Privacy Policy
Last updated: September 30, 2026
This policy explains what personal data detachbox collects, what we use it for and how you control it. The service is operated by AppMaster Inc. Write to [email protected] with any privacy question or request.
- Operator
- AppMaster Inc
- Registered address
- 111 Pier Ave STE 100, Hermosa Beach, CA 90254, United States
- Governing law
- State of California, USA; courts of Los Angeles County
1. What we collect
- Account data: your email address, name and profile picture from Google, or the public key of your passkey.
- Billing data: your Stripe customer and subscription identifiers, plan, payment status and invoices. Card details go to Stripe and never reach our servers.
- Box data: each box's name, plan, status, resource usage (CPU, memory, disk, network), and the SSH public keys you add.
- Connected accounts: for each Codex or Claude account you connect, the provider's account ID, email, plan name, OAuth tokens and snapshots of your usage limits.
- Technical data: IP addresses, browser user agent, request and SSH connection logs, and error reports.
- Messages you send us, for example to support or abuse.
2. Your Codex and Claude tokens
When you connect a Codex (ChatGPT) or Claude account in the dashboard, OpenAI or Anthropic issues OAuth tokens for it: an access token and a refresh token. We store both encrypted in our database, with a key held only by our server.
We use them for two purposes. First, to read your usage limits from the provider and show them on your limits board. Second, to put a current access token into the boxes you attach the account to, so the command-line tools there can work. We renew the access token on schedule with the refresh token.
The refresh token never leaves our server and is never written into a box. Anyone with access to your box, including an agent running there with sudo, can read the access token in it, so attach an account only to boxes you control.
You can disconnect an account at any time. We then delete its tokens and usage history from our database and remove the credential file from every box it was attached to. Deleting your detachbox account does the same for all your connected accounts.
3. What is on your boxes
Files, databases and programs on your boxes are your content. Our staff do not browse them. We access a box's contents only when you ask for help, when we investigate a security incident or abuse, or when the law requires it.
4. Why we use your data
- To provide the service you signed up for: run your boxes, sign you in, show your limits and bill you (performance of our contract with you).
- To keep the service secure and stop abuse, using resource and network statistics and logs (our legitimate interest).
- To send you service emails: box created, payment problems, planned maintenance, a reset limit, a dead connected account (performance of contract).
- To keep accounting records (legal obligation).
5. Who processes it for us
- Stripe: payments and invoices.
- Google: sign-in with Google.
- Amazon Web Services: delivery of our emails.
- Cloudflare: DNS and the network edge in front of our website and dashboard.
- Sentry: error reports from our software.
- OpenAI and Anthropic: when you connect an account, we exchange and refresh tokens with them and read your usage on your behalf.
- Google Analytics, when enabled on the website: aggregated visit statistics.
6. Where it is stored
Our servers and your boxes are located in Kazakhstan. The processors above may handle data in other countries under their own safeguards.
7. How long we keep it
Account data is kept while your account exists. A deleted box is removed from our servers; residual copies in infrastructure backups expire on their normal rotation. Connected-account tokens are deleted when you disconnect the account or delete your detachbox account. Billing records are kept as long as accounting law requires. Logs are kept only as long as we need them for security and troubleshooting.
8. Cookies
The dashboard uses a session cookie to keep you signed in. The marketing website sets no cookies of its own; Google Analytics, when enabled, sets its own.
9. Your rights
You can ask us for a copy of your data, to correct it, to delete it or to export it. You can also object to processing based on our legitimate interest. Write to [email protected]; we answer within 30 days. You can also complain to your local data protection authority.
10. Changes
We will post changes here and email you about significant ones before they take effect.