Legal

Privacy Policy

What Doffly collects, why, and how we protect it. Simple, no unnecessary jargon.

Last updated: September 30, 2026

Metrics first.CPU, memory, disk, network: the agent only sends what the dashboard needs.
No passwords.Sign in with Google: Doffly doesn't store your password.
No inbound ports.The agent talks to Doffly over outbound HTTPS only.
01

Who is responsible for your data

Doffly (“Doffly”, “we”) publishes the Linux monitoring service available at doffly.app. We are responsible for processing the data described on this page.

For any question: anelka.bag@gmail.com.

02

The data we collect

  • Account: name, email address and, depending on your Google account, profile picture. Doffly neither receives nor stores your password.
  • Servers: the name of your servers, their ID and the secret specific to each agent.
  • Metrics: CPU, memory, disk, network, uptime, basic system information and connection status.
  • Logs, alerts and notifications, for the plans that include these features.
  • Team and API: invited members, roles, API keys, webhooks and audit logs, for the relevant plans.
  • Technical data: IP address, browser type and access logs, used for security and diagnostics.

The agent only sends the categories listed above. We don't collect the content of your files or your application data.

03

How the agent communicates

The Doffly agent is a Rust binary installed as a service on your machine. It sends its metrics to Doffly over outbound HTTPS only: no inbound port is opened on your server.

Each server gets a secret scoped to its own machine. Remote endpoints require an authentication token and unprotected public HTTP is refused.

04

Why we use this data

  • To provide the service: show your servers, their metrics, their status and your alerts (performance of the contract).
  • To manage your account, your plan and support (performance of the contract).
  • To secure the service, prevent abuse and diagnose incidents (legitimate interest).
  • To comply with our legal obligations.

We don't sell your data and we don't use it for advertising.

05

How long we keep it

Metrics are kept according to your plan's history: 7 days (Free), 30 days (Pro), 90 days (Team) and 1 year (Business). After that, they are deleted.

Account data is kept as long as your account is active. When it is deleted, the data is erased or anonymized, unless the law requires us to keep it.

06

Who we share it with

We rely on service providers to run Doffly, only to the extent necessary:

  • Google, for signing in to your account.
  • Vercel and Render, for hosting the site and the API.
  • A payment provider, for paid plans. Doffly has no access to your full card number.

We may also disclose data if the law requires it. Some providers are located outside the European Union: transfers are then covered by appropriate safeguards, such as standard contractual clauses.

07

Your rights

You can request access, correction, deletion or portability of your data at any time, as well as restriction of or objection to its processing.

Write to us at anelka.bag@gmail.com. You can also contact the data protection authority in your country (in France, the CNIL).

08

Cookies

Doffly only uses the cookies required for the service to work, such as your sign-in session. We don't use advertising cookies.

09

Minors

Doffly is intended for professionals and developers. The service is not intended for people under 16.

10

Changes to this policy

We may update this page. If there is an important change, we will let you know by email or in the dashboard. The date of the last update is shown at the top of the page.

A question about your data?

Write to us and we'll get back to you.