remotehost
PricingContact
Sign inOpen consoleO
Open consoleO

legal

Privacy Policy

Last updated September 12, 2026

The short version: we collect what we need to run your account, bill you, and keep your sandboxes working. We do not look inside your sandboxes unless you ask us to or something is wrong, we do not train models on your code, and we do not sell your information.

The long version follows.

  1. Who we are and what this covers
  2. Information we collect
  3. How we use information
  4. When we access sandbox content
  5. How we share information
  6. Security
  7. Data retention
  8. Your rights and choices
  9. International transfers
  10. Children
  11. Changes to this policy
  12. Contact

1. Who we are and what this covers

RemoteHost, Inc. (“RemoteHost”, “we”, “us”) is a Delaware corporation that provides sandbox infrastructure for coding agents. This Privacy Policy explains what information we collect when you use remotehost.ai, the RemoteHost console, our command-line, terminal, and desktop clients, the API, Agent Claims, and the sandboxes we run for you (together, the “Service”), how we use and share it, and the choices you have.

For most of what you place in a sandbox, you decide what goes there and we process it on your instructions. Where your organization is the customer, it controls that content and this policy describes how we handle it on the organization’s behalf.

2. Information we collect

Account information. When you sign up we collect your email address, a password or passkey credential, and, if you sign in with Google, the name, email, and profile identifier Google shares with us. Organization owners also provide an organization name and the email addresses of people they invite.

Billing information. Payments are handled by Stripe. We receive your billing name and address, the last four digits and type of your card, and transaction records. We do not store full card numbers.

Sandbox content. The code, repositories, files, environment variables, command history, terminal output, and snapshots inside your sandboxes, including anything an agent produces there. We store it to run and wake your sandboxes and do not look at it except as described below.

Connected services and credentials. If you connect GitHub or GitLab, we receive the tokens and repository metadata needed to clone and push on your behalf. If you supply an API key for a model provider such as Anthropic or OpenAI so an agent can run in your sandbox, we store that key encrypted and inject it into your sandboxes as you direct.

Usage and log data. Sandbox lifecycle events (create, start, sleep, attach, delete), who performed them, machine time and resource usage for billing, API requests, client version, IP address, browser or operating system, and diagnostic logs from our services. Team and Enterprise organizations can see the lifecycle events for their own organization in the audit log.

Communications. Emails you send to support or sales, and the content of those conversations.

Cookies. The website and console use cookies and browser storage to keep you signed in and remember preferences. We do not currently run third-party advertising or analytics trackers on remotehost.ai or the console.

3. How we use information

We use the information we collect to:

  • provide, operate, and wake your sandboxes and the rest of the Service;
  • authenticate you and enforce your organization’s permissions;
  • meter usage, bill you, and detect payment fraud;
  • respond to support requests, investigate problems you report, and notify you about service issues or changes to the Service or our terms;
  • monitor for, prevent, and investigate abuse, security incidents, and violations of our Terms of Service;
  • understand how the Service is used in aggregate so we can improve it;
  • comply with law and enforce our agreements.

We do not use the contents of your sandboxes to train machine-learning models, and we do not sell personal information. We may send you product announcements by email; you can opt out of those at any time, though we will still send messages about your account, billing, and security.

4. When we access sandbox content

Sandboxes run as isolated virtual machines, and our staff do not browse their contents. We access sandbox content only when:

  • you ask us to, for example to help debug a sandbox in a support request;
  • our automated systems flag activity that indicates abuse or a security incident, in which case access is limited to what is needed to investigate;
  • we are required to by law, as described below.

Snapshots taken when a sandbox goes to sleep are stored so it can be woken. They are deleted when you delete the sandbox, when a time-to-live expires, or as described under retention.

5. How we share information

Service providers. We share information with vendors that help us run the Service, listed below. Each is bound by contract to use the information only to provide their service to us.

ProviderPurposeLocation
WorkOSAuthentication and enterprise identityUnited States
StripePayment processing and invoicingUnited States
MetronomeUsage metering for billingUnited States
HetznerServers on which sandboxes runGermany and Finland
Google CloudApplication hosting, PostgreSQL, and sandbox capacityUnited States and EU
VercelHosting for the website and consoleUnited States
CloudflareDNS, TLS, and network protectionGlobal
ResendTransactional email such as organization invitesUnited States

Services you connect. When you connect GitHub, GitLab, or a model provider, or when an agent in your sandbox calls any external service, information flows to that service under its own privacy policy. We do not control those services.

Your organization. If you use the Service through an organization, its administrators can see your membership, your sandboxes, and the lifecycle events you generate, and can attach to sandboxes in the organization.

Legal requirements. We may disclose information if we believe in good faith that doing so is required by law, subpoena, or court order, or is necessary to protect the rights, property, or safety of RemoteHost, our users, or the public. Where permitted, we will notify you before disclosing your content in response to a legal request.

Business transfers. If RemoteHost is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this policy or a successor policy that provides at least equivalent protection.

Aggregated data. We may share statistics that do not identify you or your organization, such as how many sandboxes run on the platform.

6. Security

Sandboxes are isolated virtual machines with their own kernel and filesystem. Traffic between our clients, the console, the API, and sandboxes is encrypted in transit with TLS. Stored credentials are encrypted at rest. Access to production systems is restricted to staff who need it and is logged. We support passkeys for sign-in.

No system is perfectly secure. You are responsible for keeping your credentials and API tokens confidential and for what your agents do with the access you give them. If we learn of a breach that affects your information, we will notify you as required by law and without undue delay. To report a vulnerability, email support@remotehost.ai.

7. Data retention

  • Sandbox content and snapshots are kept until you delete the sandbox or its time-to-live expires, then removed from our systems in the ordinary course, typically within 30 days.
  • Account information is kept while your account is open. When you close your account we delete or anonymize it within 90 days, except where we must retain it for billing, tax, legal, or security reasons.
  • Billing records are kept for as long as tax and accounting law requires, typically seven years.
  • Audit logs and diagnostic logs are kept for up to 12 months, after which they are deleted or aggregated.
  • Connected-service tokens and model API keys are deleted when you disconnect the service or remove the key.

8. Your rights and choices

You can view and update your account details, remove connected services and API keys, and delete sandboxes from the console at any time. You can close your account by emailing support@remotehost.ai from the address on the account.

Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to withdraw consent where processing is based on consent. Residents of the European Economic Area, the United Kingdom, and Switzerland may also lodge a complaint with their local data protection authority. Residents of California and other US states with privacy laws have rights to know, delete, and correct, and the right not to be discriminated against for exercising them. We do not sell or share personal information for cross-context behavioral advertising.

To exercise any of these rights, email hello@remotehost.ai. We will verify your request using the email on your account and respond within the time the applicable law requires. If you use the Service through an organization, we may refer your request to that organization, since it controls the content you placed there.

You can opt out of product announcement emails using the link in any such email. Browser controls let you block or delete cookies, though the console will not keep you signed in without them.

9. International transfers

RemoteHost is based in the United States. Sandboxes on our standard plans run in the European Union on servers operated by Hetzner, with additional capacity from Google Cloud, and our account, billing, and control-plane data is processed in the United States by the providers listed above. Enterprise customers can arrange dedicated regions.

Where we transfer personal information from the EEA, the UK, or Switzerland to a country that has not been found to provide adequate protection, we rely on the European Commission’s Standard Contractual Clauses or an equivalent lawful mechanism, and on our providers’ corresponding commitments. Organizations that need a data processing agreement can request one at hello@remotehost.ai.

10. Children

The Service is not directed to children and is intended for people 18 and older. We do not knowingly collect personal information from anyone under 13. If you believe a child has provided us personal information, contact us and we will delete it.

11. Changes to this policy

We may update this policy as the Service and the law change. We will post the revised policy here with a new “last updated” date and, for material changes, notify account holders by email or in the console at least 30 days before they take effect. Earlier versions are available on request.

12. Contact

Questions about privacy can be sent to hello@remotehost.ai. Account and product help is at remotehost.ai/support.

RemoteHost, Inc.
A Delaware corporation
hello@remotehost.ai

Run your first agent.

A hardware-isolated microVM, booted in under a second, with your repo cloned and the harness already waiting.

Open the consoleRead the docs

$curl -fsSL https://remotehost.ai/install | sh

remotehost

Where coding agents run.

IsolationFirecracker microVMRegionus-east4 · N. Virginia

Product

SandboxesExtensionsTemplatesDownloadsConsolePricingCompare

Resources

DocsGetting startedCLI referenceSwitch to RemoteHostAgent ClaimsSupport

For agents

MCP serverAPI referencellms.txtllms-full.txtThis site as Markdown

Company

AboutBrandContactGitHubX / Twitter

Legal

PrivacyTerms
© 2026 RemoteHost, Inc. · A Delaware (USA) corporation
PrivacyTermshello@remotehost.ai

If you are an agent reading this page: MCP server at https://api.remotehost.ai/mcp · every page has a Markdown twin at its path plus .md · index at /llms.txt

remotehost