Privacy Policy
What we store, why we store it, and what stays on your own server.
Last updated: 29 July 2026 · Deutsche Fassung
1. Controller
We have not appointed a data protection officer; we are not required to.
2. The short version
We store what we need to give you access and to bill you: your e-mail address, the details of your server, your organisation, and your subscription. We also store two API keys of yours in encrypted form, because without them we could not restart your server for you.
What we do not store is your work. Your files, your projects and your conversations with the agent live on your own server in your own Hetzner account. We do not copy them and we do not read them.
3. Account and login
When you create an account we process your e-mail address, a hash of your password, and the timestamps of creation and confirmation. Authentication runs on Supabase; the session is kept in a cookie that is technically necessary for the site to work.
Purpose: providing the service. Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
4. Your server
To create and manage your server we store: an internal box identifier, the Hetzner server number, its IPv4 address, the user name you chose for it, its status, and the identifiers of devices you paired for file synchronisation. We also store a hash of the token your server uses to authenticate to our relay, and the server's synchronisation identity in encrypted form, so that a rebuilt server keeps the same identity and your own computers do not have to trust it again.
Purpose: providing the service. Legal basis: Art. 6(1)(b) GDPR.
5. API keys we store for you
We store your Hetzner API token and, if you use one, your Anthropic API key. Both are encrypted with AES-256-GCM before they are written to the database, each with its own nonce, and they are decrypted only in the moment they are used.
We store them because you asked for a product that can restart, rebuild and remotely repair your server with one click. Every one of those actions needs the Hetzner token, and a rebuilt server needs the Anthropic key again. The alternative would be to ask you to paste both keys each time.
You can end this at any time by deleting your server in the settings and revoking the tokens at Hetzner and Anthropic. We recommend giving fastpal a Hetzner token that is scoped to a project used only for this.
Purpose: providing the service. Legal basis: Art. 6(1)(b) GDPR.
6. Organisations and invitations
If you set up an organisation, we store its name, who owns it, the e-mail address and role of each member, and which projects are shared with whom. For an invitation we store the invited address, the role, an expiry date, and a hash of the invitation token — never the token itself, so a look into our database does not yield a usable invitation link.
Purpose: providing the service. Legal basis: Art. 6(1)(b) GDPR.
7. Payment
Payments run through Stripe Payments Europe Ltd. We store the Stripe customer and subscription identifier, the status of your subscription, the currency, the amount per seat, the number of seats, the end of the current period, and when your free trial ends.
Card details are entered on Stripe's pages and never reach us. Stripe processes the payment data as an independent controller under its own privacy policy. For invoices, Stripe processes your billing address and, if you provide it, your VAT identification number; German law requires us to keep those invoices for ten years.
Purpose: performance of the contract and compliance with our tax obligations. Legal basis: Art. 6(1)(b) and Art. 6(1)(c) GDPR.
8. What happens on your server, not on ours
Your files, your projects, the state of the agent and the record of your sessions are stored on your server. That server runs in your Hetzner account, and for its contents you are the controller, not us.
Your server writes a log of the prompts you send to the agent. It contains the prompts only, not the answers, it never leaves the server, and it is rotated after about thirty days. We do not collect it. We can only reach it if you ask us for support and give us access, or, within an organisation, if the person who set it up uses the remote maintenance functions.
If you invite colleagues, their servers are created in your Hetzner account and you decide what happens on them. In that relationship you are the controller and, to the extent we process data on your behalf, we are a processor. If you need a data processing agreement under Art. 28 GDPR, write to us and we will provide one.
9. Server logs
Our hosting providers keep short-lived technical logs of requests, including IP address, time, and the page requested. They serve operational security and troubleshooting.
Purpose: secure operation. Legal basis: Art. 6(1)(f) GDPR (our legitimate interest in a functioning, secure service).
10. Who else is involved
We use the following providers. Each of them processes only what its function requires:
- Hetzner Online GmbH, Germany — the relay that carries the connection to your server, and the servers created in your own account.
- Supabase Inc. — database and authentication. Our project runs in the EU (Frankfurt).
- Vercel Inc., United States — hosting of the web application.
- Stripe Payments Europe Ltd., Ireland, and Stripe Inc., United States — payment and invoicing.
- Loops (Fifty Nine Inc.), United States — the e-mails we send you, such as address confirmation and invitations.
- Anthropic PBC, United States — the model behind Claude Code. Whatever you send the agent goes to Anthropic under the account whose key is used, and Anthropic's terms and privacy policy apply to it.
11. Transfers outside the EU
Vercel, Stripe, Loops and Anthropic process data in the United States. These transfers are based on the European Commission's adequacy decision for the EU-US Data Privacy Framework where the provider is certified under it, and otherwise on the standard contractual clauses under Art. 46(2)(c) GDPR.
12. How long we keep things
- Account and organisation data: until you delete your account.
- Server details and encrypted keys: until you delete the server, and at the latest when your account is deleted.
- Invitations: until accepted, withdrawn, or expired.
- Payment and invoice data: ten years, because German commercial and tax law requires it.
- The prompt log on your server: about thirty days, then it is rotated away.
13. Cookies
fastpal sets one cookie: the session cookie that keeps you signed in. It is technically necessary and needs no consent. We use no analytics, no tracking and no advertising cookies.
14. Your rights
You have the right to access your data (Art. 15), to have it corrected (Art. 16) or erased (Art. 17), to restrict its processing (Art. 18), to receive it in a portable form (Art. 20), and to object to processing based on our legitimate interests (Art. 21). Write to m.hofmann@fastpal.com.
You also have the right to complain to a supervisory authority. The one responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen.