Privacy Policy
1. Who we are
Layerbeat (“Layerbeat”, “we”, “us”) provides virtual private servers (“VPS”), a web console and an API at layerbeat.com. Layerbeat is the controller of the personal data described here.
This policy covers our website, console, API and emails. It does not cover the software or data you run on your own servers, for which you are responsible (see section 3).
2. What we collect
Account and sign-in
- Email address and whether you have verified it.
- Password, stored only as a one-way bcrypt hash. We cannot read it.
- If you sign in with Google or GitHub: that provider’s account identifier and the email address it shares with us. We do not receive your Google or GitHub password.
- Sessions and API keys: we store only a hash of each secret, together with its name, permissions, creation time, expiry and last use.
- Preferences, such as your billing currency (USD or IDR) and which notification emails you want.
- Workspaces and members: workspace names, who belongs to them and with which role.
Servers you create
- Server name, region, plan, operating system or application image, IP addresses, status, term and expiry, firewall rules (including any description you add) and renewal settings.
- SSH public keys you upload. Public keys are not secret, but we only use them to set up your servers.
- Initial server passwords, if you choose password login. They are encrypted, can be read only by the person who bought the server, and are deleted after the server is set up (a password you chose) or after 24 hours or when you dismiss it (a generated password).
- Usage metrics for your servers (CPU, memory, disk and traffic), read from our infrastructure and cached for at most five minutes to show them to you.
Credit and payments
- Your credit balance and an append-only history of top-ups, purchases, renewals, holds, releases and adjustments.
- USDC payments: the network, sending wallet address, transaction identifier and amount. Blockchain transactions are public by design; we do not control that data.
- Agent payments (x402): the payment request we issued and the signed payment your agent submitted.
- QRIS and bank transfer payments in IDR are processed by Doit. We receive the order amount, the payment method, the payment status and Doit’s transaction identifier. We never receive your bank or e-wallet login details.
Referrals and partners
- If you arrive through a referral link, a first-party cookie records the referring account for up to 30 days. If you sign up, we record who referred you so that the referrer can earn a reward from your eligible purchases.
- For partners: rewards, earnings history, payout requests and the Solana address you give us for payouts.
Technical and security data
- IP address, used for rate limiting and recorded in our audit log with security-relevant actions (for example sign-in, key creation, purchases and server changes).
- Request and error logs kept by our servers and by our network provider.
- If enabled, the country our network provider derives from your IP address, used only to suggest a billing currency when you sign up.
- Records of emails we send you and whether they were delivered, bounced or marked as spam. If an address bounces or complains, we keep a hash of it so that we stop sending to it.
We do not use advertising trackers or third-party analytics on our website or console, and we do not sell personal data.
3. Your server contents
The files, databases, software and traffic on your servers are yours. We do not inspect them, and our software has no agent inside your server beyond the first-boot setup you choose (SSH keys, password and basic hardening). If your servers process other people’s personal data, you are responsible for that processing, and we and our infrastructure providers process it only to host your server on your instructions. We may need to act on a server’s contents if we receive a valid legal order or a credible abuse report (see our Terms of Service).
4. How we use it
| Purpose | Data | Legal basis |
|---|---|---|
| Create and secure your account, sign you in | Account, sign-in, sessions, API keys | Contract |
| Provide, manage and renew servers | Server data, SSH keys, initial passwords, metrics | Contract |
| Hold credit, take payments, issue receipts | Credit and payment data | Contract; legal obligation (accounting and tax) |
| Send service emails (verification, password reset, receipts, expiry and renewal notices) | Email address, account and server data | Contract |
| Run the referral and partner programs | Referral and partner data | Contract; your consent where required |
| Prevent fraud, abuse and attacks; keep an audit trail | IP address, audit log, request logs | Legitimate interests |
| Comply with law and respond to lawful requests | As required | Legal obligation |
We do not make decisions about you that have legal or similarly significant effects based solely on automated processing. Automated checks (for example rate limits, or refusing a purchase when your credit is insufficient) apply the same rules to everyone, and you can contact us about any of them.
6. International transfers
We and our providers process data in several countries, including the region where you place a server. When we transfer personal data across borders we rely on the safeguards the applicable law provides, such as adequacy decisions, standard contractual clauses or your consent where required.
7. How long we keep it
- Account data: while your account is open, then deleted or anonymized within 90 days after you close it, except as below.
- Sessions: expire after 7 days or when you sign out. Google or GitHub sign-in state lasts at most 10 minutes. Email verification and password reset links expire after one use or a short period.
- Initial server passwords: as described in section 2.
- Server data: while the server exists, and afterwards as part of your billing and audit history.
- Payment, credit and receipt records: for 10 years, as Indonesian accounting and tax law requires. Our ledger is append-only for this reason.
- Audit log: while the workspace exists, and for up to 12 months after it is closed. Request and error logs: up to 30 days, longer only while we investigate a specific security incident.
- Referral cookies: up to 30 days.
9. Security
We protect data with encryption in transit, encryption of server passwords at rest, hashed passwords and secrets, database-enforced separation between customers, scoped API keys, rate limiting and an audit log. No system is perfectly secure. If a breach affects your personal data, we will notify you and the authorities as the law requires.
You keep your API keys, passwords, SSH private keys and console links safe. A console link gives direct access to your server.
10. Your rights
Depending on where you live (for example under Indonesia’s Personal Data Protection Law or the EU and UK GDPR), you may have the right to:
- access and receive a copy of your personal data;
- correct inaccurate data;
- delete your data or close your account;
- restrict or object to some processing;
- withdraw consent where we rely on it;
- complain to your data protection authority.
You can change your email preferences, billing currency, API keys and sessions in the console. For anything else, email [email protected] from your account’s email address. We will answer within the time the law requires. We may keep data we must keep by law, such as payment records, and cannot delete data that is public on a blockchain.
11. Children
Layerbeat is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.
12. Changes
We will update this page when our practices change and change the date at the top. If a change is significant, we will tell you by email or in the console before it takes effect.
13. Contact
For privacy questions and requests, email [email protected].