Legal

Privacy Policy

What we collect, why, and for how long. The short version: your email address to sign you in, a record of who did what so your workspace has an audit log, and nothing for advertising.

Last updated 24 September 2026

1. Who this covers

This policy describes how Jia Yang Inc., trading as Jiayang Cloud, handles personal data when you visit jiayang.cloud, sign in to the dashboard at app.jiayang.cloud, use the CLI or the API, or open an app someone has shared with you on jiayang-apps.cloud.

Jia Yang Inc. 2810 N Church St STE 90394 Wilmington, DE 19802 US Contact: privacy@jiayang.cloud

For the account data described below, we are the controller. For the data inside our customers' apps (what an app stores about the people who use it), the customer who deployed the app is the controller and we are their processor, under the Data Processing Addendum. If you have a question about an app's data, the app's owner is the right person to ask; their email is shown in the dashboard to everyone the app is shared with.

2. What we collect

Account

Sign-in and sessions

Workspaces and apps

Audit log

Billing

Support

The website

We don't buy data about you, enrich your profile from other sources, or track you across other sites.

3. Why, and on what basis

PurposeDataBasis (GDPR)
Signing you in, and keeping your account yoursEmail, sign-in metadata, sessionsPerformance of the contract; our legitimate interest in preventing account takeover
Running the platform: deploying, serving and sharing appsWorkspace and app data, your contentPerformance of the contract
The audit log: showing workspace members who did whatAudit events, request logsPerformance of the contract; the customer's legitimate interest in knowing who used their apps
Billing and taxBilling recordsPerformance of the contract; legal obligation (tax and accounting law)
Answering youSupport emailsPerformance of the contract; legitimate interest
Security: detecting abuse, attacks and fraudSign-in metadata, request logsLegitimate interest in keeping the Service and its customers safe; legal obligation
Telling a workspace's owners what is happening to it: a payment failing, the move to Free that follows, the Free request allowance running out, a suspension, audit-log entries about to be deletedOwners' email addresses; the workspace's plan, billing status and request countsPerformance of the contract
Telling you about changes to the Service, the terms or the pricesEmailPerformance of the contract; legal obligation

We don't use your data for advertising, we don't send marketing email, and we don't make automated decisions about you that have legal or similarly significant effects.

4. Cookies

The dashboard and the apps use exactly two cookies, both of which exist only to sign you in. Neither is used for tracking, and there are no third-party cookies.

CookieSet byWhat it doesLasts
__Host-jiayang_sessionapp.jiayang.cloud, and each app's own address once you open itYour signed-in session. Signed by us; the platform verifies the signature on every request.12 hours, or until you sign out or revoke it
__Host-jiayang_stateAn app's address, during sign-inTies the redirect back from the dashboard to the browser that started it, so a sign-in link can't be replayed elsewhere.Minutes; deleted once the sign-in completes

Because these cookies are strictly necessary to provide the service you asked for, no consent banner is required for them. The website at jiayang.cloud sets none. Apps deployed by our customers may set their own cookies; those are the app owner's responsibility.

5. Who we share it with

We share personal data only with:

We don't sell personal data, and we don't share it with advertisers or data brokers.

6. Where it is processed

The platform runs on Cloudflare's global network, so a request is handled at the Cloudflare location nearest the person making it. Stored data lives in the United States: account data with Cloudflare, the control-plane database with Neon (AWS us-east-2, Ohio), and billing with Stripe. The exception is email you send us, which Proton holds in Switzerland, Germany or Norway. The platform's email (sign-in codes, invitations and notices to workspace owners) is sent through Resend from eu-west-1 (Ireland). The Subprocessors page has the detail.

Where data about people in the European Economic Area, the United Kingdom or Switzerland is transferred to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) with each provider, together with the safeguards in section 9. You can ask us for a copy of the clauses we have in place.

7. How long we keep it

DataKept
Account (email, terms acceptance)Until you delete your account, then removed within 30 days
Sign-in codes10 minutes, or until used; the record that one was sent stays an hour longer, for rate limiting
Browser sessions and their metadataUntil they expire (12 hours) or are revoked; the record of the session for 30 days after it ends, for security
CLI sessions and their metadataUntil they expire (30 days) or are revoked; the record of the session for 90 days after it ends, for security
Apps and your content (code, files, databases, containers)Until the app or the workspace is deleted, then removed from Cloudflare at once. Deletion is permanent; nothing is restorable
The control plane's records of a deleted appIts configuration, versions, sharing grants, tokens, secrets and environment variables are removed at once, with the app. Its entries in the workspace's audit log, the one recording the deletion among them, stay there, where the workspace's members can still see and export them, and are deleted with the rest of the log (below)
The control plane's records of a deleted workspace (names, members, configuration, billing status)30 days after the deletion, for accounting, then removed. Not restorable in that time either
Audit log3 months on Free and Team, 12 months on Business, measured from the event; then deleted. After a downgrade, events older than the new plan's retention are deleted 30 days after the plan changed. A deleted workspace's log goes with its other records, 30 days after the deletion. A workspace owner can export it on every plan
Billing records7 years after the transaction, as tax and accounting law requires. Stripe keeps its own records under its policy
Support email2 years after the last message in the thread
Security and access logs at the edgeUp to 30 days
Our own record of account and workspace events (terms accepted, an account or workspace deleted, a workspace suspended)7 years, like billing records. Once you delete your account, your email address in these records, and in our log of your sign-ins and sessions, is replaced by a one-way hash of it
Backups of the control-plane databaseNeon's point-in-time restore, on the plan we run: up to 7 days of history (Launch plan, neon.com/pricing, checked 22 September 2026), so a deletion is gone from it within that time. The restore history is for disaster recovery and is never used to restore a deleted workspace or app
Point-in-time history of each app's databaseA Workers app's database is Cloudflare D1, which keeps a point-in-time history of the last 30 days (Time Travel, on the Workers Paid plan we run: developers.cloudflare.com/d1/reference/time-travel, checked 23 September 2026). Cloudflare maintains it, it is always on and it cannot be switched off, so a row an app deletes or overwrites stays in that history for up to 30 days. The platform offers no way to restore from it

Where a legal hold, a dispute or an investigation requires it, we keep the relevant data for as long as that requires and no longer.

8. Your rights, and how to use them

Wherever you are, you can ask us what we hold about you and ask us to correct or delete it. If you are in the EEA, the UK, Switzerland or another place with similar law, you also have the rights to restrict or object to processing, to data portability, and to complain to your supervisory authority. Most of this you can do yourself, immediately, from the dashboard:

Anything you can't do yourself: write to privacy@jiayang.cloud from the address on your account. We answer within 30 days, and we don't charge for it unless a request is plainly unfounded or repetitive.

If you are unhappy with our answer, you can complain to the data protection authority where you live. We would rather you told us first.

9. Security

The Security page describes how the platform is built to protect your data: every app behind one door, signed identity on every request, row-level isolation between workspaces, secrets encrypted with a platform key, and revocation within a minute. Data is encrypted in transit and at rest by the providers that store it. Access to production by our staff is limited to what operating the service needs, and is logged.

If we learn of a breach affecting your personal data, we tell you without undue delay, and the affected workspace owners within 72 hours of confirming it, with what we know and what we are doing about it.

10. Children

The Service is for businesses and professional use and is not directed at children. We don't knowingly collect data about anyone under 18; if you think we have, tell us and we will delete it.

11. Changes

When this policy changes in a way that affects you, we email workspace owners at least 30 days before it takes effect, and the date at the top changes. Clarifications take effect when published. Earlier versions are available on request.

12. Contact

Privacy questions and requests: privacy@jiayang.cloud. Everything else: support@jiayang.cloud, or by post at the address above.