Privacy
Draft, pending legal review. This document is written to be read: it says what we actually do, in the words we would use to explain it. No lawyer has been over it yet, and some of it will change when one has, so treat the clauses marked open as open. Last changed 2026-10-07.
The short version
We collect the little we need to log you in, bill you correctly, and keep the platform up. We do not sell it, we do not run ad tracking, and we do not use your code or your data to train models. The rest of this page is the specific version of those sentences, because a privacy policy that only says the short version is not telling you anything.
What we collect
To sign you in. Your email address, and a session cookie once you are in. The emailed login code is stored as a hash rather than as the code itself, and it is consumed the first time it is used.
To bill you. A record of what your machines used, sampled continuously: CPU-seconds, memory held, and bytes stored. This is per-machine, per-second arithmetic, not a record of what was running. Card details go to Stripe and never reach us; what we keep is a customer reference, and the invoices and balance history attached to it.
To run your machines. The metadata you give them: names, sizes, the images you boot from, snapshots, network and ingress configuration, and the API tokens and secrets you register.
To keep the service working. Request logs from the API and the website, holding IP addresses, user agents, timestamps, and a correlation id that lets us follow one request through the system. We use these to debug failures, find abuse, and answer your support questions.
If you link Discord. Your Discord user id, and whether that account is a member of our server. That pair is the whole point of the link: it is how the signup credit is limited to one per person. We do not read your messages and we could not if we wanted to.
If you write to us. The email, in our inbox, for as long as email lives in inboxes.
How we use and store it
We use what we collect to sign you in, meter and bill your usage, run your machines, and debug and defend the service. Account, billing, and machine metadata live in our databases, and machine contents live on storage we operate in the United States, as described below. Login codes, connector codes, and refresh tokens are stored as hashes.
What is inside your machines
The contents of your machines - your files, your databases, your environment variables, your secrets - are yours, and we treat them as opaque. We do not index them, scan them for content, or read them to learn what you are building, and we do not train models on them.
Our operations staff can reach guest storage, because running a hosting platform means someone can. That access is used to keep the platform working, to respond to a report of abuse or a security incident, or where the law requires it, and not otherwise.
The Claude connector
The ix connector at ix.dev/mcp lets Claude and other MCP clients
act on your ix account after you approve them. This section covers what that
adds. Everything else on this page still applies.
What we collect. When a client registers, we store its name
and its redirect addresses. When you approve it, we store a single-use
authorization code, which lives 60 seconds, and a refresh token, which lives 30
days and rotates on every use. Both are kept as hashes, never as the raw
value. We also mint an API token named connector: <client name> in your account, which expires after one hour and is replaced each time the
client refreshes. The approval is tied to your account, and the request logs
described above cover these calls.
How we use it. Only to check that a request comes from a client you approved, and to let you see and revoke it. The connector server forwards your access token to ix on each call and stores nothing itself.
What passes through. The commands Claude runs, the files it reads and writes, and the output come from and go to your own machine. The connector server does not store them. Claude receives the results and handles them under Anthropic's own policies, which we do not control. We do not receive your conversation with Claude.
Sharing. We share nothing about the connector with anyone beyond the processors listed above. Anthropic is not our processor. It receives tool results because you asked Claude to run the tool.
Retention and revoking. Revoke a connector from the api tokens on your profile. The access token stops working at once, and a refresh token that has been spent or has expired cannot be used again. We have not yet set a deletion schedule for spent or expired code and token records, and will state it here when we do.
Website analytics
The website uses PostHog to count page views and see which parts of the site people actually use. It processes your IP address, which gives it an approximate location, and it is configured to build a per-person profile only for signed-in users. There is no advertising network involved and nothing here follows you to other sites.
Two honest details. The analytics requests go out through a path on our own domain rather than directly to PostHog, so a content blocker keyed to PostHog's domain will not catch them; a blocker that blocks by request path will. And the site does not currently act on a Do Not Track header, so please do not read one as an opt-out here.
Who else touches it
Five companies process some of this on our behalf:
- Stripe - payments, cards, invoices, and subscriptions
- Resend - the transactional email we send you (login codes, receipts, notices)
- Cloudflare - serving this website and its DNS, plus a bot-check script the site loads on every page
- PostHog - the website analytics described above
- Google Workspace - the mailboxes that receive email you send us
If you link Discord, Discord is in the path too, on their terms as well as ours. Everything else - your machines, your volumes, the metering, the logs - runs on hardware we operate ourselves, in data centers in the United States. If you are outside the US, your data is processed in the US.
What we do not do
- We do not sell personal data, and we have never had a reason to want to
- We do not share it with advertisers or data brokers
- We do not use your code, data, or machine contents to train models
- We do not hand data to law enforcement without valid legal process, and where we are allowed to tell you about a demand, we will
How long we keep it
Billing and usage records stick around, because they are the account's history and we may be required to keep them. Machine and snapshot data is deleted when you delete the machine or snapshot; copies can persist briefly in backups until those roll off. Operational logs (requests, errors and the audit trail of sign-ins and tokens) are deleted after 30 days.
Your choices
You can delete your own data yourself, at any time: machines, API tokens, and secrets from the dashboard, and all of that plus snapshots from the CLI. You can unlink Discord; the credit already granted stays granted, and the link stops being checked. You can close your account, and we remove what is left of it.
For anything the product does not do for you - a copy of what we hold, a correction, deletion of the rest - email andrew@ix.dev and a person will do it by hand. Depending on where you live you may have a formal right to some of this; we would rather just do it than argue about which law applies.
Security
Traffic to ix is encrypted in transit. Each machine is a real virtual machine, isolated from every other tenant, and access to production systems is limited to the people who operate them. We will not claim more than that here: we are early, we have not been audited, and there is no certification to point at yet. If you find a hole, email us and we will treat you well for it.
Children
ix is a tool for building software and is not directed at children. We do not knowingly collect personal data from anyone under 13, and we delete it if we learn we have.
Changes to this policy
The current version lives at this URL with the date it last changed at the top. If we start collecting something materially new, or add a processor that sees your data, we will update this page and email the address on your account.
Contact
Email andrew@ix.dev with anything on this page, including the parts you think are wrong.