We hold your servers' credentials. Here is exactly what we do with them.
This is not a template. Every statement below describes what the software actually does, and the sections on what we deliberately do not store are the ones worth reading first.
Last updated 4 September 2026 · ServerAlly is operated by FireVPS.
What we store about you
Your email address, an optional display name, your language preference, and your plan. If you turn on two-factor authentication we store the secret needed to check your codes.
Your password is never stored. We keep a bcrypt hash, which cannot be turned back into the password you chose.
We do not ask for a phone number, a postal address, or a payment card. Payment is handled entirely by FireVPS's billing system, which tells us only which plan you are on.
What we store about your servers
Login details are encrypted with AES-256-GCM before they are written down, and no part of the product will show them to you again after you save them — not the interface, not the API, not the connector your AI uses. We checked this by taking a real account payload apart field by field rather than by trusting the code to be right.
We also store what we need to be useful: your servers' names and addresses, the websites found on them, health readings such as processor and disk use, the results of security and malware scans, and a record of the work done for you.
What we deliberately do not store
The text of commands run through the connector. When an AI runs a command on your server, we record that a command ran, the plain-English summary of what it was doing, and how it ended — never the command itself. An assistant can write a password into a command, so the safest place for that text is nowhere.
The contents of your conversations with the AI. Our usage record counts requests and their cost. It holds no messages, no answers and no server output.
Your files. When a backup is copied to your own cloud storage it goes from your server straight to your bucket. We create a link that is valid for one hour and for one file, and the data never passes through us.
Secrets are masked before they reach an AI: when a file or a log is read for you, values that look like credentials are replaced before the text leaves your server.
Artificial intelligence
We do not resell AI, and we do not run your work through an AI account of ours. There are two ways to use AI with ServerAlly, and in both of them the AI is yours:
Connect your own assistant. Claude, ChatGPT or another assistant connects to ServerAlly and asks it to do things. Your assistant's provider sees whatever you type to it and whatever ServerAlly returns. We are not a party to that conversation and we do not receive it.
Give Ally your own API key. Ally then talks to that provider using your key and your account. If you never enable Ally, no AI provider is contacted on your behalf at all.
Who else can see any of this
Nobody, unless you connect them. ServerAlly contacts an outside service only when you have set that service up:
Your AI provider, if you enable Ally with your own key. GitHub, if you connect a repository to deploy. Your cloud provider (Amazon, DigitalOcean, Hetzner, Google, Microsoft), if you connect an account. Slack, Telegram or an SMS provider, if you set one up to receive alerts. Your own storage bucket, if you send backups offsite.
Email we send you goes through a mail server we run ourselves, on the same machine as the product. It is not handed to a third-party mail service.
We do not sell data, we do not share it for advertising, and there is no analytics or tracking code anywhere in this site or in the product.
Cookies
This marketing site sets no cookies and makes no third-party requests. The product stores a sign-in token in your browser so you stay signed in, and remembers whether you prefer the light or dark theme. Neither is used to follow you anywhere.
How long we keep things
Two kinds of data age out on their own, because they are dense readings rather than records anyone reports on:
Health readings are kept 7 days on Free and 365 days on Pro. Uptime check results are kept 30 days on Free and 365 days on Pro. Integration delivery logs are kept 14 days on Free and 90 days on Pro.
Everything that is a record is kept until you delete it: what was done on your servers and by whom, security and malware scan results, what was installed, proof that a backup ran, and the administrative log. A malware scan is often worth most long after the fact, so it is not something we quietly expire.
Your choices
You can remove a server at any time, which deletes it and everything recorded about it. You can revoke an AI connection from Settings, and it stops working immediately. You can ask us for a copy of your data, or to delete your account entirely, by writing to the address below.
Deleting an account removes your servers, their encrypted credentials and their history. Administrative records of billing changes are kept without your account attached to them, because a record of what was done has to survive the account it was done to.
Security incidents
If we discover a breach affecting your data, we will tell you what happened, what it touched and what to do about it — and we will tell you even when the answer is embarrassing. Given what this product holds, anything less would be worthless to you.
Contact
Questions about this policy, a request for your data, or a security report: privacy@firevps.net.
ServerAlly is in early access and this policy will change as the product does. When it changes materially we will say so here and date it rather than replacing it quietly.