Legal

Privacy Policy

Last updated July 8, 2026

This Privacy Policy explains how Pylon ("Pylon", "we", "us") collects, uses, discloses, and protects information when you visit pylonsync.com or use Pylon Cloud (together, the "Service"). By using the Service you agree to this Policy.

1. Information we collect

We collect the following categories of information:

  • Account information — your name, email address, a hashed password, and organization/workspace details you provide when you sign up (or the profile your OAuth provider shares if you sign in with Google or GitHub).
  • Billing information — plan, subscription status, and a customer identifier. Payments are processed by our payment provider (Stripe); we do not receive or store full payment-card numbers.
  • Content and application data — the projects, code, configuration, and data you create, deploy, or store through the Service.
  • Usage and diagnostic data — logs, metrics, feature usage, and error reports we generate to operate and improve the Service.
  • Technical data — IP address, browser and device information, and cookies or similar technologies used for authentication and preferences.

2. How we use information

We use information to:

  • Provide, operate, maintain, and secure the Service;
  • Authenticate you and manage your account and workspaces;
  • Process payments and manage subscriptions;
  • Provide customer support and respond to your requests;
  • Send service, security, and administrative communications;
  • Monitor, debug, and improve the Service and develop new features;
  • Detect, prevent, and address fraud, abuse, and security issues; and
  • Comply with legal obligations and enforce our agreements.

We do not sell your personal information, and we do not use your application content to train machine-learning models.

3. Legal bases (EEA/UK users)

Where the GDPR or UK GDPR applies, we process personal data on the bases of performance of a contract (to provide the Service you request), legitimate interests (to secure, operate, and improve the Service), consent (where you provide it, such as optional communications), and legal obligation.

4. Your data vs. our role

For personal data contained in the application data you store or process through the Service, you are the controller and Pylon acts as a processor on your behalf, handling that data according to your instructions and this Policy. You are responsible for having a lawful basis to collect and process that data and for informing your own end users.

5. Cookies

We use strictly necessary cookies to keep you signed in and to remember your preferences. We do not use third-party advertising or cross-site tracking cookies. You can control cookies through your browser, though disabling essential cookies may prevent you from signing in.

6. How we share information

We share information only in these circumstances:

  • Service providers (subprocessors) — trusted vendors that help us run the Service, such as cloud infrastructure/hosting, payment processing (Stripe), email delivery, and error monitoring. They may access data only to perform services for us and are bound by confidentiality obligations.
  • Legal and safety — when required by law, legal process, or to protect the rights, property, or safety of Pylon, our users, or the public.
  • Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.

We do not sell or rent your personal information.

7. Data retention

We retain personal data for as long as your account is active and as needed to provide the Service, then for a reasonable period afterward to comply with legal, tax, accounting, or dispute-resolution obligations. When data is no longer needed, we delete or anonymize it. You can delete your workspace data at any time from the dashboard.

8. Security

We use administrative, technical, and organizational safeguards to protect information, including encryption in transit, access controls, and least-privilege practices. No method of transmission or storage is 100% secure, so we cannot guarantee absolute security.

9. International transfers

We are based in the United States and may process and store information in the United States and other countries where we or our service providers operate. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for cross-border transfers.

10. Your rights

Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal data, and to object to certain processing or withdraw consent. If you are in California, you may request to know, delete, or correct your personal information and to opt out of its "sale" or "sharing" — which we do not do. To exercise any of these rights, contact us at the address below; we will not discriminate against you for doing so.

11. Children

The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us and we will delete it.

12. Changes to this Policy

We may update this Policy from time to time. We will post the updated version here and revise the "Last updated" date, and for material changes we will provide additional notice (such as by email or an in-product notice).

13. Contact us

Questions about this Policy or your data? Email us at [email protected].