Legal
Privacy Notice — decent-render.farm (DRAFT)
DRAFT — not yet reviewed by counsel. Controller will be [Decent Render Verein] once registered; until then Block Lab GmbH, CHE-480.725.572.
This notice describes how decent-render.farm handles personal data. It is written first for the Swiss Federal Act on Data Protection (revDSG); where the EU/EEA GDPR applies, the same rights and standards are applied by analogy.
1. Controller
[Decent Render Verein], [seat], Switzerland, from registration; until then Block Lab GmbH, CHE-480.725.572, [address]. Contact: [privacy@decent-render.farm].
2. What we collect
- Account data: email address, workspace name, session records, password hash if you set a password (magic-link email sign-in is the default).
- API usage logs: timestamps, API key identifiers, endpoints, outcomes — to secure the service and attribute credit spends.
- Operator device metadata: platform, chip, supervisor version, heartbeats, job counts for paired machines. No contents of operator machines.
- Render job metadata: bundle hash, composition parameters, status, credit price, errors — what the dashboard shows you.
We do not keep render content beyond a job’s lifetime, and we build no advertising or tracking profiles.
3. The purge rule
Tenant content (bundles, inputs, in-progress frames) is deleted from operator machines automatically when the job ends, completion or failure alike. Operators contractually never inspect, copy, or retain it.
The finished output is kept in our storage bucket for [7] days so you can download it, then deleted. Purge rule plus the 7-day output window are the only retention of render content.
4. Sub-processors
Running the service uses these processors, each bound to process only on our instructions under a data-processing agreement:
| Processor | Role |
|---|---|
| Cloudflare (Workers + R2) | Site hosting, API edge, output file storage |
| Fly.io | Dispatch service (queue and WebSocket job assignment) |
| Turso (libSQL) | Database hosting (accounts, ledger, job records) |
| Resend | Delivery of sign-in (magic-link) emails |
Operators are independent controllers of their own devices but handle tenant content for us under the Operator Agreement’s confidentiality and purge rules; they are not sub-processors in the render path.
5. Retention
- Account/workspace data: until deletion on request, plus short backups.
- Sessions: expired sessions removed automatically.
- API usage and job records: while the workspace exists, for billing and security; no render content.
- Render content: per section 3 — nothing beyond the job, output for [7] days.
6. Your rights
You have rights of access and deletion, correction, restriction, and objection — under the revDSG in Art. 25 ffl., under the GDPR in Art. 15 ffl. Write to [privacy@decent-render.farm]; we answer within 30 days. You may also complain to the Swiss Federal Data Protection and Information Commissioner (or your local EU authority, where applicable).
7. No sale, no tracking
We do not sell personal data and do not use it for advertising. The site runs no analytics cookies and no third-party trackers; the only cookie is the session cookie needed to keep you signed in.
8. Changes
Material changes are emailed to account holders at least 30 days in advance. The DRAFT banner above disappears once counsel has reviewed this text.