Legal

Privacy policy

This explains what Kernel6 collects when you use kernel6.com, why we need it, where it lives, and how to get it deleted. We have tried to make it specific rather than long.

Last updated 3 October 2026

Who we are

Kernel6 (“we”, “us”) provides managed website hosting at kernel6.com. For the personal data described here, Kernel6 decides why and how it is processed. You can reach us through the contact form. Our sending address, no-reply@kernel6.com, cannot receive mail, so please do not reply to it.

What we collect

Your account

  • Email address and name, which you give us when you sign up. We use them to sign you in and to write to you about your account.
  • Your password, stored only as a bcrypt hash. We cannot read it and nobody at Kernel6 can tell you what it is.
  • Password-reset requests: a SHA-256 hash of the one-time reset token, when it expires, and how many requests were made recently (to stop the form being used to flood someone’s inbox). The reset email itself includes the IP address the request came from, so you can spot a request you did not make.
  • Subscription details: which payment provider you used, the provider’s subscription and customer reference, your plan, its status and when the current period ends.

What you host with us

  • Projects: the name you give each one, the Git repository URL and branch you point us at, build settings (root directory, install, build and start commands), the port it runs on and its status.
  • Your code: we clone the repository you give us onto the server that runs it, install its dependencies and build it there. We do not copy your code anywhere else.
  • Environment variables: the keys and values you save for each project. Values are encrypted with AES-256-GCM before they are stored, are written to the server only when your app is deployed, and are not shown back to anyone, including our own staff, through the dashboard.
  • Deployment logs: the output of each deploy (clone, install, build, start), so you can see what happened. These can contain anything your build prints.
  • Domains: hostnames you add, whether their DNS points at us yet, and when we last checked.

When you contact us

The contact form stores your name, email address, message and the IP address it was sent from. We keep the message in our database as well as emailing it to ourselves, so it is not lost if email delivery fails. The IP address is used to limit how many messages one address can send.

Billing records

For each payment we keep an invoice or receipt: its number, your name and email as they were at the time, the plan, the amount, the payment provider and its reference, and the billing period.

What we do not collect

  • Card or bank details. Payments are taken by Razorpay, Stripe or Dodo Payments on their own pages or checkout windows. Your card number never reaches our servers.
  • Analytics or advertising trackers. kernel6.com runs no analytics, advertising or social-media scripts. Fonts are bundled with the site, not loaded from a third party.
  • Your visitors’ data. What your own website collects from its visitors is between you and them. We run your app; we do not inspect or use the data it handles.

Cookies

We set one cookie, cd_token, when you sign in. It holds a signed token that tells us who you are, is marked HttpOnly so scripts on the page cannot read it, and expires after 7 days. There are no other cookies of ours. If you open a payment provider’s checkout, that provider may set its own cookies under its own policy.

Why we use it

PurposeData used
Running your account and signing you inEmail, name, password hash, session cookie
Building, running and serving your websitesProjects, repository URL, environment variables, domains
Telling you when something goes wrongEmail, project status (we check every few minutes whether your app is running)
Security notices (password or email changed)Email, the IP address the change came from
Billing, invoices and tax recordsSubscription details, invoices
Answering your messagesContact-form submissions

We do not sell your data, rent it, or use it for advertising. We send you email about your account, your sites and your billing. We do not send marketing newsletters.

Who processes it for us

We rely on a small number of providers to run the service:

ProviderWhat for
Amazon Web Services (AWS)The servers that run kernel6.com, our database, and your websites
GoDaddyDelivering the emails we send you
Razorpay, Stripe, Dodo PaymentsTaking payments, depending on which one you choose at checkout
Let’s EncryptIssuing HTTPS certificates for your sites’ hostnames
Your Git host (for example GitHub)We fetch your code from the repository URL you give us

HTTPS certificates are recorded in public Certificate Transparency logs, so a hostname you put on Kernel6 becomes publicly visible in those logs. This is true of every HTTPS site.

We may disclose data if Indian law requires it, for example in response to a valid order from a court or a government authority.

Where your data is stored

kernel6.com and its database run on AWS in the Asia Pacific (Sydney) region, Australia. On the Dedicated plan, your own server runs in the AWS region we provision it in, which is Asia Pacific (Mumbai), India, by default. This means your account data is stored outside India. By using Kernel6 you understand that your data is transferred to and processed in those locations.

How long we keep it

  • Your account, projects, environment variables, domains and deployment logsare kept while your account exists. Deleting a project removes its deployments and logs and stops and removes the app from its server.
  • When you close your account (Settings → Delete account), we stop and remove every app you run, and delete your projects, deployments, logs, domains, the contact messages sent from your email address, and your account itself.
  • Invoices and receipts are kept after you close your account. They are financial records, and tax law and our payment providers require us to keep them.
  • A record of billing actions (for example, when a subscription was cancelled and by whom) is kept so that billing disputes can be resolved.

Your rights

Under Indian law, including the Digital Personal Data Protection Act, 2023, you can ask to see the personal data we hold about you, have it corrected, or have it erased. Much of this you can do yourself:

  • Change your name or email address in Settings.
  • Delete a project, or your whole account, from the dashboard.
  • For anything else, including a copy of your data, write to us through the contact form. We will confirm it is really you before acting on the request.

How we protect it

Passwords are hashed with bcrypt, environment variables and server credentials are encrypted with AES-256-GCM, and sessions use an HttpOnly cookie. Your apps are only reachable through our HTTPS proxy, not directly. Our security page has the detail. No system is perfectly secure. If we become aware of a breach that affects your data, we will tell you and the relevant authorities as the law requires.

Children

Kernel6 is a service for businesses and adults. You must be at least 18 years old to create an account.

Grievances

If you have a complaint about how we handle your data or any content on the platform, send it through the contact form and start the message with “Grievance”. We acknowledge grievances within 24 hours and aim to resolve them within 15 days.

Changes to this policy

If we change what we collect or who processes it, we will update this page and the date at the top. If a change is significant, we will email account holders before it takes effect.