Privacy Policy

Last updated: July 28, 2026

This Privacy Policy explains what data NullBin Hosting (“NullBin”) collects, why we collect it, and the control you have over it. We aim to collect the minimum needed to run the service securely.

1.Data we collect

  • Account credentials — your username and a password hashed with bcrypt. We never store passwords in plain text.
  • Backend content — the files, environment variables, deployment logs, and subdomains for the backends you create.
  • Operational metadata — account creation date, container status, and backend limits.
  • Network & security data — the IP addresses used to sign up and log in, login timestamps, and abuse-prevention signals (including VPN/proxy detection results). This is used to protect the platform and enforce bans.

2.How we use your data

  • To authenticate you and operate your account and backends.
  • To secure the platform — rate limiting, IP bans, and VPN/proxy detection to prevent abuse.
  • To respond to support requests and legal notices (such as DMCA).
  • To maintain reliability and diagnose problems.

We do not sell your personal data.

3.Secrets

Environment variables marked as secret are masked in the interface and are only revealed to users who can manage the corresponding backend.

4.Cookies & sessions

We use a single, httpOnly session cookie to keep you logged in. It is not used for advertising or cross-site tracking. Clearing it (or signing out) ends your session.

5.Third parties

  • Cloudflare — provides DNS, TLS, and DDoS/bot protection. Requests pass through Cloudflare’s edge, which processes connection metadata such as your IP address.
  • IP intelligence provider — to detect VPNs and proxies, we may send a visitor’s IP address to a reputation service. Only the IP is shared, and results are cached.

6.Data retention

We keep account and backend data for as long as your account is active. Security logs and IP records are retained only as long as needed for abuse prevention. When you delete your account, your personal data and backends are permanently removed (see below).

7.Your rights & controls

From Account Settings → Privacy & Data, you can:

  • View all account data we store about you.
  • Download a copy of your data as JSON.
  • Delete your account permanently after confirming your password.

Deleting your account removes your profile, backends, deployments, backend files, stored environment variables, subdomains, API keys, sessions, and associated database records. This action is irreversible.

8.Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above.