hydrant
Appearance
Hydrant

Where the water goes.

Version 4 · Adopted Sep 17, 2026 — v4: listed PostHog as the processor for optional signed-in usage events in the United States. v3: workspace content is permanently purged after the seven-day cancellation window. v2: account deletion is now self-service from Settings. v1: adopted alongside Terms and Privacy for paid sign-up.

Who processes your data and where

Cloudflare hosts the application on its global network and stores images and encrypted backups in R2 in its eastern North America region. Neon runs the PostgreSQL database in the United States (AWS us-east-2). GitHub provides sign-in, deployment and the scheduled backup jobs. Resend sends transactional email such as invitations. Better Stack runs uptime checks and the public status page and sees only probe results. Sentry receives error reports that are scrubbed of personal data before they leave the app.

PostHog processes limited signed-in usage events in its US region when analytics is enabled: page categories and workspace or issue creation, without issue content, names, email addresses or private URLs. PostHog processes the connection IP to receive events; IP storage and geographic enrichment are disabled. Payments through Stripe are planned and will be listed here before they are switched on. There are no data residency options.

What is stored

Account records: your GitHub identity, name, email and profile image, sessions with IP address and browser details, and encrypted provider tokens. Workspace content: issues, comments, activity, revisions, relationships, labels, views, projects, cycles, library and playbook documents, and uploaded images. Credentials: hashed agent keys, hashed MCP tokens and the consents you grant. Operational records: email delivery status without message content, rate-limit counters and backup completion records.

Never stored: card details, raw agent keys or raw MCP tokens.

How long it is kept

Trashed issues: purged 30 days after trashing (the purge job is planned; until it ships, trashed issues are retained). Activity and revisions: for the life of the workspace. Sessions: seven days, refreshed while you keep using Hydrant. Records of which Terms and Privacy versions you accepted: for the life of your account. Deleted accounts: removed immediately when you delete your account, keeping an anonymous deletion record, your contributions under “Deleted account”, and workspace records such as invitations that were sent to your email address. Unlinked uploaded images: 24 hours. Deleted workspaces: a seven-day cancellation window, then permanent purge of live workspace content; a deletion record is retained. Encrypted backups: the newest snapshot for each of the last seven days and four weeks, plus the operator’s independently verified copy. Email delivery records: 90 days (automatic deletion is planned; until it ships, records are retained). Error reports at Sentry: 30 days. Previously delivered PostHog usage events may remain under an opaque account identifier after account deletion; contact bots@hydrant.dev to request deletion of those provider records.

Your requests

You can ask for access to, correction of, export of or deletion of your data. Identity is verified by signing in with GitHub to the account concerned; email alone is not proof. You will get a response within 30 days. You can delete your account yourself from Settings. Until self-service export ships, the operator handles export and other requests by hand. Send requests to bots@hydrant.dev.

If something goes wrong

On a confirmed breach the operator preserves the evidence, contains it by rotating secrets and revoking affected credentials, notifies affected accounts within 72 hours of confirmation, notifies the relevant authority where EU or UK residents are affected, and records what happened.

Operator access

Production access is limited to the operator’s own accounts. No contractor or third party has access. Backup decryption keys are held outside the application and the cloud providers.

Send a flare to bots@hydrant.dev