Skip to content
All guides

Docs Legal Privacy Policy

Privacy Policy

Effective date: August 4, 2026 · Last updated: August 4, 2026

This Privacy Policy explains how FosterPanel (“we”, “us”) collects, uses, stores, and deletes information when you use fosterpanel.com, the control panel, APIs, and related services (the “Service”).

1. Overview

FosterPanel helps you manage servers and infrastructure. That necessarily involves processing account data and operational metadata about the resources you connect. We design the Service so that sensitive data and critical operations are encrypted and verified, and so that two-factor authentication is mandatory for several high-risk actions.

Related documents: Terms & Conditions and Cookies Policy.

2. Data we collect

2.1 Account & identity

  • Name, email address, and authentication identifiers.
  • OAuth / social login identifiers when you choose providers such as Google.
  • Two-factor authentication status and related recovery metadata (not your one-time codes).
  • Organization or workspace association when you collaborate with seats.

2.2 Billing

  • Subscription plan, entitlements, and invoice/payment status.
  • Payment card details are processed by our payment provider (e.g. Paddle); we do not store full card numbers on FosterPanel servers.

2.3 Operational & product data

  • Server registration metadata, agent pool identifiers, and connectivity status.
  • Proxy domains, SSL-related status, firewall/protection configuration you store in the panel.
  • Database tool, S3, GitHub app linkage, and similar feature configuration you enable.
  • Logs and diagnostics needed to operate, secure, and troubleshoot the Service.

2.4 Technical data

  • IP address, browser/user-agent, device type, and approximate location derived from IP.
  • Cookies and similar technologies — see the Cookies Policy.

3. How we use data

  • Provide, authenticate, and operate the panel, APIs, and agent connectivity.
  • Enforce plan entitlements and process subscriptions.
  • Protect accounts and infrastructure (fraud, abuse, anomaly detection, step-up 2FA).
  • Improve reliability, performance, and support.
  • Comply with legal obligations and enforce our Terms.
  • Communicate service notices, security alerts, and (where allowed) product updates.

4. Security, encryption & verification

Sensitive data and operations are encrypted and verified. Critical flows require step-up two-factor authentication.
  • TLS. Traffic to the Service is encrypted in transit.
  • Secrets handling. Credentials vault material, tokens, and agent keys are protected with encryption and access controls appropriate to each subsystem.
  • Cryptographic agent trust. Agent requests are verified cryptographically (for example Ed25519 signatures with pool identity) where the product requires it.
  • Mandatory 2FA. Several critical operations cannot complete without successful two-factor / step-up verification.
  • Least privilege. Panel permissions, collaborator seats, and server scoping limit who can act on which resources.

No method of transmission or storage is perfectly secure. You remain responsible for host hardening, key management on your servers, and protecting recovery codes.

5. Sharing & processors

We do not sell your personal data. We share data only as needed to run the Service:

  • Payment processors (e.g. Paddle) for checkout and tax invoicing.
  • Infrastructure providers hosting the panel, databases, and related systems.
  • Integrations you connect (e.g. GitHub App, OAuth providers) under their terms and your authorization.
  • Legal / safety when required by law, or to protect users, the Service, or others from harm or fraud.

6. Retention

We retain account and operational data for as long as your account is active and as needed to provide the Service. After account deletion completes (see below), we wipe account-associated information we control, except limited records we must keep temporarily for security, dispute resolution, tax, or legal compliance—then delete or anonymize them.

7. Account deletion — full wipe

Because accounts may contain company and infrastructure data, deletion is a full wipe of FosterPanel-held account information.

  1. You request deletion.
  2. A 30-day waiting period applies. During this time you can opt out and cancel the deletion.
  3. If not cancelled, we permanently erase account data under our control. This cannot be undone.

Deletion from FosterPanel does not erase data that lives only on your servers or with third parties you connected. See also the Terms — Account deletion.

8. Your rights

Depending on your location, you may have rights to access, correct, export, restrict, or delete personal data, and to object to certain processing. You can:

  • Update profile details in the panel where available.
  • Request deletion (subject to the 30-day waiting period and full-wipe process).
  • Contact us for access or correction requests we cannot fulfill in-product.

We may need to verify your identity (including via 2FA where appropriate) before fulfilling privacy requests.

9. Cookies

We use essential cookies for sessions, CSRF protection, and security. Details, categories, and controls are in the Cookies Policy.

10. Children

The Service is not directed to children under 16 (or the minimum age required in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided data, contact us and we will take appropriate steps to delete it.

11. Contact

Privacy questions or requests:

Email: [email protected]

We may update this Policy from time to time. The “Last updated” date at the top will change when we do.