Skip to content
Layerbeat
Log in Sign up

Privacy Policy

Last updated: October 7, 2026

  1. Who we are
  2. What we collect
  3. Your server contents
  4. How we use it
  5. Who receives it
  6. International transfers
  7. How long we keep it
  8. Cookies and browser storage
  9. Security
  10. Your rights
  11. Children
  12. Changes
  13. Contact

1. Who we are

Layerbeat (“Layerbeat”, “we”, “us”) provides virtual private servers (“VPS”), a web console and an API at layerbeat.com. Layerbeat is the controller of the personal data described here.

This policy covers our website, console, API and emails. It does not cover the software or data you run on your own servers, for which you are responsible (see section 3).

2. What we collect

Account and sign-in

  • Email address and whether you have verified it.
  • Password, stored only as a one-way bcrypt hash. We cannot read it.
  • If you sign in with Google or GitHub: that provider’s account identifier and the email address it shares with us. We do not receive your Google or GitHub password.
  • Sessions and API keys: we store only a hash of each secret, together with its name, permissions, creation time, expiry and last use.
  • Preferences, such as your billing currency (USD or IDR) and which notification emails you want.
  • Workspaces and members: workspace names, who belongs to them and with which role.

Servers you create

  • Server name, region, plan, operating system or application image, IP addresses, status, term and expiry, firewall rules (including any description you add) and renewal settings.
  • SSH public keys you upload. Public keys are not secret, but we only use them to set up your servers.
  • Initial server passwords, if you choose password login. They are encrypted, can be read only by the person who bought the server, and are deleted after the server is set up (a password you chose) or after 24 hours or when you dismiss it (a generated password).
  • Usage metrics for your servers (CPU, memory, disk and traffic), read from our infrastructure and cached for at most five minutes to show them to you.

Credit and payments

  • Your credit balance and an append-only history of top-ups, purchases, renewals, holds, releases and adjustments.
  • USDC payments: the network, sending wallet address, transaction identifier and amount. Blockchain transactions are public by design; we do not control that data.
  • Agent payments (x402): the payment request we issued and the signed payment your agent submitted.
  • QRIS and bank transfer payments in IDR are processed by Doit. We receive the order amount, the payment method, the payment status and Doit’s transaction identifier. We never receive your bank or e-wallet login details.

Referrals and partners

  • If you arrive through a referral link, a first-party cookie records the referring account for up to 30 days. If you sign up, we record who referred you so that the referrer can earn a reward from your eligible purchases.
  • For partners: rewards, earnings history, payout requests and the Solana address you give us for payouts.

Technical and security data

  • IP address, used for rate limiting and recorded in our audit log with security-relevant actions (for example sign-in, key creation, purchases and server changes).
  • Request and error logs kept by our servers and by our network provider.
  • If enabled, the country our network provider derives from your IP address, used only to suggest a billing currency when you sign up.
  • Records of emails we send you and whether they were delivered, bounced or marked as spam. If an address bounces or complains, we keep a hash of it so that we stop sending to it.

We do not use advertising trackers or third-party analytics on our website or console, and we do not sell personal data.

3. Your server contents

The files, databases, software and traffic on your servers are yours. We do not inspect them, and our software has no agent inside your server beyond the first-boot setup you choose (SSH keys, password and basic hardening). If your servers process other people’s personal data, you are responsible for that processing, and we and our infrastructure providers process it only to host your server on your instructions. We may need to act on a server’s contents if we receive a valid legal order or a credible abuse report (see our Terms of Service).

4. How we use it

PurposeDataLegal basis
Create and secure your account, sign you inAccount, sign-in, sessions, API keysContract
Provide, manage and renew serversServer data, SSH keys, initial passwords, metricsContract
Hold credit, take payments, issue receiptsCredit and payment dataContract; legal obligation (accounting and tax)
Send service emails (verification, password reset, receipts, expiry and renewal notices)Email address, account and server dataContract
Run the referral and partner programsReferral and partner dataContract; your consent where required
Prevent fraud, abuse and attacks; keep an audit trailIP address, audit log, request logsLegitimate interests
Comply with law and respond to lawful requestsAs requiredLegal obligation

We do not make decisions about you that have legal or similarly significant effects based solely on automated processing. Automated checks (for example rate limits, or refusing a purchase when your credit is insufficient) apply the same rules to everyone, and you can contact us about any of them.

5. Who receives it

We share personal data only as needed to run the service, with:

  • Cloud infrastructure providers that host the servers you buy in the region you choose. They receive the server configuration, SSH public keys or initial password, and the network traffic of your server.
  • Cloudflare, which carries all traffic to layerbeat.com, protects it from attacks and hosts our documentation at docs.layerbeat.com.
  • Our hosting provider, where our application and database run.
  • Resend, which delivers our emails.
  • Google and GitHub, only if you choose to sign in with them.
  • Doit, only if you pay with IDR, and blockchain networks and payment facilitators, only if you pay with USDC.
  • Members of your workspace, who see the workspace’s servers and its audit log according to their role. Your personal credit and payments are visible only to you.
  • Authorities, courts or others when the law requires it, or to protect our users, our service or the public from fraud or harm.
  • A buyer or successor if Layerbeat is reorganized, merged or sold, under this policy.

Our service providers may use the data only to provide their service to us.

6. International transfers

We and our providers process data in several countries, including the region where you place a server. When we transfer personal data across borders we rely on the safeguards the applicable law provides, such as adequacy decisions, standard contractual clauses or your consent where required.

7. How long we keep it

  • Account data: while your account is open, then deleted or anonymized within 90 days after you close it, except as below.
  • Sessions: expire after 7 days or when you sign out. Google or GitHub sign-in state lasts at most 10 minutes. Email verification and password reset links expire after one use or a short period.
  • Initial server passwords: as described in section 2.
  • Server data: while the server exists, and afterwards as part of your billing and audit history.
  • Payment, credit and receipt records: for 10 years, as Indonesian accounting and tax law requires. Our ledger is append-only for this reason.
  • Audit log: while the workspace exists, and for up to 12 months after it is closed. Request and error logs: up to 30 days, longer only while we investigate a specific security incident.
  • Referral cookies: up to 30 days.

8. Cookies and browser storage

We only use storage that the service needs. We do not use advertising or cross-site tracking cookies.

WhatWhyHow long
Session cookie (HttpOnly)Keeps you signed in to the consoleUp to 7 days
Security cookieProtects forms against cross-site request forgeryYour session
Social sign-in cookie (HttpOnly)Completes Google or GitHub sign-in safely10 minutes
Referral cookie (HttpOnly)Remembers the referral link you usedUp to 30 days
Local storageTheme, sidebar layout and dismissed bannersUntil you clear it
Session storageSelected workspace and unfinished server ordersUntil you close the tab

9. Security

We protect data with encryption in transit, encryption of server passwords at rest, hashed passwords and secrets, database-enforced separation between customers, scoped API keys, rate limiting and an audit log. No system is perfectly secure. If a breach affects your personal data, we will notify you and the authorities as the law requires.

You keep your API keys, passwords, SSH private keys and console links safe. A console link gives direct access to your server.

10. Your rights

Depending on where you live (for example under Indonesia’s Personal Data Protection Law or the EU and UK GDPR), you may have the right to:

  • access and receive a copy of your personal data;
  • correct inaccurate data;
  • delete your data or close your account;
  • restrict or object to some processing;
  • withdraw consent where we rely on it;
  • complain to your data protection authority.

You can change your email preferences, billing currency, API keys and sessions in the console. For anything else, email [email protected] from your account’s email address. We will answer within the time the law requires. We may keep data we must keep by law, such as payment records, and cannot delete data that is public on a blockchain.

11. Children

Layerbeat is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.

12. Changes

We will update this page when our practices change and change the date at the top. If a change is significant, we will tell you by email or in the console before it takes effect.

13. Contact

For privacy questions and requests, email [email protected].

© Layerbeat
PricingPrivacyTerms