Legal
Privacy Policy
What we collect, why, and for how long. The short version: your email address to sign you in, a record of who did what so your workspace has an audit log, and nothing for advertising.
1. Who this covers
This policy describes how Jia Yang Inc., trading as Jiayang Cloud, handles personal data when you visit jiayang.cloud, sign in to the dashboard at app.jiayang.cloud, use the CLI or the API, or open an app someone has shared with you on jiayang-apps.cloud.
For the account data described below, we are the controller. For the data inside our customers' apps (what an app stores about the people who use it), the customer who deployed the app is the controller and we are their processor, under the Data Processing Addendum. If you have a question about an app's data, the app's owner is the right person to ask; their email is shown in the dashboard to everyone the app is shared with.
2. What we collect
Account
- Your email address. It is your identity on the platform: how you sign in, how apps are shared with you, and how you appear in audit logs. We don't collect a name unless you write one to us.
- Terms acceptance: which version you accepted and when.
Sign-in and sessions
- For every sign-in code we send and every session we create: the time, the IP address, the browser or CLI user agent, and the country the request came from (as reported by Cloudflare). A browser session lasts 12 hours and a CLI session 30 days, and neither can be extended. You can see your active sessions in the dashboard and revoke any of them.
- Sign-in codes themselves are stored hashed, expire after ten minutes, and are deleted after use.
Workspaces and apps
- Workspace names and members; app names, addresses and versions; environment variable names (values are encrypted and never shown back to a person); public paths, and which provider signs the deliveries to each path that has a webhook verifier (its signing secret is encrypted and never shown back to a person); bearer token names and when each was last used (the token itself is stored hashed).
- The code and files you deploy, and the data your apps store, which we host on your instructions and do not read.
Audit log
- Every action on a workspace (a deploy, a share, a token, a change of settings), with who did it, when, and from which IP address.
- Every request to an app: the time, the app, the path and method, the response status, and the identity of the caller (an email address, a token name, the webhook provider for a delivery whose signature the platform checked, with the identifier the provider gives that delivery where it gives one, or nobody for any other request to a public path). This is the audit log the workspace's members can see, and it is why the platform exists.
Billing
- If a workspace is on a paid plan, we create a customer for it at Stripe with the workspace owner's email address as the customer's email and the workspace's name as the customer's name, so the invoices say whose they are. Stripe then collects your billing name, address, card details and tax information, including a VAT, GST or tax ID if you enter one. We never see the card number. We keep Stripe's customer and subscription identifiers, the plan, its status and the dates of the current billing period, and the hourly request counts we report to Stripe, which is what the allowance and the overage are worked out from. Invoices and their amounts live in Stripe; we store no amounts.
Support
- Emails you send us, and what we need to answer them.
The website
- jiayang.cloud itself sets no cookies and runs no analytics. Cloudflare, which serves it, keeps standard access logs for a short period for security and operations. Everything the pages load, the typefaces included, comes from jiayang.cloud itself.
We don't buy data about you, enrich your profile from other sources, or track you across other sites.
3. Why, and on what basis
| Purpose | Data | Basis (GDPR) |
|---|---|---|
| Signing you in, and keeping your account yours | Email, sign-in metadata, sessions | Performance of the contract; our legitimate interest in preventing account takeover |
| Running the platform: deploying, serving and sharing apps | Workspace and app data, your content | Performance of the contract |
| The audit log: showing workspace members who did what | Audit events, request logs | Performance of the contract; the customer's legitimate interest in knowing who used their apps |
| Billing and tax | Billing records | Performance of the contract; legal obligation (tax and accounting law) |
| Answering you | Support emails | Performance of the contract; legitimate interest |
| Security: detecting abuse, attacks and fraud | Sign-in metadata, request logs | Legitimate interest in keeping the Service and its customers safe; legal obligation |
| Telling a workspace's owners what is happening to it: a payment failing, the move to Free that follows, the Free request allowance running out, a suspension, audit-log entries about to be deleted | Owners' email addresses; the workspace's plan, billing status and request counts | Performance of the contract |
| Telling you about changes to the Service, the terms or the prices | Performance of the contract; legal obligation |
We don't use your data for advertising, we don't send marketing email, and we don't make automated decisions about you that have legal or similarly significant effects.
4. Cookies
The dashboard and the apps use exactly two cookies, both of which exist only to sign you in. Neither is used for tracking, and there are no third-party cookies.
| Cookie | Set by | What it does | Lasts |
|---|---|---|---|
__Host-jiayang_session | app.jiayang.cloud, and each app's own address once you open it | Your signed-in session. Signed by us; the platform verifies the signature on every request. | 12 hours, or until you sign out or revoke it |
__Host-jiayang_state | An app's address, during sign-in | Ties the redirect back from the dashboard to the browser that started it, so a sign-in link can't be replayed elsewhere. | Minutes; deleted once the sign-in completes |
Because these cookies are strictly necessary to provide the service you asked for, no consent banner is required for them. The website at jiayang.cloud sets none. Apps deployed by our customers may set their own cookies; those are the app owner's responsibility.
5. Who we share it with
We share personal data only with:
- Our subprocessors: the providers that host the platform, store data, send and hold email, and take payment. The current list, with what each does and where, is on the Subprocessors page. Each is bound by a contract that limits what it may do with the data. We tell workspace owners 30 days before adding one.
- The people in your workspace. Your email address and your actions are visible to the other members of a workspace you belong to, and to the owner of an app you have been given access to, in the audit log. That is the product.
- Authorities, when a law, a court order or a binding request obliges us to, and only to the extent it does. Where we are allowed to, we tell the affected customer first.
- A successor, if the business is sold or merged; the successor takes over this policy and you are told.
We don't sell personal data, and we don't share it with advertisers or data brokers.
6. Where it is processed
The platform runs on Cloudflare's global network, so a request is handled at the Cloudflare location nearest the person making it. Stored data lives in the United States: account data with Cloudflare, the control-plane database with Neon (AWS us-east-2, Ohio), and billing with Stripe. The exception is email you send us, which Proton holds in Switzerland, Germany or Norway. The platform's email (sign-in codes, invitations and notices to workspace owners) is sent through Resend from eu-west-1 (Ireland). The Subprocessors page has the detail.
Where data about people in the European Economic Area, the United Kingdom or Switzerland is transferred to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) with each provider, together with the safeguards in section 9. You can ask us for a copy of the clauses we have in place.
7. How long we keep it
| Data | Kept |
|---|---|
| Account (email, terms acceptance) | Until you delete your account, then removed within 30 days |
| Sign-in codes | 10 minutes, or until used; the record that one was sent stays an hour longer, for rate limiting |
| Browser sessions and their metadata | Until they expire (12 hours) or are revoked; the record of the session for 30 days after it ends, for security |
| CLI sessions and their metadata | Until they expire (30 days) or are revoked; the record of the session for 90 days after it ends, for security |
| Apps and your content (code, files, databases, containers) | Until the app or the workspace is deleted, then removed from Cloudflare at once. Deletion is permanent; nothing is restorable |
| The control plane's records of a deleted app | Its configuration, versions, sharing grants, tokens, secrets and environment variables are removed at once, with the app. Its entries in the workspace's audit log, the one recording the deletion among them, stay there, where the workspace's members can still see and export them, and are deleted with the rest of the log (below) |
| The control plane's records of a deleted workspace (names, members, configuration, billing status) | 30 days after the deletion, for accounting, then removed. Not restorable in that time either |
| Audit log | 3 months on Free and Team, 12 months on Business, measured from the event; then deleted. After a downgrade, events older than the new plan's retention are deleted 30 days after the plan changed. A deleted workspace's log goes with its other records, 30 days after the deletion. A workspace owner can export it on every plan |
| Billing records | 7 years after the transaction, as tax and accounting law requires. Stripe keeps its own records under its policy |
| Support email | 2 years after the last message in the thread |
| Security and access logs at the edge | Up to 30 days |
| Our own record of account and workspace events (terms accepted, an account or workspace deleted, a workspace suspended) | 7 years, like billing records. Once you delete your account, your email address in these records, and in our log of your sign-ins and sessions, is replaced by a one-way hash of it |
| Backups of the control-plane database | Neon's point-in-time restore, on the plan we run: up to 7 days of history (Launch plan, neon.com/pricing, checked 22 September 2026), so a deletion is gone from it within that time. The restore history is for disaster recovery and is never used to restore a deleted workspace or app |
| Point-in-time history of each app's database | A Workers app's database is Cloudflare D1, which keeps a point-in-time history of the last 30 days (Time Travel, on the Workers Paid plan we run: developers.cloudflare.com/d1/reference/time-travel, checked 23 September 2026). Cloudflare maintains it, it is always on and it cannot be switched off, so a row an app deletes or overwrites stays in that history for up to 30 days. The platform offers no way to restore from it |
Where a legal hold, a dispute or an investigation requires it, we keep the relevant data for as long as that requires and no longer.
8. Your rights, and how to use them
Wherever you are, you can ask us what we hold about you and ask us to correct or delete it. If you are in the EEA, the UK, Switzerland or another place with similar law, you also have the rights to restrict or object to processing, to data portability, and to complain to your supervisory authority. Most of this you can do yourself, immediately, from the dashboard:
- Access and portability. On every plan, a workspace owner can export the workspace as one JSON document from the workspace's Settings: its configuration, members, sharing grants, the names of its tokens, secrets and environment variables, and the audit log the plan retains. Each app's database can be exported on its own, as SQL, from the dashboard or with
jiayang db export; a static site is the files you uploaded. Your sessions are listed in the account menu. - Correction. Your email address is your identity, so it can't be edited in place; sign in with the new address and move your workspaces across, or ask us.
- Erasure. Delete an app from its page, or a workspace from its Settings, with a typed confirmation. Deletion is immediate and permanent: the app's data is removed from Cloudflare right away and its records with it, except its entries in the workspace's audit log, which stay for the log's retention; only the control plane's records of a deleted workspace linger 30 days for accounting, never restorable; export first. Deleting a workspace on a paid plan cancels its subscription at once, with no refund for the rest of the period. Delete your account from the account menu; it is refused only while you are the sole owner of a workspace or of an app.
- Objection and restriction. Email us. Note that the audit log is kept in the interest of the workspace whose apps you used; we will weigh an objection against that interest and tell you what we decided and why.
Anything you can't do yourself: write to privacy@jiayang.cloud from the address on your account. We answer within 30 days, and we don't charge for it unless a request is plainly unfounded or repetitive.
If you are unhappy with our answer, you can complain to the data protection authority where you live. We would rather you told us first.
9. Security
The Security page describes how the platform is built to protect your data: every app behind one door, signed identity on every request, row-level isolation between workspaces, secrets encrypted with a platform key, and revocation within a minute. Data is encrypted in transit and at rest by the providers that store it. Access to production by our staff is limited to what operating the service needs, and is logged.
If we learn of a breach affecting your personal data, we tell you without undue delay, and the affected workspace owners within 72 hours of confirming it, with what we know and what we are doing about it.
10. Children
The Service is for businesses and professional use and is not directed at children. We don't knowingly collect data about anyone under 18; if you think we have, tell us and we will delete it.
11. Changes
When this policy changes in a way that affects you, we email workspace owners at least 30 days before it takes effect, and the date at the top changes. Clarifications take effect when published. Earlier versions are available on request.
12. Contact
Privacy questions and requests: privacy@jiayang.cloud. Everything else: support@jiayang.cloud, or by post at the address above.