Skip to content
pols
FeaturesDocsLog inSign upDeutschDE

Privacy policy

This is a courtesy translation. The German Datenschutzerklärung is the binding version.

This policy covers the pols.so website: these pages, the documentation at docs.pols.so, the account pages for signing up, logging in, managing API keys and the vault and viewing your sandboxes (my.pols.so/signup, /login and /account), the install script at pols.so/install.sh and the program files it downloads from pols.so/dl/.

Controller

PEWEO Sàrl
5, Montée des Aulnes
L-6611 Wasserbillig
Luxembourg
Email: team@peweo.com

What is processed when you visit these pages

When you open a page or download a file, our server receives your IP address and the request itself (the address requested, browser or program details). This is technically necessary to deliver the page or file to you (Art. 6(1)(f) GDPR).

We keep no access log for these pages, the documentation, the account pages or the downloads. Only when a connection fails, for example when a TLS handshake does not complete, can an error message with your IP address end up in the server's system log. These messages serve troubleshooting only and are rotated and deleted with the system log.

Cookies and tracking

These pages, the documentation and the account pages use no analytics or tracking tools and load no fonts, scripts or other content from other servers. The install script, too, downloads the program and its checksums only from pols.so/dl/ and contacts no other servers.

There is exactly one cookie: __Host-pols_session. It is set only after you have logged in with a login link, and it keeps you logged in. It contains only a random session ID, applies only to my.pols.so, cannot be read by scripts and expires after 7 days or when you log out. It is strictly necessary for the login you requested (§ 25(2) no. 2 TDDDG) and is used for nothing else. Without a login, pols.so sets no cookies.

If you explicitly choose between the light and the dark design on the account pages, your browser stores that choice in its local storage (localStorage, entry pols-theme) so the pages look that way on your next visit. The entry is not sent to us, is strictly necessary for the display you requested (§ 25(2) no. 2 TDDDG) and can be deleted in your browser settings. Without that choice, the pages follow your system setting.

Account and login

When you sign up or log in, we process your email address to send you a login link and to run your account (Art. 6(1)(b) GDPR). For your account we store:

  • your email address, when you signed up and whether your account is approved;
  • the organization every account receives, with its quotas;
  • your API keys: name, start of the key, when it was created, last used and revoked, and of the key itself only a checksum (SHA-256);
  • the entries in your organization's vault (see below);
  • for each login link your email address, a checksum of the link and when it was created and used, and for each login a checksum of the session ID with its start and expiry;
  • whether and since when we have suspended your account.

We reject sign-ups with addresses of known disposable email services. Where needed, we approve new accounts by hand; for this our operators learn the address of every new sign-up by email. To protect against abuse, we limit how many login links and sign-ups can come from one IP address (Art. 6(1)(f) GDPR). For this the server keeps your IP address in memory for at most 25 hours; it is not stored or logged.

Administration by our operators

In a protected administration area, our operators see your email address, the status of your account, your quotas and their use, the name and start of your API keys, and your sandboxes with their current processor, memory and disk usage. There they can approve or reject sign-ups, change quotas, suspend and unsuspend accounts, revoke API keys and stop, start or delete sandboxes. They have no access from there into your sandboxes, that is, to their files, command line, desktop or browser.

We log each of these actions with the time, the email address of the operator who acted, the kind of action, the account concerned and the target (for example your email address, the start of an API key or the ID of a sandbox) and the result. This serves the traceability and security of the service (Art. 6(1)(f) GDPR). The entries cannot be changed; only our operators see them.

Vault for passwords and environment variables

In the vault at my.pols.so/account you can store passwords and environment variables for your sandboxes (Art. 6(1)(b) GDPR). For each entry we store the name, the kind (password or environment variable), when it was created and last changed, when a sandbox last received it, and the value only in encrypted form (AES-256-GCM). The key for it is not kept in the database. After saving, we never show the value again and write it to no log. It is decrypted only when you create a sandbox with this entry: the sandbox then receives it as an environment variable, and everything you run in the sandbox can read it. You decide which values you store; do not put personal data of third parties there that you are not allowed to use in a sandbox.

Sending email

We send login links and notifications about your account through Lettermint B.V., Willemsvaart 16 B, 8019 AB Zwolle, Netherlands, as a processor (Art. 28 GDPR). For this, Lettermint receives your email address and the content of the email, processes them in the European Union and deletes them after 28 days. Open and click tracking is switched off.

Retention

  • Login links are valid for 15 minutes and only once; we delete their entries after 24 hours.
  • We delete sessions when you log out, otherwise shortly after they expire after 7 days.
  • We keep vault entries until you delete them on my.pols.so/account or your account is deleted; a sandbox that has received an entry keeps it until you delete the sandbox.
  • We keep your account with its organization and API keys until you ask for its deletion, unless statutory retention obligations (for example for invoices) prevent this. We keep rejected sign-ups in the same way so the same address cannot sign up again; here too you can ask for deletion.
  • The server keeps the usage of your running sandboxes in memory for the last hour only; it is not stored.
  • We keep log entries about administrative actions as long as the account concerned. If you ask for your account to be deleted, we also remove the entries concerning it, unless we need them to prevent abuse or for legal claims.

Hosting and DNS

The server is located in a data centre of Hetzner Online GmbH in Germany, which operates it for us as a processor. Name resolution (DNS) for pols.so is handled by Cloudflare; your page requests do not pass through Cloudflare but go directly to our server.

Processors

The following service providers process personal data on our behalf:

  • Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany: hosting of the server, in Germany.
  • Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA: name resolution (DNS) for pols.so only; page requests are not routed through Cloudflare.
  • Lettermint B.V., Willemsvaart 16 B, 8019 AB Zwolle, Netherlands: sending login links and account emails, in the European Union.

As soon as we bill for paid offerings, we will add the payment provider here.

Your rights

You have the right to access, rectification, erasure and restriction of processing of your data, to data portability and to object to the processing. Write to team@peweo.com for this. You can also lodge a complaint with a data protection supervisory authority, for example the Luxembourg Commission nationale pour la protection des données (CNPD).

© 2026 PEWEO Sàrl · Hosted in Germany
pols.soDocsmy.pols.soLegal noticePrivacyTermsDeutsch