This Privacy Policy describes how Pod42 LLC, the owner and operator of privatedatapod.com (“we,” “us,” “our”), collects, uses, and protects information about you when you use the Private Data Pod service. It applies to our website, your pod, and any connected platform services (the “Service”).
1. Overview
Private Data Pod is built around a simple principle: your data is yours. Our business model is a subscription fee, not data monetisation. We do not sell, rent, share, or exploit your personal information or the contents of your pod for advertising, analytics resale, or any commercial purpose other than operating the Service for you.
We collect only what is necessary to create your account, process payment, deliver the Service, and ensure its security. Everything else stays in your pod, where only you control access.
2. Information We Collect
We collect the following categories of information when you use the Service:
- Account information: your email address and full name, provided at registration. These are used for authentication, your pod WebID profile, and service notifications.
- Billing information (Pro plan only): your name, email address, and card last 4 digits, card brand, and card expiry date. Full payment card details are processed exclusively by Stripe and never stored on our servers.
- Pod content: the files, documents, and data you store in your pod. This content is stored on your behalf and is described further in Section 5.
- Server access logs: IP address, timestamp, HTTP method, URL path, response status code, and user-agent string. Retained for 30 days for abuse prevention, security monitoring, and troubleshooting.
- Session data: an encrypted session cookie issued after login, used to maintain your authenticated session. It contains only a session identifier and does not store personal data directly.
3. What We Never Collect
We do not collect, and have taken active steps to ensure we cannot collect, the following:
- Advertising identifiers or cross-site tracking cookies
- Behavioural analytics, browsing history, or user-activity telemetry
- Device fingerprints, canvas probes, or font enumeration
- Third-party analytics (no Google Analytics, no Segment, no Mixpanel, no Meta Pixel)
- Full payment card numbers, CVVs, or bank account details — these never touch our servers
- The contents of your pod files for any purpose other than serving them back to you or people you grant access to
4. How We Use Your Information
We use the information we collect only for the following purposes:
- Account creation and authentication: to create and secure your pod and account login.
- Service delivery: to route requests to your pod, enforce access control, and serve your data to authorised clients.
- Billing: to process Pro plan subscriptions, issue receipts, and manage renewals and cancellations via Stripe.
- Service communications: to send essential account notifications, such as password resets, billing receipts, and critical service updates. We do not send marketing email without your explicit opt-in.
- Security and abuse prevention: to detect and investigate unauthorised access, enforce our Terms of Service, and protect the integrity of the Service and other users’ pods.
- Legal compliance: to comply with applicable law, respond to lawful requests from public authorities, and protect our legal rights.
We do not use your information to build advertising profiles, train machine-learning models, or derive inferences about your behaviour, interests, or identity beyond what is necessary to operate the Service.
5. Your Pod Content
The data you store in your pod is yours. We act as a data custodian, not a data controller, with respect to pod content. We do not read, analyse, index for search advertising, or otherwise process the contents of your pod except as technically required to:
- Store and retrieve files in response to authenticated HTTP requests
- Enforce storage quotas (Pro: 10 GB; Free: 1 GB)
- Deliver email notifications that you have configured (e.g. password reset)
- Comply with a valid legal order, after exhausting applicable legal challenges
Pod content is encrypted at rest on AES-256 encrypted EBS volumes (AWS-managed key). Access control is enforced by the Solid Web Access Control (WAC) layer on every request: public resources are opt-in only. No employee or contractor has routine access to your pod data.
6. Third Parties & Subprocessors
We use a minimal, fixed set of third-party services to operate the infrastructure. We do not use subprocessors for advertising, analytics, or data enrichment. The complete list is below.
| Vendor | Purpose | Data shared |
|---|---|---|
| Amazon Web Services (AWS) | EC2 compute and EBS storage for all services | Pod content (encrypted at rest), server logs, all traffic processed on-instance |
| Amazon Route 53 | DNS for privatedatapod.com and wildcard subdomains | Domain names only; no user data or pod content |
| Let’s Encrypt | Automated TLS certificates via the ACME protocol | Domain names only; no user data |
| Stripe | Pro plan payment processing and subscription management | Name, email, and full payment card details for Pro subscribers only. Stripe never accesses pod content. Stripe’s privacy policy is at stripe.com/privacy. |
| Zoho Mail (SMTP) | Transactional email delivery (password resets, billing receipts) | Email address and message content for emails you trigger (e.g. password reset). No pod content. |
We will update this table before adding any new subprocessors. We do not use subprocessors that are not listed here.
7. Data Retention
We retain your data for the following periods:
- Account and billing information: retained for the duration of your account, and for up to 7 years after account closure to satisfy legal and accounting obligations.
- Pod content: retained while your account is active. After account closure, pod content is retained for 30 days to allow you to export your data, then permanently deleted.
- Server access logs: retained for 30 days on a rolling basis, then deleted.
- Session cookies: expire after 14 days of inactivity or immediately on logout.
- Stripe payment records: retained by Stripe per their own data retention policies.
You can export your pod data at any time before deletion using any compatible Solid client or the standard HTTP download method. See our Trust Center for instructions.
8. Your Rights
Regardless of where you are located, you have the following rights with respect to your personal information:
- Access: you can view and download all data in your pod at any time via the standard Solid HTTP API.
- Correction: you can update your account email and name from your pod settings page.
- Deletion: you can delete your account and all associated data from your pod settings page. Deletion is permanent within 30 days as described above.
- Data portability: your pod data is stored in open, interoperable formats (Turtle/RDF and binary). You can export it at any time without our involvement.
- Objection / restriction: you can revoke any connected app’s access to your pod at any time from your account page. This immediately terminates that app’s authorisation.
- Withdraw consent: where we rely on consent as a legal basis, you can withdraw it at any time by contacting us.
If you are located in the European Economic Area (EEA), the United Kingdom, or another jurisdiction with a comprehensive privacy law, you may have additional rights (e.g. under the GDPR). To exercise any right, email support@privatedatapod.com. We will respond within 30 days.
10. Children’s Privacy
The Service is not directed at children under 13 years of age. We do not knowingly collect personal information from anyone under 13. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email and by posting a notice on the site at least 14 days before the changes take effect. The “Last updated” date at the top of this page always reflects the most recent revision.
Continued use of the Service after changes take effect constitutes acceptance of the updated Policy. If you disagree with a change, you may close your account and export your data before the effective date.
12. Contact
Questions, data requests, or concerns about this Privacy Policy? Contact us:
- Email: support@privatedatapod.com
- Company: Pod42 LLC
- Governing law: State of Michigan, United States
We aim to respond to all privacy-related inquiries within 5 business days.