Privacy Policy
Last updated 14 August 2026
Who runs this service
unlayered.cloud is run by unlayered, an independent company that owns the brand, provides the service and holds your contract.
Who is responsible for your data
unlayered provides the service and is the controller of everything described below. It is an independent company: it runs unlayered.cloud, owns the unlayered brand, and your contract for the service is with it.
unlayered
contact@unlayered.cloud
What we collect, and why
Only what the panel needs in order to work. There is no tracking pixel, no advertising network and no data broker anywhere in it.
- Account. Your username, the hash of your account token, an optional email address with the date it was verified, the date you registered and the time you last signed in. This is what identifies the account and lets you back into it.
- Credits and payments. Your credit balance and a ledger of every movement on it, covering top-ups, purchases, renewals, corrections and who made them, plus the payment records our payment provider returns for each top-up: order reference, amount, currency, status and time. Needed to bill you correctly and to answer questions about a charge.
- Servers. For virtual servers: hostname, IP address, plan, operating system template and expiry date. For dedicated orders: plan, location, price and setup fee, the address of the machine, and the credentials you need to use it, which are the out-of-band management URL and login, plus the initial root password. Needed to run, renew and hand over the server.
- Support. Your tickets and the messages in them, on both sides, plus internal notes staff add to your account so that whoever picks up the next ticket knows the history.
- Sign-in and security events. Each sign-in, sign-in attempt, token replacement and email verification, with the event type, a short detail, the IP address it came from and the time. Needed to spot account takeover and abuse.
- Sessions. A hash of your session cookie with the IP address and browser user agent it was created from, and when it was created, last used and expires. This is what keeps you signed in and lets you see and revoke your own sessions.
- Sign-in links. When you use email sign-in, a hash of the one-time link, the address it went to, its purpose and whether it has been used.
- Notifications. In-panel notifications and, where you asked to be told when a sold-out plan comes back, the plan you are watching.
Legal bases
- Performance of a contract. Running your account, provisioning and renewing servers, taking credits, answering tickets. Without this data there is no service to provide.
- Legitimate interest. Preventing fraud, payment abuse and account takeover, and keeping the platform and other customers safe. This covers the sign-in event log, session metadata and abuse investigations.
- Legal obligation. Keeping payment and credit ledger records for the periods that accounting and tax law require, and responding to lawful requests from authorities.
Who it is shared with
Nothing is sold, rented or shared for advertising. Data goes to a third party only where the service cannot work otherwise:
- Our payment provider, which creates and settles the cryptocurrency invoice for a top-up. It receives the invoice amount and reference, and we receive its confirmation.
- Our email provider, where email is configured. It only ever carries sign-in and verification links, to the address you gave us. No marketing mail is sent.
- The infrastructure provider whose facilities host the servers and the network they run on.
- The platform that hosts this panel, which processes requests to it in order to serve them.
Beyond that, we disclose data only where we are legally required to, and only what is asked for.
How long it is kept
- Account data, which covers username, email, credits, servers and tickets, is kept for as long as the account exists. Closing the account removes it, apart from what we have to keep below.
- Payment records and the credit ledger are kept as accounting records for the retention period the applicable tax and commercial law sets, even after an account is closed.
- Sign-in and security events are deleted automatically after 90 days.
- Sessions expire 30 days after their last use and are deleted when they expire or when you sign out. One-time sign-in links are deleted a day after they expire.
- A suspended server and the data on it are deleted when it is reclaimed, five days after suspension.
Security
There are no passwords in this system at all, so there are none to leak. Your account token secret and your session identifier are stored only as SHA-256 hashes, so a copy of the database cannot be replayed as a login. The session cookie is HttpOnly, so page scripts cannot read it, and it is sent over HTTPS only.
The credentials we hand over for a dedicated server are stored so that you can retrieve them in the panel. Change them once you have taken the machine over, because that is the one secret in the system we cannot hash.
Cookies
One cookie: the session cookie that keeps you signed in. It is strictly necessary, HttpOnly, and lasts as long as the session. There are no analytics cookies, no advertising cookies and no third-party cookies, which is why the panel asks you for no cookie consent.
Nothing on any page reports your visit anywhere. There is no analytics product on this site, not even a cookieless one.
Your rights
You can ask us to give you a copy of your data, correct it, export it in a portable form, or delete it and close the account. You can also object to processing we base on a legitimate interest, and ask us to restrict processing while a dispute is being sorted out.
Use any of the channels in the Contact section at the end of this page. If you write by email, use the address on the account. We answer within one month. Requests made from an account are honoured for that account only, so we may ask you to sign in rather than prove your identity another way.
If you think we have handled your data badly, you can complain to the data protection supervisory authority of your own country of residence. We would rather you told us first, but you do not have to.
International transfers
The location of each server is shown on its plan before you order it. Our payment, email and platform providers may process data outside the country you are in, in which case the transfer relies on the safeguards set out in that provider's data processing terms, which are standard contractual clauses or an equivalent mechanism. We do not transfer your data anywhere else.
Contact
These are the ways to reach unlayered.
- Telegram
- @unlyrd
- Support tickets
- Open a ticket in the panelNeeds a signed-in account.