Privacy Policy
Last updated: September 2, 2026
1. Introduction
Staticbot ("we", "us", or "our") is operated by BITFICTION, s.r.o., a company registered in the Slovak Republic. This Privacy Policy explains what we collect, why, who we share it with, how long we keep it, and how you can get it deleted, when you use staticbot.dev (the "Site") and the Staticbot service (the "Service").
BITFICTION, s.r.o. is the data controller for personal data described here. Where you use Staticbot to migrate or deploy your own application, we act as a processor for the content of that application on your instructions.
2. Information We Collect
- Account data. Your email address, username and authentication records, held in our self-hosted Keycloak identity server. If you sign in with a third-party provider, we receive your email address and basic profile from that provider.
- Connected-account credentials. Access tokens, refresh tokens and API keys for services you connect — such as GitHub, Supabase, Cloudflare and AWS. These are encrypted at rest and are used only to perform the actions you request.
- Application content you ask us to process. To run a migration, deployment or synchronization, we process your repository source code, database schema and data, storage objects, edge function code, and environment configuration. This may contain personal data belonging to your end users; you remain the controller of it.
- Operational records. Migration, deployment and synchronization job history, logs, error output and status, used to run and troubleshoot the Service.
- Billing data. If you purchase a paid plan or credits, our payment processor collects and holds your payment details. We receive the transaction record, not your full card details.
- Usage and technical data. IP address, browser type and version, pages visited, timestamps and similar diagnostics.
3. How We Use Your Information
- To provide, operate, secure and maintain the Service.
- To perform the migrations, deployments, DNS changes and synchronization runs you request.
- To diagnose failures, including AI-assisted troubleshooting (see section 4).
- To process payments and administer entitlements.
- To communicate with you about the Service, and — only where you have opted in — to send you product news.
- To detect and prevent fraud and abuse, and to comply with legal obligations.
Our legal bases are performance of a contract with you, our legitimate interest in operating and securing the Service, your consent where we ask for it, and compliance with legal obligations.
4. AI Processing
Staticbot uses large language models for two narrow purposes: troubleshooting failed migration or deployment jobs, and proposing schema or merge-conflict resolutions for your review. When one of these runs, the relevant excerpt — typically an error message, a SQL migration file, a schema description or a conflicted file — is sent to our AI provider's API.
We do not send your credentials, access tokens or API keys to the AI provider. AI-assisted troubleshooting is rate-limited and never applies a change on its own: proposed fixes are surfaced for your explicit approval. Our AI provider processes this data as our subprocessor under its API terms and does not use it to train its models.
5. Connected AI Assistants (MCP)
You may connect Staticbot to an AI assistant such as ChatGPT through our hosted MCP server. This uses OAuth: you sign in to Staticbot, see exactly which permissions are requested, and approve them. Two scopes exist — staticbot:read to view your repositories, migrations, projects and deployments, and staticbot:write to create and manage them. You may grant read access alone.
Once connected, the assistant provider receives the data its requests return, and its own privacy policy governs what it then does with it. We never send your stored third-party credentials to a connected assistant. You can revoke a connection at any time from the assistant, which immediately ends its access.
6. Data Sharing and Subprocessors
We do not sell your personal information. We share it only with the providers below, each acting on our behalf or at your direction:
| Provider | Purpose |
|---|---|
| Amazon Web Services | Hosting and static site delivery for deployments |
| Cloudflare | Application hosting, DNS and TLS certificates |
| DigitalOcean | Hosting of the Staticbot control plane and database |
| Supabase | Source and target databases you connect for migrations |
| GitHub | Repository access for analysis, deployment and synchronization |
| OpenAI | AI-assisted troubleshooting and schema suggestions (section 4) |
| Paddle | Payment processing and invoicing |
| ZeptoMail (Zoho) | Transactional email delivery |
| Slack | Internal operational alerting to our own team |
We may also disclose information where required by law or in response to valid requests by public authorities, and in connection with a merger, acquisition or sale of assets, in which case we will notify you before your data becomes subject to a different policy.
7. International Transfers
We are established in the European Union and prefer EU-hosted infrastructure. Some subprocessors listed above process data outside the European Economic Area, including in the United States. Where that happens, transfers are made under the European Commission's Standard Contractual Clauses or another lawful transfer mechanism offered by that provider.
8. Data Retention
- Account and organization records: kept while your account is active, and deleted after a verified erasure request.
- Connected-account credentials: kept until you disconnect the integration or delete your account, then deleted.
- Migration and deployment job records and logs: kept up to 24 months for support and troubleshooting.
- Downloadable migration packages: kept for a limited period after generation, then removed automatically.
- Billing and invoice records: retained for as long as Slovak accounting and tax law requires, which is longer than the periods above and applies even after account deletion.
9. Your Rights and How to Delete Your Data
If you are in the EEA or the UK you have the right to access, correct, erase, restrict or object to the processing of your personal data, and the right to data portability. You may also lodge a complaint with a supervisory authority — in Slovakia, the Office for Personal Data Protection of the Slovak Republic.
Requesting deletion
To have your account and associated personal data erased, email hello@staticbot.dev from the address registered on your account with the subject line "Data deletion request".
- We confirm receipt within 5 working days.
- We verify that the request comes from the account holder. If you write from a different address we will ask you to confirm from the registered one.
- We complete the deletion within 30 days and confirm in writing when it is done.
Deletion covers your account and login records, your organization, your stored third-party credentials, and your migration, deployment, synchronization and connected-project records. We retain only billing and invoice records, for the statutory period described in section 8.
Infrastructure in your own accounts is not deleted. Anything Staticbot deployed into cloud accounts you own — your AWS, Cloudflare or Supabase resources — belongs to you and stays under your control. Removing your Staticbot account does not tear it down. If you want those resources removed, delete them in the relevant provider, or ask us first and we will tell you exactly what was created.
You may exercise any other right listed above using the same address. We do not charge for these requests.
10. Data Security
Third-party credentials are encrypted at rest. Access to production systems is restricted and network-limited. We use administrative, technical and physical measures to protect your information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us with personal data, contact us and we will delete it.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page and revise the date above. Where changes are material, we will take reasonable steps to notify you.
13. Contact Us
Questions about this Privacy Policy, or any request concerning your data, can be sent to hello@staticbot.dev.
