Legal

Privacy

Short, because there is genuinely little to say about the website. Longer about the product, because it runs on your servers and you should know exactly what that means.

Last updated August 2026

Who is responsible

Noctrel is built and run by an individual developer, not a company. That person is the data controller for everything described here. There is no group of companies, no parent, and no affiliate to share anything with.

This site vs. the product

Two different things are covered below, and they are kept deliberately separate:

  • This website — the public pages you are reading, plus status.noctrel.dev. Neither has a form, a sign-in, or anything that collects data about you.
  • The Noctrel console — the application customers sign into to manage their servers. It is a separate application on a separate address, and it handles far more.

Creating an account happens on the console, not on this website — the buttons here just link there. Visiting this site or status.noctrel.dev never creates an account and never touches the console’s data.

What this website collects

Nothing. This site and status.noctrel.dev have no forms, no sign-in, and nothing that writes anything about you to a database — they are static pages plus links to the console for anyone who wants to create an account there.

We do not record your IP address, your browser, a device fingerprint, or the page that referred you.

There are no cookies and no analytics, advertising, or tracking scripts on either site. There is no consent banner because there is nothing to consent to.

This wasn’t always true: the site used to run a waitlist that collected an email address and an optional line of text. That form is gone now that signup is self-serve — see “How long it is kept” below for what happens to the handful of addresses collected while it existed.

What the console collects

If you are given an account, the product stores what it needs to do its job:

  • Account — email, password hash, optionally a name, date of birth and avatar, and your organisation membership.
  • Sign-in history— the IP address and browser user-agent of each login, so you can spot a session you don’t recognise. This is the one place we deliberately do keep an IP address.
  • Your servers — the names, hostnames and health metrics you connect, the capability catalogue you write, and every command proposed or run along with its output.
  • Conversations — what you type to the AI and what it replies.
  • Audit log — an append-only record of every action taken, by a person or by the AI.
  • Terminal sessions — what the shell printed. Keystrokes are deliberately not recorded, because they would capture whatever was typed at a password prompt.

Your AI provider API key is encrypted before it is written to the database and is never sent to an agent on your servers. It is only ever decrypted server-side to call the provider you chose.

Command output and what ends up in it

When a command runs on your server, its output is stored so you and the AI can read the result. Output is passed through a redaction step before it is saved, which strips values that look like secrets — but no redaction is perfect. Treat the command catalogue you write as the real control: it decides what can run at all, and therefore what output can ever exist.

Why we keep it

Console data exists to make the product work: to show you your servers, to let the AI reason about them, and to keep an audit trail you can rely on afterwards.

The handful of remaining legacy waitlist addresses are kept only because deleting them requires an explicit request (see “Your rights” below) — nothing is sent to them; there is no newsletter, no drip sequence, and no active waitlist to be emailed from anymore.

Who else sees it

Nothing is sold, rented, or shared with advertisers or data brokers. A handful of processors run the infrastructure on our behalf:

  • Amazon Web Services (AWS) hosts the database (RDS for PostgreSQL).
  • Vercel runs the console application itself — every request to the product passes through it.
  • Resend sends transactional email (password resets, sign-in codes, security alerts) on our behalf, using Amazon SES as its own delivery infrastructure. It receives the address and the message, nothing more.
  • Whichever AI provider is handling your conversations receives them, and the server context needed to answer — that is what calling a model means. By default that is Groq, via a key Noctrel provides; if you add your own provider key (Anthropic, OpenAI, Google, or your own Groq key) under Settings, that provider takes over instead.

Where it is stored

The database runs on AWS in Virginia, United States (region us-east-1). Noctrel is operated from Türkiye, so this is a transfer of personal data outside Türkiye, and outside the EEA.

Saying so plainly matters more than it might look: under KVKK a cross-border transfer is something you are entitled to know about before you hand over an address, and the United States is not on Türkiye’s list of countries with an adequate level of protection — this transfer relies on the data subject’s own explicit consent (given by creating an account), the KVKK mechanism available to a controller of this size. If you would rather your data not leave Türkiye, do not create an account — that is the only honest advice, because there is currently no Turkish-region option.

How long it is kept

The site no longer collects waitlist signups — creating an account is self-serve now. A small number of addresses collected before that changed are kept until you ask for removal, then deleted rather than archived.

Console data is kept while your account exists. Requesting deletion (Settings › Security) does not remove anything immediately — it starts a 90-day grace period, during which your account keeps working normally and you can cancel the request at any time. After 90 days it is permanently removed: your servers, capabilities, conversations and credentials. Audit entries are the deliberate exception: they survive the deletion of the thing they refer to, because an audit trail with holes in it is not an audit trail.

Your rights

Under the GDPR, and in Türkiye under KVKK, you can ask for a copy of what is held about you, ask for it to be corrected, or ask for it to be deleted. Two of those are already self-serve in the console:

  • Export — Settings › Security › Export data gives you a machine-readable JSON file of your account, servers, conversations, audit log and sign-in history.
  • Delete— Settings › Security › Delete account, which is password-confirmed and starts a 90-day cancelable grace period rather than deleting immediately (see “How long it is kept” above).

For a legacy waitlist address there is no self-serve control — it is a single row, so just email and it will be removed immediately, without needing a reason.

US state privacy rights

Noctrel does not sell personal information, and does not share it for cross-context behavioural advertising — there is no ad-tech and no data-broker relationship, so there is nothing here to opt out of on that front.

If you are a resident of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, or another state with a comprehensive privacy law now in effect, you have the same core rights described above under “Your rights” — access, correction, and deletion — reachable the same way, by email or through the console’s own export/delete tools.

Security

Passwords are hashed, provider keys are encrypted at rest, API tokens are scoped and can be given an expiry, and two-factor authentication is available. No system is perfectly secure, and nothing here should be read as a guarantee — but if something is found, it gets fixed and disclosed rather than quietly patched.

Changes

If this notice changes in a way that materially affects you, the date at the top changes and anyone with an account is emailed. Silent edits to widen what we collect are not something we do.

Contact. Data requests — access, correction, deletion — go to contact@getdast.tech.

Noctrel is operated by an individual rather than a registered company, so there is no company number or registered office to list. If a supervisory authority needs the controller’s identity, it is provided on request.