Privacy policy
v8 · 2026-09-03
This policy covers the expanse.sh website and the Expanse product (the Console, daemon, CLI, and the services behind them). It sets out what we collect, how we use it, who processes it, and your rights.
Summary
- We do not sell, rent, or share your personal data, and we use no advertising trackers or marketing pixels.
- Website analytics is self-hosted and cookieless.
- In the product, your code and telemetry remain yours; our account systems never receive your workload content, and a self-hosted deployment keeps it inside your network.
- Contact privacy@expanse.sh to access or delete the data we hold about you.
Part 1 · When you visit our website
What we collect
Two ways: what you type into the contact form, and what your browser sends automatically when you visit.
From the contact form (the only place we ask for personal details)
- Your first and last name, and your email address.
- The message you write us.
- Your IP address and browser user-agent. Stored only for spam filtering. We don't put them in the notification we send ourselves, and we never share them.
- The referring URL (origin and path only; query strings and fragments stripped before we save) and any UTM parameters on the link you followed.
Automatically, on every page
- Analytics. We run our own copy of Plausible. It records which page you viewed, the site you arrived from, and your country and browser type. It sets no cookies, uses no cross-site identifier, and does not store your IP address.
- Our fonts and icons are served from our own site, so loading a page fetches nothing from a third party. The one exception is the blog: pages there load commenter avatars from GitHub (where our community discussions live), and a post that embeds a video loads it from YouTube in privacy mode (youtube-nocookie.com). GitHub and YouTube receive your IP address and browser as a normal part of serving the image or video.
What we do with it
We use contact-form submissions to respond to your enquiry and follow up where relevant. Analytics is read only in aggregate, to understand which pages are useful; we do not use it to profile individuals.
Cookies and browser storage
- No tracking cookies. None, anywhere on the site.
- While you fill in the contact form, what you type stays in the page itself. Nothing is written to sessionStorage or any other browser storage, so it is gone if you refresh or close the tab.
- The Console uses a strictly necessary, secure session cookie to keep you signed in.
- Our website analytics is cookieless, so there is no analytics cookie to consent to.
Who handles website data
- A cloud hosting provider stores the data behind the website.
- An email provider sends the contact notification to our founders.
- Slack receives the same notification so a founder can reply quickly.
- GitHub hosts our community discussions and the blog comment threads, and serves commenter avatars. Visiting a blog page loads those avatars from GitHub, so it sees your IP address and browser.
Our analytics is self-hosted; our community discussions are on GitHub. We do not sell or rent your data or hand it to advertisers or data brokers. We may disclose information where the law requires it.
Part 2 · When you use the Expanse product
When you use the product we handle two kinds of data: the account details that identify you and your organisation, described below; and the workload content Expanse captures from your compute, which we handle under your agreement with us.
Account and identity
You sign in through your organisation's identity provider, which we configure with you. We do not run a password login or store login credentials. From that sign-in we hold:
- Your name and work email, as your identity provider asserts them.
- Your organisation and your role in it.
- API keys and browser sessions, stored only in hashed form.
The systems that manage your account do not receive your workload content: no source, telemetry, logs, or model prompts. They record that a compute and an execution exist, not what ran inside them.
Your workload content
The daemon observes your workloads read-only and captures evidence about how they run: a bounded source bundle, scheduler metadata, runtime metrics, and outcome (the documentation covers what is and isn't captured). We handle this content to provide the Service and generate your answers, under your customer agreement (and our Data Processing Addendum where one applies), not this policy.
On the hosted service, this content is stored encrypted at rest and scoped to your organisation. If you self-host, it stays in your own infrastructure and the only routine call back to us is a licence check and some operational metadata, not your workload content. Evidence from the hosted service may be used to improve our models under your agreement; self-hosted evidence never reaches us and is never used for that. Where a feature needs to generate a written answer, it sends the relevant context to a model provider (such as OpenAI or Anthropic), or to your own endpoint if you self-host.
Billing
Paid plans are billed per cluster through Stripe. Stripe receives your name, work email, organisation, and payment details, and handles your card data under its own PCI compliance. We store the Stripe customer and subscription identifiers and your plan status, never your card number. Billing applies to the hosted service only.
Sub-processors
- A cloud hosting provider stores our services and, on the hosted service, your workload content.
- OpenAI or Anthropic is our model provider, unless you self-host and point to your own endpoint.
- Stripe processes payments for paid plans.
If you self-host, your workload content does not reach our environment or any third party we choose, beyond a model provider you configure yourself. Processors that handle workload content under a Data Processing Addendum are set out in that addendum.
The rest (applies to both)
How long we keep it
Website form data: until you ask us to delete it, or until we decide we don't need it (for example, we haven't heard from you in years). Product account data: for as long as your organisation has an account. Workload metrics carry a rolling retention window, configurable per deployment; evidence and source bundles are kept per your retention settings. Email privacy@expanse.sh and we'll delete what we hold tied to you.
How it's protected
Everything travels over TLS. On the hosted service, databases sit in a private network, not reachable from the public internet, object storage is encrypted at rest, and access is limited to the team and scoped to your organisation. Expanse is SOC 2 Type II compliant.
Your rights
Wherever you are, you can email privacy@expanse.sh to ask what we hold on you, correct it, or delete it. If you're in the UK or EU, your UK GDPR and GDPR rights apply: access, correction, deletion, objection, and the right to complain to your data protection authority. If you're a California resident, your CCPA rights apply: to know what we hold, to delete it, and to opt out of the sale of personal information, which we do not do.
Changes to this policy
If we change this policy, we'll update the date at the top and post the new version here. If a change materially affects you, we'll let you know.
Who we are
Expanse Compute Inc., a Delaware corporation, operating in the UK through an England & Wales subsidiary. For privacy questions or deletion requests, privacy@expanse.sh. Our Terms of Service cover use of the product.