Privacy Policy
Effective September 16, 2026
This Privacy Policy explains how PicoSvc collects, uses, stores, and shares information when you use PicoSvc websites, APIs, dashboards, runtime endpoints, developer tools, and related services (collectively, the “Service”).
1. Information we collect
Account and identity information
When you sign in, our authentication provider may provide identifiers and account details such as your user ID, organization ID, email address, profile information, session information, and authentication events.
Product and configuration data
We collect information needed to operate the PicoSvc products you use, including deployment metadata, repository references, branches, endpoint configuration, mock responses, webhook configuration, feed configuration, scheduled jobs, files, feature settings, and other product-specific data.
Source code, secrets, and service content
Some products may need to access source code, deployment configuration, environment variables, payloads, files, URLs, email content, webhook bodies, or other content you provide. We process that content only as needed to provide, secure, troubleshoot, and maintain the requested service. Where PicoSvc supports stored deployment secrets, those secrets are intended to be encrypted at rest and are not returned in plaintext by management APIs.
Usage and technical data
We may collect request counts, build counts, product usage, timestamps, IP addresses, user-agent information, error logs, security events, rate-limit data, diagnostic information, and similar technical information needed to operate and protect the Service.
Billing information
If you purchase a paid product plan or bundle, our billing or payment provider may process payment-card details, billing address, tax information, subscription status, invoices, and transaction identifiers. PicoSvc generally receives subscription and payment status rather than full payment-card numbers.
Connected third-party services
If you connect a service such as GitHub, we may receive repository identifiers, installation information, account identifiers, authorization metadata, and data necessary to perform the actions you request. Short-lived access credentials may be used to retrieve private repository content when required.
2. How we use information
We use information to provide and operate PicoSvc; authenticate users; enforce product plans, bundles, quotas, and rate limits; deploy and run services; process requests; troubleshoot failures; secure accounts and infrastructure; prevent fraud and abuse; communicate service changes; process billing; comply with legal obligations; and improve reliability and product design.
We do not sell personal information. We do not use private service content such as repository code, secrets, webhook payloads, or files for third-party targeted advertising.
3. Product plans and bundles
PicoSvc products are normally subscribed to separately. We store product-level entitlement and usage information so that access to one product does not automatically grant access to another. If you purchase a bundle, we may store bundle identifiers and the product entitlements granted by that bundle.
4. Service providers and sharing
We may share information with vendors that help us provide the Service, such as authentication providers, cloud infrastructure providers, source-code hosts, observability providers, email providers, and payment processors. These providers may process information on our behalf under their own contractual and security obligations.
We may also disclose information when reasonably necessary to comply with law, respond to valid legal process, protect users or the public, investigate abuse or security incidents, enforce our Terms, or complete a merger, acquisition, financing, reorganization, or sale of assets subject to appropriate protections.
5. International processing
PicoSvc and its service providers may process information in countries other than the country where you live. Those countries may have different data-protection laws. Where required, we use reasonable mechanisms intended to support lawful cross-border processing.
6. Retention
We retain account, product, billing, security, and usage information for as long as reasonably necessary to provide the Service, maintain security, resolve disputes, meet accounting or legal obligations, and enforce agreements. Product content may be deleted when you delete the associated resource or account, subject to reasonable backup, recovery, fraud-prevention, and legal-retention periods.
Temporary build data, runtime files, short-lived access tokens, caches, and logs may have shorter retention periods depending on the product and infrastructure provider.
7. Security
We use technical and organizational safeguards designed to protect information, including access controls, encrypted transport, isolation of untrusted workloads where appropriate, credential hashing or encryption where supported, and rate limiting. No system is perfectly secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur.
8. Your choices and rights
Depending on where you live, you may have rights to request access to, correction of, deletion of, restriction of, or information about certain personal data. You may also be able to withdraw consent or object to certain processing where applicable. We may need to verify your identity before fulfilling a request, and some information may be retained where legally permitted or required.
You can remove many product resources directly through the Service. You can also disconnect third-party integrations through PicoSvc or the third party where available.
9. Cookies and similar technologies
PicoSvc and its authentication or infrastructure providers may use cookies, local storage, or similar technologies for sign-in, security, session management, preferences, abuse prevention, and core functionality. We may also use limited analytics to understand aggregate Service usage.
10. Children
The Service is intended for developers and organizations and is not directed to children who cannot lawfully consent to the processing of their personal information or enter into the applicable Terms. If you believe a child has provided personal information without appropriate authorization, contact us through the private support channel displayed in the Service.
11. Changes to this Policy
We may update this Privacy Policy as PicoSvc adds products, providers, or legal requirements. We will update the effective date above and provide additional notice when a change materially affects how we handle personal information.
12. Contact
For privacy questions or data-rights requests, use the private contact or support channel displayed on the PicoSvc website or in your account dashboard. Do not send passwords, private keys, API secrets, or other sensitive credentials in a support request.