Privacy policy

Last updated 2026-07-12.

This Privacy Policy explains how Docker HQ, operated under the Nepali Programmer trading name ("we", "us", "our"), collects, uses, discloses, and protects personal data when you use the Docker HQ mobile app, website, and related services (the "Service"). We act as the data controller for the personal data described below. It covers both the mobile app and the website; some sections apply only to one, and say so.

1. Data we collect

  • Account and profile data: your name, email address, and a hashed (non-reversible) password. If you sign in with Google, Apple, or GitHub, we receive your email address and name (and, where available, an avatar) from that provider to create and identify your account.
  • Billing references: subscription status and the Paddle customer, subscription, and transaction identifiers needed to manage your Pro plan. Payment card details are collected and stored by Paddle, not by us.
  • Host connection metadata (Pro sync): when you enable cloud sync, the name, address/hostname, and port of the servers you save are stored on our servers so they sync across your devices. The sensitive credentials for those hosts are encrypted on your device first (see section 3).
  • Push notification data: a device identifier we generate and a push (FCM) token, so we can deliver alerts and notifications you enable.
  • Usage and analytics data: the app and website use Google Firebase Analytics, which automatically collects events such as screen views, session starts, app version, device and OS model, and coarse location derived from IP address, tied to an app-instance identifier.
  • Crash and diagnostic data: the app uses Firebase Crashlytics, which collects crash reports and related device information to help us fix stability problems.
  • Advertising data (free tier only): the free tier shows ads through Google AdMob. AdMob may access device and advertising identifiers and serve personalized ads subject to your device settings. Pro subscribers see no ads.
  • Security and audit data: we log IP address, user agent, request identifiers, and the actions taken on your account for security, fraud prevention, and audit purposes.
  • Support data: the contents of emails and requests you send us.

2. What we do not have server-side

We store the name, address, and port of synced hosts, but not their credentials in readable form. We are not able to read the contents of the servers you connect to, or the commands and output of your SSH sessions — those flow directly between your device and your server.

Exception — server-side monitoring. If you turn on monitoring for a host, our service must connect to that host on a schedule on your behalf. The credential you provide for monitoring is therefore not part of your zero-knowledge Vault: it is encrypted with a key held in our cloud key-management service (AWS KMS) so that our monitoring worker can decrypt it at connection time, under strict, audited access controls. Only credentials for hosts you explicitly enable for monitoring are handled this way. Everything else stays in your Vault, which we cannot read. If you are not comfortable with this trade-off, do not enable monitoring for a host.

3. Your Vault (zero-knowledge)

SSH usernames, passwords, private keys, and key passphrases are stored on your device in an encrypted database, with the key held in your device's secure keychain. When cloud sync is enabled, these credentials are sealed inside your Vault: they are encrypted on your device using a key derived from your Vault passwordbefore being uploaded, so we hold only ciphertext we cannot decrypt (a "zero-knowledge" design).

Your Vault password is chosen by you and is separate from your login password. It, and the key derived from it, never leave your device and are never sent to our servers. We cannot recover your Vault password or the data it protects. At setup you are given a one-time recovery key — store it somewhere safe and offline, because it is the only way to regain access if you forget your Vault password. If you lose both your Vault password and your recovery key, the data in your Vault is permanently and irreversibly lost. This is a deliberate security property, not a defect.

4. How we use your data

  • Provide, maintain, and secure the Service.
  • Authenticate you and manage your account and subscription.
  • Deliver notifications and alerts you enable.
  • Show ads to free-tier users through AdMob.
  • Measure usage and diagnose crashes to improve the Service.
  • Send transactional email (verification, password resets, password changes, account deletion, and billing notices).
  • Detect and prevent fraud and abuse, and comply with legal obligations.

5. Legal bases (UK/EU)

Where the UK GDPR or EU GDPR applies, we process personal data on these bases: performance of our contract with you (providing the Service and billing); our legitimate interests (security, fraud prevention, and improving the Service); consent (where required for analytics and personalized advertising); and compliance with legal obligations.

6. Advertising and analytics choices

You can limit ad and analytics tracking through your device controls: on iOS via the system tracking and privacy settings, and on Android via the Google "Ads" settings, where you can reset or delete your advertising identifier and opt out of ad personalization. Upgrading to Pro removes ads entirely. You can manage Google's use of data for ads at adssettings.google.com.

7. Payment processing

Subscriptions are sold and processed by Paddle.com Market Ltd, which acts as the Merchant of Record and as an independent controller of the payment data it collects. Paddle's handling of that data is governed by its own privacy notice at paddle.com/legal/privacy.

8. Third parties we share data with

We do not sell your personal data. We share it only with service providers that help us operate the Service, each processing data on our instructions or as an independent controller under their own terms:

  • Google / Firebase — authentication (Google, Apple, and GitHub sign-in), push messaging, analytics, and crash reporting.
  • Google AdMob — advertising to free-tier users.
  • Apple and GitHub — social sign-in, if you use it.
  • Paddle — billing and subscription management.
  • Amazon Web Services — cloud hosting, media storage and CDN (for avatars), and key management for server-side monitoring credentials.
  • Our email provider — delivery of transactional email.

If you configure an optional alert webhook (for example to Slack), alert data is sent to the endpoint you choose; that endpoint is under your control, not ours. We may also disclose data where required by law or to protect our rights and users.

9. Email and marketing

We send transactional email necessary to operate your account. We do not send marketing email without your opt-in consent, and you can withdraw that consent at any time.

10. Cookies (website)

On the website we set a session cookie and a refresh cookie when you sign in; these are strictly necessary to keep you authenticated. The website also uses Google Analytics. We do not set advertising cookies on the website.

11. Data retention

We retain account data for as long as your account is active. When you delete your account we anonymize personal fields and keep a soft-delete record so that subscription and audit history stays consistent; after 30 days we purge the soft-delete record. Billing records may be retained longer where required by tax or accounting law. Analytics and crash data are retained per Google's default retention settings.

12. Security

We use industry-standard measures including encryption in transit, hashed passwords, and access controls. Two-factor authentication secrets are encrypted at rest. Synced SSH credentials are client-side encrypted (zero-knowledge). Where we run server-side monitoring for Pro, the credentials used are encrypted with AWS Key Management Service. No system is perfectly secure, but we work to protect your data and to notify you and the relevant authorities of any breach as required by law.

13. Your rights

Subject to applicable law, you may request access to, correction of, deletion of, or a copy of your personal data, and you may object to or restrict certain processing or withdraw consent. You can exercise most of these directly from the Account page or by emailing us. If you are in the UK or EU you also have the right to complain to your data protection authority.

14. International transfers

Your data may be processed in countries outside your own. Where it is, we rely on appropriate safeguards such as the UK/EU standard contractual clauses to protect it.

15. Children

The Service is not directed to children under 16 and we do not knowingly collect their personal data.

16. Changes to this policy

We may update this policy from time to time. We will update the "Last updated" date above and, for material changes, notify you by email or in the app.

17. Contact

Email support@dockerhq.app with any privacy request or question. See also our Terms of service and Refund policy.