Privacy Policy
The short version
Your information lives in two very different places. We hold your account and billing records on our control plane. Your code, files, terminal history, agent sessions, and any keys you paste live on your own server — we do not copy them, mine them, index them, or train on them.
We use a small number of service providers: Vultr for servers, Stripe for payments, Resend for email, Google for optional sign-in, Vercel for this website. We run first-party analytics on this website with no third-party trackers and no advertising cookies. We do not sell personal information.
1. Who we are
Black Sky Ventures LLC, a limited liability company organised in the United States, trading as TermRoam, is the controller of the personal information described in this policy. Contact us at privacy@termroam.com.
This policy covers the TermRoam website at termroam.com, the TermRoam customer portal, and the TermRoam software running on servers we provision for customers.
2. The split: our systems vs your server
This is the most important thing to understand about privacy at TermRoam, and it is the reason a generic policy would mislead you.
- Our control plane holds the small set of records needed to run an account: who you are, what you pay, and what servers exist. We look at these in the ordinary course of running the business.
- Your server holds your actual work. We do not routinely access it, we do not copy its contents into our systems, and we do not have a process that reads it. Section 11 explains the two ways a human at TermRoam can ever touch it.
3. What we hold on the control plane
| Category | What it is |
|---|---|
| Account | Email address, display name, organisation name and slug, role (owner, admin, member), account status. |
| Authentication | Single-use sign-in tokens (stored hashed), a signed session cookie, and — if you use Google sign-in — the email address and basic profile Google returns. |
| Billing | Stripe customer and subscription identifiers, plan, billing status, current period end, and invoice metadata. Card numbers go directly to Stripe. We never receive or store them. |
| Infrastructure | Server records: identifier, region, hardware spec, status, cloud provider instance ID, and the server's IP address. |
| Team | Invitations you send: email address invited, status, and who sent them. |
| Audit and security events | Account and billing lifecycle events, provisioning events, sign-in and support-access events. These may include the IP address the request came from. |
| Alpha and waitlist | If you asked for alpha access from this website: your email address, the plan you were interested in, and your survey answers. |
| Support | Emails you send us and any diagnostics bundle you choose to send. |
4. What stays on your server
The following live on the server we provision for you, under your control, and are not collected by us:
- Your code, files, repositories, and projects.
- Terminal sessions and scrollback history.
- AI agent sessions, prompts, and output.
- Any credentials, tokens, or API keys you place there — including the Anthropic or OpenAI keys you supply and the Claude account you connect.
We do not copy this material to our systems, mine it, index it for our own purposes, sell it, or use it to train any AI model.
5. Analytics on this website
termroam.com runs first-party analytics that we operate ourselves. There are no third-party analytics scripts, advertising pixels, or cross-site trackers on this site.
When you view a page or click a link, your browser sends a small event to our own servers containing:
- the page path and hostname, and the event type (page view, click, or page leave);
- the referring URL and any UTM campaign parameters in the address;
- for clicks, the label and destination of the link;
- time spent on the page, and your browser's viewport width;
- a random visitor identifier stored in your browser's local storage.
We do not store your IP address alongside these events. The random visitor identifier is generated in your browser, is not derived from anything about you, and is not linked to your account. Clearing site data for termroam.com resets it.
6. Cookies and local storage
- Portal session cookie — a signed cookie set after you sign in to the customer portal, so you stay signed in. Strictly necessary; there is no way to use the portal without it.
- Analytics visitor ID — a random string in your browser's local storage on termroam.com, described in section 5.
We do not set advertising cookies and we do not participate in any ad network.
7. Why we process this information
- To provide the service — creating your account, provisioning and managing your server, letting you sign in. (Performance of our contract with you.)
- To bill you — subscriptions, invoices, dunning, and tax records. (Contract and legal obligation.)
- To communicate — sign-in links, invitations, billing notices, security notices, and support replies. (Contract and legitimate interests.)
- To keep the service secure and to enforce our terms — audit and security events, abuse investigation. (Legitimate interests.)
- To understand how this website performs — the first-party analytics in section 5. (Legitimate interests in running a website we can improve.)
- To meet legal obligations — tax, accounting, and responding to lawful requests.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
8. Service providers we share with
| Provider | Purpose | What they get |
|---|---|---|
| Vultr | Hosting your server and our control plane | Server metadata and, by construction, the contents of the disk they host |
| Stripe | Payments and subscription billing | Name, email, billing address, and card details you enter with them directly |
| Resend | Transactional email delivery | Your email address and the message content |
| Optional sign-in | Only used if you choose Google sign-in; we receive your email and basic profile | |
| Vercel | Hosting this marketing website | Standard web request data for termroam.com |
We may also disclose information where we are legally required to, to enforce our terms, or in connection with a merger or sale of the business — in which case we will tell you before your information becomes subject to a different policy.
9. AI providers are yours, not ours
You connect your own Claude account and supply your own Anthropic and/or OpenAI API key. Those providers are engaged by you, under your own account. We are not a processor of that traffic and it does not flow through our systems.
What those providers do with your prompts, code, and output is governed by their privacy policies and data-retention settings, not by this one. If you care about model-training opt-outs, zero-retention modes, or enterprise data terms, configure them with the provider directly.
10. Where your data is located
Our control plane and all customer servers are hosted in the United States. Servers are provisioned on Vultr, with Newark, New Jersey as the default region. We do not currently offer a region choice at signup.
If you are outside the United States, using TermRoam means your information is transferred to and stored in the United States. If a specific data-residency requirement applies to you, contact us before subscribing.
11. Support access to your server
There are exactly two ways a person at TermRoam touches your server:
- A diagnostics bundle you send us — health, versions, and redacted logs, pulled at your request when you open a support ticket. This is the default and covers nearly all support.
- Time-boxed break-glass access you approve — hands-on access requires your explicit approval, expires automatically, and is recorded in an audit trail you can see.
We do not operate a standing support login into customer servers and we do not monitor their contents.
Disclosure about recovery keys. As the service is built today, an operator recovery key is installed on your server when it is provisioned, so that a broken server can be recovered. We do not use it for routine support, and any use is subject to the approval and audit process above. We are working to remove standing key material from customer servers; until then we would rather disclose it than imply it does not exist.
12. Security
We use TLS for all connections, store sign-in tokens hashed rather than in plain text, sign session cookies, keep card data entirely with Stripe, and record audit events for account, billing, and support-access actions.
No system is perfectly secure. If you discover a vulnerability, please report it to security@termroam.com — we will not pursue good-faith researchers who report responsibly and do not access other customers' data.
13. How long we keep things
| What | How long |
|---|---|
| Everything on your server | Until the server is destroyed — on cancellation, on reclaim after non-payment, or when you delete your account. Destruction is permanent. See the Billing, Refund & Cancellation Policy. |
| Account records | For the life of the account. On account deletion we anonymise the account and user records so they no longer identify you. |
| Billing and tax records | Retained after account closure for as long as tax, accounting, and dispute-resolution law requires — typically seven years. |
| Audit and security events | Retained as a record that actions occurred. On account deletion, the event payloads and source IP addresses are cleared, leaving the event type and timestamp. |
| Website analytics events | Retained in aggregate; they contain no account identifier and no IP address. |
| Support email | Retained while it is useful for supporting you and for a reasonable period afterwards. |
14. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a portable copy of your personal information, to object to or restrict certain processing, and to complain to a data protection authority.
To exercise any of these, email privacy@termroam.com from your account address. We will respond within 30 days.
Two practical notes:
- For everything on your server, you already have direct access — you can read, export, or delete it yourself at any time through the cockpit, without asking us.
- We cannot delete billing and tax records we are legally required to keep, and we retain the record that you accepted these documents for as long as a dispute over them remains possible.
We will not discriminate against you for exercising any of these rights.
15. Children
TermRoam is not intended for anyone under 18 and we do not knowingly collect personal information from children. If you believe a child has given us information, contact privacy@termroam.com and we will delete it.
16. Changes to this policy
We may update this policy. If a change is material, we will notify account holders by email and in the portal before it takes effect. The "last updated" date at the top always reflects the current version.
17. Contact
Black Sky Ventures LLC, trading as TermRoam.
- Privacy: privacy@termroam.com
- Security: security@termroam.com
- Support: support@termroam.com