocessors; we tell organizations' owners by email before adding one.

  • Cloudflare — the application, its database and file storage, the tunnels to your servers, the login form's bot check (Turnstile). Customer Content in file storage is encrypted with a key per workspace before it is written.
  • Hetzner — the control planes that create and manage Cloud Sessions (Germany and Finland).
  • Fly.io — the machines Cloud Sessions run on, in the region your organization chose (Amsterdam, Frankfurt, Paris, London, Stockholm today). A session's files exist on its machine while it runs and are saved back to our storage at the documented points.
  • Stripe — payments; your card details go to Stripe and never to us.
  • Resend — sends our emails.
  • TypeSafe — the interpreter: receives the sentence you typed and the names of the things it could refer to (your workspaces, sessions, agents), returns a command.
  • Groq — transcription of push-to-talk audio.
  • GitHub, Slack, Microsoft — when you connect them: the tokens they issue us, and the messages and events they deliver for the things you connected.
  • Your own AI providers — an agent you run talks to the provider of the credential you gave it (Anthropic, OpenAI, or another) under your agreement with that provider; what the agent sends them is your prompt and your code, from inside your session, not through us.

Some of these providers are in the United States. Where personal data leaves the European Economic Area we rely on the EU–US Data Privacy Framework where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses.

3. How long we keep it

datakept
Account, organizations, memberships, tokensuntil you delete them, or your account; a revoked or expired token is deleted 30 days after
Login codes and session cookiesuntil they expire (a code within minutes; a session as set at sign-in), then deleted
Invitationsuntil accepted (the acceptance record stays with the membership) or 30 days after expiry
Customer Contentuntil your organization deletes the workspace, the agent or the organization; a deleted organization's content is removed within 30 days
Usage and metering, ledger, invoicesas long as the law requires for accounting (10 years in Italy)
Activity log90 days
Chat routing records (hash, length, decision)90 days
Voice audio and transcriptsnot stored
Technical logsup to 30 days at the hosting provider
Acceptance of the Terms (who, when, which version)as long as the account or organization exists, then as part of the accounting record

4. Your rights

You can see and change your account data on the Account page, export a workspace (its files and its agents' memory) from the Workspace page, revoke any token from the Account page, leave an organization, and delete your account. Beyond that, under the GDPR you may ask us to access, correct, erase or port your personal data, to restrict or object to its processing, and to withdraw a consent you gave. Write to privacy@isolation.cloud; we answer within one month. You may also complain to your data protection authority — in Italy, the Garante per la protezione dei dati personali (garanteprivacy.it).

For Customer Content, where we are the processor, ask your organization's owners: they control it, and we act on their instructions.

5. Security

Credentials, secrets and workspace content are encrypted at rest; secrets travel to a session sealed for that session alone and are never written to logs, URLs or repositories. Every action is logged with who did it. Our staff reach Customer Content only to provide the Service or when you ask us to help. Sessions are isolated from each other and from us at the machine or container level. More at isolation.cloud/docs/servers and isolation.cloud/docs/credentials.

6. Cookies

The website uses one cookie, the session that keeps you signed in, and the Turnstile bot check on the login form. There are no advertising or analytics cookies. The isolation command and other tools you connect keep their own token on your machine, not a cookie.

7. Children

The Service is not for children under 16, and we do not knowingly collect their data.

8. Changes

We will publish changes at isolation.cloud/legal/privacy with a new version and date, and email organizations' owners before a material change takes effect.