HolyCode Cloud — Privacy & Data Handling Note
Last updated: July 10, 2026. HolyCode Cloud is operated by TigerPoint Technologies LLC ("we," "us"), a New York limited liability company based in Brooklyn, NY, United States. Contact: support@holycode.cloud · https://holycode.cloud. This note explains, in plain language, how we handle your data.
This note covers the paid HolyCode Cloud product only. Our marketing site and waitlist are handled separately.
The short version
HolyCode Cloud gives you a persistent, always-available Linux coding workstation in the cloud (it suspends when idle to save resources and wakes from idle in about 1 second). To run it, we hold three things: your account email, your billing details through Stripe, and the data inside your workspace (the code and files you put there). We do not upload or centrally store your AI API keys, and we do not sell your personal information.
Beta is US-only. During the paid beta, HolyCode Cloud is offered to customers in the United States only. Stripe Checkout is country-restricted to the US, so we handle the personal data of US-based customers.
What we collect and why
| Data | Why we have it |
|---|---|
| Account email | To create your account, deliver your workspace, and contact you about your service, billing, or support. |
| Billing information | To take payment. Card details are handled by Stripe, our payment processor — we do not see or store your full card number. We keep the record of your plan, subscription status, and Stripe customer/subscription IDs. |
| Workspace data (your code, files, and anything you save on the workstation) | This is the core of the service. Your workspace runs on a persistent disk so your work survives restarts and idle suspends. We store it because that is what running your workstation requires. |
| Workspace access credentials | We generate a username/password to protect your workstation's web login. We store these securely (in a private secrets store), never in a shared or public file. |
| Basic operational logs | Standard system and platform logs (e.g., machine start/stop, errors) used to keep the service running and troubleshoot problems. We do not use these to inspect the contents of your code. |
For California residents: this section serves as our notice at collection. We collect the categories above for the purposes described and retain them as explained under "How long we keep it."
What we do not do
- We do not upload or centrally store your AI keys. HolyCode Cloud is Bring-Your-Own-Key (BYOK). When you add your Anthropic, OpenAI, or Google API key or subscription, it lives on your own workspace disk. We do not upload or centrally store your keys, and we do not access them in the normal course of operating the service. Because we never hold your key, your AI usage is billed to you directly by your AI provider — we never resell AI tokens or see your AI bills.
- We do not sell your personal information, and we do not use your code or files to train AI models.
- We do not share your data except with the service providers listed below (who process it on our behalf) or where we are legally required to.
Who processes data for us (subprocessors)
We use a small number of trusted providers to run the service:
| Provider | What they handle |
|---|---|
| Fly.io | Hosts your workstation and stores your workspace data on their infrastructure. |
| Stripe | Processes payments and stores billing/card details. |
| Resend | Sends account and support emails. |
Each provider processes data on our behalf under its own terms and data processing agreement, and we rely on their security and privacy practices for the parts of the service they run. This list may change as the product grows; we will keep it current.
Where your data is stored
Your workspace runs in a United States Fly.io region, selected when your workstation is provisioned. Backups and operational data are held on Fly.io and, for billing, on Stripe. Because the beta is US-only, we do not currently host customer workspaces outside the United States.
Who can access your workspace
HolyCode Cloud is currently provisioned and supported by hand by a solo founder. To set up, support, or troubleshoot your workstation, we may have administrative access to it. We do not routinely look at the contents of your code or files, and we access a workspace only when needed to provide the service, respond to a support request you make, or comply with the law.
How long we keep it
- While you're a customer: we keep your account email, billing record, and workspace data for as long as your subscription is active.
- Backups: backups are best-effort and retained according to your plan's window — from 7 days (Lite) up to 90 days (Max). Older backups roll off automatically. We do not guarantee that any particular backup will be available or recoverable, so please keep your own copies of anything critical.
- When you cancel: you get a 7-day window to export your workspace data. After that window, we initiate deletion of your workstation and its data and force-purge its backups early (overriding the normal retention window above). Residual copies in our providers' systems (for example, provider-level snapshots and logs) are purged on their normal rolling cycle, up to 30 days. We cannot promise instant, irreversible deletion of every copy the moment you cancel.
- Billing records (the exception): separately from your workspace data, we and Stripe may retain payment and transaction records — plan, amounts, dates, Stripe IDs — after your workspace is deleted, where we need them for tax, accounting, or legal reasons. These records do not contain your code or files.
Your choices and rights
You can:
- Access / get a copy of your account information.
- Export your workspace data at any time while active, and during the 7-day window after cancellation.
- Delete your data — cancel your subscription to trigger the export-then-deletion process above, or email us to request deletion.
If you are a California resident, you can also ask us to disclose or delete the personal information we hold about you, and you will not be discriminated against for exercising these rights. As noted above, we do not sell your personal information.
Because your BYOK AI keys live on your own workspace (not with us), you control them directly — add, rotate, or remove them on your workstation at any time.
To make a request, email support@holycode.cloud. We may need to verify your identity (for example, confirm you control the account email) before acting.
Security
We take reasonable steps to protect your data, including securing workspace credentials and relying on our providers' platform security. No online service can be guaranteed 100% secure. HolyCode Cloud is an early-access product; please keep your own backups of anything critical.
Data-breach notification. If we learn that your personal data has been materially compromised, we will notify affected customers without undue delay and describe what happened and what you can do about it.
Not for children
HolyCode Cloud is intended for adults. You must be at least 18 years old to use it. It is not directed at anyone under 18, and we do not knowingly collect data from anyone under 18. If we learn we have collected data from someone under 18, we will delete it.
Changes to this note
We may update this note as the product changes. If we make a significant change, we will let account holders know by email or on https://holycode.cloud.
Contact
Questions or requests: support@holycode.cloud · TigerPoint Technologies LLC, Brooklyn, NY, United States · New York
Governing law: New York.