InfraNestInfraNest

Privacy Policy

How InfraNest collects, uses and protects your data — in plain language.

Privacy Policy

How InfraNest collects, uses and protects your data — in plain language.

Last updated: 21 July 2026.

The short version: InfraNest brings your domains, DNS, servers, certificates and monitoring into one place. To do that we handle some personal data — your account details, what you connect, and how you use the service. We don't sell it, we don't run advertising trackers, and we use a small set of trusted providers to run everything. The details are below, in plain language.

Who we are

InfraNest is run by Jaspar Steenman, Hansaring 79, 50670 Köln, Germany. We are the "data controller" for the personal data described here — meaning we decide how and why it's used. Any privacy question, or to exercise your rights: [email protected].

What this policy covers

This applies to the InfraNest marketing site (infranest.app) and the InfraNest app and API (dashboard.infranest.app). When you connect a third-party provider (a registrar, DNS host or cloud), that provider has its own privacy policy for the data it holds.

What we collect, and why

When you visit the site

  • Analytics — we run Umami, self-hosted on our own servers and cookieless. It gives us aggregate numbers only — page views and a rough country — with no personal profiles, no cross-site tracking, and no session recording.
  • The contact form — your name, email and message, so we can reply.
  • Support chat — if you message us, the conversation (handled by our self-hosted Chatwoot).

When you have an account

  • Account details — your name, email, password (stored only as a secure hash) and organization.
  • Signing in with Google or GitHub — if you choose this, that provider confirms your identity and shares your basic profile (name, email, avatar) under its own privacy policy. We use it only to create and access your account; you can use email + password instead.
  • Avatars — if avatar images are enabled, we show a Gravatar based on a hash of your email. We fetch it server-side, so Gravatar sees only the hash, never your browser or IP. You can turn this off.
  • Billing — handled by Stripe. We never see or store your full card number.
  • What you manage — the domains, DNS records, servers, certificates, monitors and watchlists in your account, plus the provider credentials and API tokens you connect. These are encrypted at rest, access is strictly limited to the parts of our system that need them to carry out what you ask for — including any automations you set to run on a schedule — and we don't use them for anything else. You can revoke them at any time.
  • Technical data — IP address, browser/device information and server logs, which we need for security and reliability. We work out an approximate country from your IP — locally, on our own servers — to flag unusual sign-ins.
  • Error diagnostics — via Sentry, so we can find and fix bugs. We send only a pseudonymous account id, never your email or other personal details.

Monitoring — when you set up a monitor, our probe servers contact the target you chose to check whether it's up. To verify DNS changes and certificates, we also query public DNS-over-HTTPS resolvers and certificate-transparency logs using your domain names.

Status-page subscribers

When someone subscribes to one of our customers' public status pages to receive incident and maintenance alerts, we (InfraNest) are the controller for that address. We collect it only with their confirmation (double opt-in), use it solely to send those alerts, and let them unsubscribe at any time — which deletes it. Sign-ups that are never confirmed are deleted after 7 days. Our customers see only aggregate counts, never individual addresses.

Our legal bases (GDPR Article 6)

  • Performing our contract with you — to provide your account, run the service and handle billing.
  • Our legitimate interests — keeping the service secure, preventing fraud, understanding usage in aggregate, monitoring errors, improving InfraNest, and answering your messages.
  • Legal obligations — for example, keeping invoices for tax purposes.
  • Your consent — only where we specifically ask for it (such as optional emails, or a status-page subscription). You can withdraw it at any time.

Cookies and local storage

We keep this simple, and we don't use any advertising or cross-site tracking cookies. The few cookies in play are strictly necessary:

  • Stripe sets a cookie during checkout, for payment security and fraud prevention.
  • Cloudflare, which delivers and protects our sites, sets a cookie for spam and bot protection.
  • Beyond that, we use your browser's local storage (not cookies) to remember your language and light/dark theme on the site, and to keep you signed in to the app.
  • Umami analytics is cookieless.

If we ever introduce tracking or marketing cookies, we'll ask for your consent first.

Who else processes your data (sub-processors)

We use a small set of trusted providers to run InfraNest:

  • Hetzner (Germany, EU) — hosting for the app, back-office systems, database and marketing infrastructure.
  • Cloudflare (EU / global) — hosting and CDN/security for the marketing site, and bot protection (Turnstile).
  • Umami — self-hosted on our own Hetzner infrastructure, so analytics data stays with us.
  • OVH — servers that run our monitoring probes in regions worldwide. You choose which regions check your services, so monitoring data is only processed outside the EU if you enable a non-EU region.
  • Sentry — error tracking and diagnostics.
  • Stripe — payment processing.
  • Amazon SES — sending transactional email (alerts, receipts and account messages).
  • Gravatar / Automattic (US) — avatar images, fetched by a hash of your email, when avatars are enabled.

International transfers

Most of our providers are based in the EU/EEA (Hetzner, Cloudflare's EU infrastructure). Some — Stripe, Sentry, Amazon SES and Gravatar — may process data outside the EU, including in the United States. And because our monitoring probes (OVH) run in regions worldwide, if you choose to monitor your services from a region outside the EU, those checks are processed there too. Where they do, the transfer is protected by appropriate safeguards such as the EU Standard Contractual Clauses.

How long we keep your data

We keep personal data only as long as we need it. Account data is kept while your account is active; when you close it, we delete or anonymise your data — except where the law requires us to keep certain records longer (for instance, invoices must be kept for up to 10 years under German tax law). Aggregate analytics and technical logs are kept for a short period, and support messages for as long as needed to help you.

Your rights

Under the GDPR you can ask us to access your data, correct it, delete it, restrict or object to how we use it, or provide it in a portable format — and you can withdraw consent at any time. Email [email protected] and we'll respond within the timeframe the law sets. You also have the right to complain to a data-protection authority; ours is the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (LDI NRW).

How we protect your data

Everything travels over encrypted connections (HTTPS/TLS). Provider credentials and other secrets are stored encrypted, access is limited to what's needed, and two-factor authentication is available on your account.

Children

InfraNest isn't intended for anyone under 16, and we don't knowingly collect their personal data.

Changes to this policy

We'll update this page whenever our practices change and revise the date at the top. For significant changes, we'll let account holders know.

Contact

Jaspar Steenman · Hansaring 79, 50670 Köln, Germany · [email protected]