CtrlOps Privacy Policy - Your Data, Always Protected
Last Updated: August 26, 2026
This policy applies to CtrlOps, a product of TST Tech Matrix Pvt Ltd ("CtrlOps", "we", "us", "our"). It is written to comply with the privacy laws of the markets we serve, including the EU GDPR, the UK GDPR and Data Protection Act 2018, the California privacy laws (CCPA/CPRA) and other US state laws, the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), and India's Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025.
We have kept this policy plain and scannable on purpose. If anything here is unclear, email us and we will explain it in normal words.
01. Introduction
CtrlOps is a 100% local-first desktop application for managing your Linux servers. It runs on your own machine and connects straight to your servers over SSH.
Because of how CtrlOps is built, the most sensitive things you handle, your server credentials, SSH keys, commands, logs, files, and live metrics, stay on your device and never reach us.
We do run a small backend for the things any paid app needs: signing you in, issuing your license, taking payment, and answering support. This policy explains exactly what that backend collects, why, and the rights you have over it.
By using CtrlOps, you agree to the practices described here.
02. What stays on your device (and never comes to us)
This is the part most people care about, so we are putting it first.
The following never leaves your machine and is never transmitted to, stored by, or accessible to CtrlOps:
- Your server credentials and passwords
- Your SSH keys and SSH configs
- The commands you run and their output
- Your server files and anything you upload, download, or unzip
- Your logs and log contents
- Your live server metrics (CPU, memory, disk, network)
- Security audit results and the PDF reports you generate
- Your saved scripts and deployment settings
- Backup contents (these go directly from your server to your own storage, such as your S3 bucket)
✓ No cloud relay, and your servers connect to nobody but you. We never receive your credentials, server data, or command content. We do collect a few product usage events to make CtrlOps better (see Sections 03 and 09), and those events never include any of the data listed above.
03. Data we do collect
To run your account and license, our backend collects a limited set of personal data:
- Email address - only if you sign up with email. We send a one-time code (OTP) by email to verify it and create your account.
- Google sign-in - if you choose "Sign in with Google," Google handles the login and we do not store your Google profile data (no name, no profile picture).
- License data - license keys, activation status, plan, and expiry dates
- Login timestamps - used to keep your account secure and detect abuse
- Product usage events - limited events about how the app is used, such as which features you open and which onboarding steps you complete, collected via Mixpanel. These events never include your credentials, server data, commands, logs, files, or any content from your servers. We use them only to understand usage and make CtrlOps better.
- Payment and billing details - handled by our payment processor, not stored on our servers
- Support communications - emails, demo requests, and chat messages you send us
✓ We never sell or rent your data, and we never share it with third parties for their marketing.
04. Why we collect it, and our legal basis
Under the GDPR and UK GDPR we must tell you the lawful basis for each use of your data. Here it is in plain terms:
| What we do | Why | Lawful basis |
|---|---|---|
| Create your account and sign you in | To give you the service you asked for | Performance of a contract |
| Generate and validate your license | To let you use the app you paid for | Performance of a contract |
| Keep login timestamps and detect abuse | To keep your account and our service secure | Legitimate interests |
| Process payments and keep invoices | To bill you and meet tax and accounting law | Contract and legal obligation |
| Answer your support requests | To help you and resolve issues | Contract and legitimate interests |
| Product usage events (via Mixpanel) | To understand how the app is used and improve it | Consent, or legitimate interests where the law allows |
| Website marketing analytics and live chat | To improve our site and support you | Your consent |
| Keep records for as long as the law requires | To meet legal and compliance duties | Legal obligation |
You can withdraw any consent at any time. Withdrawing consent does not affect processing we already did before you withdrew it.
05. The AI Terminal, explained honestly
CtrlOps includes an AI Terminal that turns plain English into server commands, with an approve-before-run gate on by default. CtrlOps does not provide or host any AI model of its own. You choose your own AI: bring your own API key, or run a model locally on your device. Here is exactly how your data flows, because it matters:
- If you bring your own AI key (OpenAI, Google, Anthropic, or any compatible provider), your prompt and its context go directly from your machine to that provider, under your own account and their terms. It does not pass through CtrlOps, and we never see or store it. That provider's privacy policy governs what happens to it.
- If you run a local or self-hosted model, your prompts and context never leave your device at all.
✓ CtrlOps never receives, stores, or transmits your AI prompts or responses.
⚠️ A good habit: avoid pasting secrets (passwords, private keys, tokens) into any AI prompt when you are using a cloud AI provider, since that content goes to them. Use a local model if you want zero external exposure.
⚠️ AI output is your responsibility. CtrlOps does not control the AI model you connect, and AI can be wrong. We are not responsible for the accuracy, safety, or consequences of any AI-generated output. By default, you review and approve every command before it runs. CtrlOps also has an optional mode you can switch on yourself that lets the AI run commands without asking each time. If you turn that on, you are choosing to skip the approval step, and you take responsibility for what runs on your servers.
06. How long we keep your data
We keep your personal data only for as long as we actually need it, and then we delete it. In practice, that means keeping it while your account is active and to provide CtrlOps, and for as long as we need it to meet our legal, tax, and accounting duties or to resolve any dispute. Once we no longer need it, we remove it.
✓ You can ask us to delete your data at any time. Where the law requires us to keep certain records, we will keep only those and delete the rest.
07. Who we share data with
We use a small number of trusted service providers (sub-processors) to run CtrlOps. Each one only gets the data it needs for its job:
- Google OAuth - secure sign-in (governed by Google's Privacy Policy)
- Google Workspace - hosts our company email, including your support correspondence
- Razorpay - PCI DSS compliant payment processing for customers in India
- Creem - PCI DSS compliant payment processing for international customers
- Brevo - delivery of transactional emails, including your login codes and service notices
- Mixpanel (hosted in the EU) - product usage analytics that help us improve the app; never receives your credentials or server data. You can opt out (see Section 09)
- Live chat widget (talk.to) - only after you opt in
We sign data processing agreements with these providers and review them for security and privacy.
✓ For the complete, current list of every sub-processor we use and where each is based, see our Sub-Processors page at /sub-processors.
✓ Your one-time login codes (OTP) are generated by our own system and only delivered to you by email through Brevo. We do not use any third-party OTP provider.
✓ We never sell or share your personal data for anyone else's advertising. If a law ever requires us to disclose data (for example, a valid legal order), we will tell you where we are allowed to.
08. International data transfers
TST Tech Matrix Pvt Ltd is based in India, and some of our providers operate in other countries. That means your data may be processed outside your home country.
When we transfer personal data out of the EU, UK, or another region with transfer rules, we protect it using approved safeguards, including Standard Contractual Clauses (EU) and the International Data Transfer Agreement (UK), plus additional security measures.
Our product analytics data (Mixpanel) is hosted in the EU.
You can ask us for a copy of the safeguards we use by emailing the contact in Section 17.
09. Cookies and analytics
In the app: we collect the limited product usage events described in Section 03 (which features are used, onboarding steps completed), and nothing else. These events never include your credentials, server data, or command content. If you would rather not share them, email us at support@ctrlops.io and we will turn them off for your account.
On our website: only strictly necessary cookies load automatically. Our marketing analytics runs for every visitor in a cookieless mode that sets nothing on your device and does not identify you. The live chat widget does not load until you opt in through our cookie consent banner, and you can change that choice at any time.
✓ Read the full Cookie Policy at /cookie-policy for the complete list of cookies, providers, and retention periods.
10. How we protect your data
Security is built into how CtrlOps works. Our measures include:
- Local-by-design architecture - your most sensitive data stays on your device (see Section 02)
- Encryption in transit and at rest (TLS/HTTPS) for all backend account and license data
- Local, secure storage of your credentials and SSH keys on your own machine
- Need-to-know access controls and least-privilege access for our staff
- Logging and monitoring of our backend systems
- Regular security audits, patching, and dependency updates
- Vendor due diligence on every sub-processor
- A documented incident response process
A vault to lock CtrlOps. You can secure the app with your own vault password, adding a layer of protection right on your device. Please keep this password safe: for your security, it is never stored anywhere we can see, so there is no password recovery. If you forget your vault password, it cannot be reset or recovered by anyone, including us.
On SOC 2: we are not yet certified, and we do not claim to be. We build and run our security program to align with the principles of SOC 2 and ISO/IEC 27001, and we are actively working toward formal certification. When we achieve either, we will state it here and make the relevant report or certificate available to enterprise customers on request.
11. Your rights
Wherever you live, you can ask us to:
- Access - get a copy of the personal data we hold about you
- Correct - fix data that is wrong or incomplete
- Delete - have your personal data erased
- Port - receive your data in a machine-readable format
- Object or restrict - object to or limit certain processing
- Withdraw consent - for anything based on your consent
To exercise any right, email the contact in Section 17. We respond within the timelines the law requires, and always within 48 hours for a first reply. We will not charge you or treat you differently for using your rights.
We do not use your personal data for any automated decision-making or profiling that produces legal or similarly significant effects.
12. Data breach notification
If a personal data breach ever affects you, we will act quickly. We will notify the relevant regulator and affected users without undue delay, and in line with the timelines the law sets (for example, within 72 hours where the GDPR or India's DPDP Rules require it). Our notice will explain, in plain language, what happened, what data was involved, and what you can do about it.
13. Children's privacy
CtrlOps is a professional tool built for adults and organizations, and we do not intend it for independent use by children. If you are under 18, you should use CtrlOps only under the supervision of a parent, guardian, or organization who holds the account and accepts our Terms. We do not knowingly collect personal data directly from a child acting on their own. If you believe a child has given us data, contact us and we will delete it.
14. Changes to this policy
We may update this policy from time to time. When we make a significant change, we will update the "Last Updated" date at the top and notify you by email or in the app. Your continued use after an update means you accept the revised policy.
15. Region-specific notices
For users in the EU and UK
- Our lawful bases are set out in Section 04, and our transfer safeguards in Section 08.
- You have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office / ICO; in the EU, your national Data Protection Authority).
For users in the United States (California and other states)
- In the past 12 months we collect these categories of personal information: identifiers (primarily your email address), commercial information (license and subscription), internet or app activity (limited product usage events, plus website analytics if you opt in), and customer records (support messages).
- We do not sell or share your personal information, including for cross-context behavioral advertising.
- You have the right to know, delete, correct, and opt out, and to be free from discrimination for exercising these rights. You may use an authorized agent, and we honor recognized opt-out signals such as Global Privacy Control.
- To exercise these rights, use the contact in Section 17.
For users in India
- We act as the Data Fiduciary and you are the Data Principal under the Digital Personal Data Protection Act, 2023.
- We process your data based on your consent or other lawful grounds, and you may withdraw consent as easily as you gave it.
- You have the right to access, correction, and erasure, the right to grievance redressal, and the right to nominate another person to exercise your rights if you are unable to.
- For any privacy question or grievance, email support@ctrlops.io and we will respond within the timelines the law requires. If your grievance is not resolved, you may approach the Data Protection Board of India.
For users in the UAE
- We process your personal data in line with the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), supervised by the UAE Data Office.
- You have rights to access, correction, deletion, restriction, portability, and objection, and the right to complain to the UAE Data Office.
16. Data Controller and Contact
Data Controller / Data Fiduciary
TST Tech Matrix Pvt LtdMondeal Heights, B-1702, Sarkhej - Gandhinagar Hwy, Satellite, Ahmedabad, Gujarat 380015, IndiaGSTIN: 24AAKCT6577G1ZXEmail: support@ctrlops.io
17. Questions about your privacy?
Reach out any time. We respond to all privacy inquiries within 48 hours.
support@ctrlops.ioCtrlOps by TST Tech Matrix Pvt Ltd.