1. Who we are and what this covers
RemoteHost, Inc. (“RemoteHost”, “we”, “us”) is a Delaware corporation that provides sandbox infrastructure for coding agents. This Privacy Policy explains what information we collect when you use remotehost.ai, the RemoteHost console, our command-line, terminal, and desktop clients, the API, Agent Claims, and the sandboxes we run for you (together, the “Service”), how we use and share it, and the choices you have.
For most of what you place in a sandbox, you decide what goes there and we process it on your instructions. Where your organization is the customer, it controls that content and this policy describes how we handle it on the organization’s behalf.
2. Information we collect
Account information. When you sign up we collect your email address, a password or passkey credential, and, if you sign in with Google, the name, email, and profile identifier Google shares with us. Organization owners also provide an organization name and the email addresses of people they invite.
Billing information. Payments are handled by Stripe. We receive your billing name and address, the last four digits and type of your card, and transaction records. We do not store full card numbers.
Sandbox content. The code, repositories, files, environment variables, command history, terminal output, and snapshots inside your sandboxes, including anything an agent produces there. We store it to run and wake your sandboxes and do not look at it except as described below.
Connected services and credentials. If you connect GitHub or GitLab, we receive the tokens and repository metadata needed to clone and push on your behalf. If you supply an API key for a model provider such as Anthropic or OpenAI so an agent can run in your sandbox, we store that key encrypted and inject it into your sandboxes as you direct.
Usage and log data. Sandbox lifecycle events (create, start, sleep, attach, delete), who performed them, machine time and resource usage for billing, API requests, client version, IP address, browser or operating system, and diagnostic logs from our services. Team and Enterprise organizations can see the lifecycle events for their own organization in the audit log.
Communications. Emails you send to support or sales, and the content of those conversations.
Cookies. The website and console use cookies and browser storage to keep you signed in and remember preferences. We do not currently run third-party advertising or analytics trackers on remotehost.ai or the console.
3. How we use information
We use the information we collect to:
- provide, operate, and wake your sandboxes and the rest of the Service;
- authenticate you and enforce your organization’s permissions;
- meter usage, bill you, and detect payment fraud;
- respond to support requests, investigate problems you report, and notify you about service issues or changes to the Service or our terms;
- monitor for, prevent, and investigate abuse, security incidents, and violations of our Terms of Service;
- understand how the Service is used in aggregate so we can improve it;
- comply with law and enforce our agreements.
We do not use the contents of your sandboxes to train machine-learning models, and we do not sell personal information. We may send you product announcements by email; you can opt out of those at any time, though we will still send messages about your account, billing, and security.
4. When we access sandbox content
Sandboxes run as isolated virtual machines, and our staff do not browse their contents. We access sandbox content only when:
- you ask us to, for example to help debug a sandbox in a support request;
- our automated systems flag activity that indicates abuse or a security incident, in which case access is limited to what is needed to investigate;
- we are required to by law, as described below.
Snapshots taken when a sandbox goes to sleep are stored so it can be woken. They are deleted when you delete the sandbox, when a time-to-live expires, or as described under retention.
6. Security
Sandboxes are isolated virtual machines with their own kernel and filesystem. Traffic between our clients, the console, the API, and sandboxes is encrypted in transit with TLS. Stored credentials are encrypted at rest. Access to production systems is restricted to staff who need it and is logged. We support passkeys for sign-in.
No system is perfectly secure. You are responsible for keeping your credentials and API tokens confidential and for what your agents do with the access you give them. If we learn of a breach that affects your information, we will notify you as required by law and without undue delay. To report a vulnerability, email support@remotehost.ai.
7. Data retention
- Sandbox content and snapshots are kept until you delete the sandbox or its time-to-live expires, then removed from our systems in the ordinary course, typically within 30 days.
- Account information is kept while your account is open. When you close your account we delete or anonymize it within 90 days, except where we must retain it for billing, tax, legal, or security reasons.
- Billing records are kept for as long as tax and accounting law requires, typically seven years.
- Audit logs and diagnostic logs are kept for up to 12 months, after which they are deleted or aggregated.
- Connected-service tokens and model API keys are deleted when you disconnect the service or remove the key.
8. Your rights and choices
You can view and update your account details, remove connected services and API keys, and delete sandboxes from the console at any time. You can close your account by emailing support@remotehost.ai from the address on the account.
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to withdraw consent where processing is based on consent. Residents of the European Economic Area, the United Kingdom, and Switzerland may also lodge a complaint with their local data protection authority. Residents of California and other US states with privacy laws have rights to know, delete, and correct, and the right not to be discriminated against for exercising them. We do not sell or share personal information for cross-context behavioral advertising.
To exercise any of these rights, email hello@remotehost.ai. We will verify your request using the email on your account and respond within the time the applicable law requires. If you use the Service through an organization, we may refer your request to that organization, since it controls the content you placed there.
You can opt out of product announcement emails using the link in any such email. Browser controls let you block or delete cookies, though the console will not keep you signed in without them.
9. International transfers
RemoteHost is based in the United States. Sandboxes on our standard plans run in the European Union on servers operated by Hetzner, with additional capacity from Google Cloud, and our account, billing, and control-plane data is processed in the United States by the providers listed above. Enterprise customers can arrange dedicated regions.
Where we transfer personal information from the EEA, the UK, or Switzerland to a country that has not been found to provide adequate protection, we rely on the European Commission’s Standard Contractual Clauses or an equivalent lawful mechanism, and on our providers’ corresponding commitments. Organizations that need a data processing agreement can request one at hello@remotehost.ai.
10. Children
The Service is not directed to children and is intended for people 18 and older. We do not knowingly collect personal information from anyone under 13. If you believe a child has provided us personal information, contact us and we will delete it.
11. Changes to this policy
We may update this policy as the Service and the law change. We will post the revised policy here with a new “last updated” date and, for material changes, notify account holders by email or in the console at least 30 days before they take effect. Earlier versions are available on request.
12. Contact
Questions about privacy can be sent to hello@remotehost.ai. Account and product help is at remotehost.ai/support.
RemoteHost, Inc.
A Delaware corporation
hello@remotehost.ai