Get Started
Back to Alios

Privacy Policy

Last updated: September 6, 2026

This Privacy Policy explains what information Alias Project, Inc. ("Alias Project," "we," "us," or "our") collects through Alios (the "Service"), how we use it, and the choices you have. It's meant to be read alongside our Terms of Service.

Because Alios manages cloud infrastructure on your behalf, some of what we collect is more sensitive than a typical web app — most notably, credentials that grant access to your servers and cloud accounts. We've tried to be specific below about exactly what that includes and how it's protected, rather than describing it in vague terms.

1. Information You Provide

  • Account information: name, email address, and password (stored as a salted hash, never in plain text) when you sign up.
  • Team information: workspace/team names and the email addresses of anyone you invite to a team.
  • Billing information: if you subscribe to a paid plan, our payment processor, Stripe, collects your payment card details directly — we never see or store your full card number. We do store your Stripe customer and subscription identifiers so we can manage your plan.
  • SSH keys you add: if you add your own SSH public key to your profile for future use, we store the public key only. (Alios also generates its own SSH key pair per team to manage servers on your behalf — see "Infrastructure Credentials" below; that's separate from, and not affected by, any personal key you add.)

2. Infrastructure Credentials

This is the category of data most specific to what Alios does, so we're describing it plainly:

  • Cloud provider connections: when you connect AWS, Google Cloud, or DigitalOcean, we store what's needed to act on your behalf — OAuth refresh tokens for Google/DigitalOcean, or an IAM role ARN for AWS (which uses temporary, short-lived credentials we request from AWS as needed, rather than a stored secret key). These values are encrypted at rest in our database, separately from your other account data.
  • Source control connections: when you connect GitHub, we store the access credentials needed to read the repositories you authorize, so the Service can deploy your code.
  • SSH access to your servers: when Alios provisions a server, or when you connect an existing one, we generate an SSH key pair for your team and install the public key on that server so Alios can configure, deploy to, and monitor it. The corresponding private key is encrypted at rest in our database. It's used by Alios's own infrastructure to connect to your servers on your behalf and is not shared with, or accessible to, other Alios customers.
  • Server and site metadata: configuration you provide (server names, regions, sizes, deployment settings, domains you're monitoring) and metadata Alios's monitoring reports back (uptime status, SSL certificate details, response times, resource usage).

You can disconnect a cloud provider, remove a server, or revoke a source-control connection at any time from the Service; doing so removes the corresponding stored credentials.

3. Information Collected Automatically

  • Usage data: pages and features you access, actions you take (recorded in an activity log visible to your team), and general device/browser information, primarily to help us operate and improve the Service and to give your team visibility into changes made to shared infrastructure.
  • Monitoring data generated by the Service itself: when you configure uptime, SSL, DNS, or performance monitoring for a site, Alios's own systems make periodic automated requests to the URLs you specify and store the results. This is Alios acting on your instructions, not third-party tracking of you.

4. How We Use Your Information

We use the information above to:

  • Operate the Service — provisioning and managing the infrastructure you've configured, deploying your code, and running the monitoring checks you've set up.
  • Send you account-related and operational emails, including incident and monitoring notifications you've configured, billing receipts, and security notices.
  • Maintain the security and integrity of the Service, including detecting abuse.
  • Provide customer support.
  • Improve the Service based on aggregate usage patterns.

We don't use the contents of your infrastructure credentials, deployed code, or monitored site data for advertising, and we don't sell your personal information.

5. Who We Share Information With

We share information only as needed to provide the Service:

  • Your connected providers (AWS, Google Cloud, DigitalOcean, GitHub) — necessarily, since the Service acts on your behalf with the credentials you've connected.
  • Stripe, to process payments and manage subscriptions.
  • Infrastructure and email-delivery providers we use to run Alios itself (hosting, database, transactional email), bound by their own confidentiality and security obligations to us.
  • Law enforcement or other parties, if required by law or a valid legal process, or to protect the rights, property, or safety of Alias Project, our customers, or others.

We do not sell personal information, and we do not share your infrastructure credentials, deployed code, or monitoring data with anyone outside the categories above.

6. Data Retention and Deletion

We retain your data for as long as your account is active. When you delete your account:

  • Any active subscription is canceled immediately.
  • Your account, team, and infrastructure-credential data is deleted from our production systems, generally within 30 days, except where we're required to retain certain records (for example, billing records) for legal or tax purposes.
  • Deleting your Alios account does not delete infrastructure running on your connected cloud providers, or repositories on your connected source-control provider — those are managed directly through those providers, independently of Alios.

You can also disconnect an individual provider or remove a single server without deleting your whole account, which removes just that connection's stored credentials.

7. Security

We encrypt sensitive credentials — cloud provider tokens, SSH private keys, and similar secrets — at rest, separately from the rest of your account data, and we use industry-standard measures (encryption in transit, access controls, and monitoring) to protect the Service generally. No method of storage or transmission is perfectly secure, and we can't guarantee absolute security — but we treat infrastructure credentials as the most sensitive data we hold, and design accordingly.

If we become aware of a security incident affecting your data, we'll notify you as required by applicable law.

8. Your Rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal information, or to object to or restrict certain uses of it. You can access and update most of your account information directly in the Service, or contact us at [email protected] for anything else, including a full account deletion request.

9. Children's Privacy

The Service isn't directed at children under 13, and we don't knowingly collect personal information from them.

10. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we'll notify you — by email, through the Service, or both — before the changes take effect.

11. Contact

Questions about this Privacy Policy, or a request relating to your data? Reach us at [email protected].