Privacy Policy
Last updated: 12 September 2026
Purpose of this policy
This Privacy Policy explains how Unlyme SA (“Unlyme SA”, “RootPilot”, “we”, “us”) processes personal data when you visit the websites, create an account, connect servers, unlock the vault, or use the AI agent, terminal, action log, dictation, or billing. It describes how the product actually works. It is not a promise of zero-knowledge while a vault session is unlocked, and it is not a claim that we monitor your servers around the clock.
Who is responsible
The controller for RootPilot is Unlyme SA, a Swiss company, Route des Flumeaux 48, 1008 Prilly, Switzerland. Privacy contact: support@rootpilot.io. Unlyme SA may process personal data itself or through a local agent, affiliate, or other local company in the country where you use the Service. Unlyme SA chooses that model. In some countries a local company will invoice you or process your payment; that company may be a separate controller or processor for the billing relationship. The checkout, invoice, or payment screen will identify the entity that bills you. Platform account data and operational logs are still administered by Unlyme SA unless we tell you otherwise. Where Swiss or EU data-protection law applies, Unlyme SA is typically the controller for your account and platform logs. When the agent or terminal acts on a server you connected, we process that operational data to provide the Service you asked for.
Data we process
Account data: email address, a password hash (we do not store your account password in plaintext), session tokens, and plan or credit balances. Server connection metadata: display name, host, port, SSH username, public SSH key material, and the encrypted private-key package (ciphertext, salt, and IV). Service activity: chat messages, agent tasks and status, command output shown in the product, Infrastructure Memory / server profile derived from inspections you run, and the server action log (commands that reached the host, confirmations, and vault lock or unlock that you trigger). Deleting a chat does not delete that server’s action log. Deleting the server does. Authentication and security events: login, registration, token refresh, failed login, and operator password resets, with IP address and user-agent where available. Billing data: plan, credits, and payment references. Card numbers are handled by the payment processor; we do not store full card numbers. Technical logs reasonably needed to operate and secure the platform. If you accept analytics cookies on a marketing site, Google Analytics receives the page URL, approximate location derived from IP, device and browser data, and a client identifier. We do not load that in the product app.
Data we do not keep as a matter of design
Vault password: entered and used only in your browser to encrypt and decrypt keys locally. We cannot read it and cannot reconstruct it for you. Server root or host password after onboarding: used once to install RootPilot’s SSH key, then discarded. It is not kept for ongoing access. Plaintext SSH private keys in our primary database: long-term storage is ciphertext only. Microphone audio from dictation: speech-to-text runs in the browser. We receive the resulting text if you leave it in a field — not the audio.
Vault sessions
When you unlock the vault, the decrypted SSH key is held in short-lived session storage so the agent and terminal can connect to your servers. The key is removed when you lock the vault, when the session ends, or when its time-to-live expires. While the vault is locked, RootPilot cannot run commands on your servers. While it is unlocked, the product is not zero-knowledge: a session credential exists so the work you requested can run. RootPilot staff do not have your vault password.
AI and research providers
To run a task we send relevant context — your prompt, server facts, prior steps, and command output as needed — to third-party model and research providers. They process that content to produce plans and replies. We use those providers as vendors, not as an official partner of any model lab. Their own terms and privacy notices also apply to what they receive. Do not put secrets in chat that you are not willing to send to a model provider.
Dictation
Optional dictation uses the browser’s speech-recognition API. Audio is handled by the browser and, depending on the browser, its vendor. It is not uploaded to RootPilot’s servers. Recognised text is treated like anything else you type.
Cookies and local storage
We use cookies and similar storage that are needed to run the Service: authentication, locale (including a locale cookie on the marketing sites), and theme. Those are necessary for the Service to work. On the marketing sites (rootpilot.ru and rootpilot.io) we may use Google Analytics 4 after you accept analytics cookies. That script is not loaded until you accept, and it is not loaded in the product app or the admin console. Analytics cookies measure how the marketing pages are used (page address, approximate region, device and browser). We do not use advertising cookies or Google Ads remarketing. On rootpilot.ru we may also use Yandex Metrica after you accept. That script is not loaded until you accept, and it is not loaded in the product app or the admin console. Yandex Metrica cookies measure visits and may include a click map and session replay (Webvisor). We do not use Yandex advertising cookies. If you refuse, we do not set Analytics or Metrica cookies and we do not send page views to Google Analytics or Yandex Metrica. You can change this later from Cookies in the footer. A Google Search Console verification tag, if present in the page, is not a cookie and does not track you. The Yandex Webmaster HTML verification file on rootpilot.ru is also not a cookie and does not track you. You can also clear or block cookies in your browser. The Service may then fall back to defaults, and you may need to sign in again.
Why we process data
We process data to provide and secure the Service: authenticate users, store connection settings you submit, run agent and terminal sessions when the vault is unlocked, show output and the action log, bill usage, prevent abuse, diagnose incidents, and answer support requests. If you accept analytics cookies, we also use them to understand how the marketing sites are used. Where the GDPR or the Swiss Federal Act on Data Protection (FADP) applies, the legal bases include performance of a contract, legitimate interests in operating and securing the platform, consent for analytics cookies on the marketing sites, consent where a browser permission is required, and legal obligation. We do not sell personal data. We do not use your vault password or plaintext private keys for advertising or unrelated profiling.
Processors and disclosures
We use infrastructure and service providers only as needed to host and operate RootPilot. That typically includes cloud hosting and databases (Google Cloud, primarily the europe-west3 / Frankfurt region), cache and session storage, email delivery, payment processing, and the model or research providers that execute a task. If you accept analytics cookies on a marketing site, Google LLC processes that analytics data as our processor. Their own terms also apply. On rootpilot.ru, if you accept, Yandex LLC also processes Yandex Metrica data as our processor. Their own terms also apply. Payment may be processed by Unlyme SA or by a local agent or payment partner in your country (for example Stripe or a local acquirer). That is why the merchant or invoicing name on a charge can differ by country. Local agents and other processors handle data under contract and only on instructions needed to provide their service. We may disclose information if required by applicable law, a binding legal process, or to protect the rights, security, or integrity of users and the platform. Where legally permitted, we will notify you of such a request.
Where data is processed
Account and platform data are hosted in the European Union and administered from Switzerland by Unlyme SA. Model or research providers may process task content in other countries. A local agent may process billing, tax, and related account data in the country where it operates. Google Analytics, if you accepted it, may process that data in the United States or other countries where Google operates. Yandex Metrica, if you accepted it on rootpilot.ru, may process that data in the Russian Federation or other countries where Yandex operates. Where a transfer needs a safeguard, we rely on appropriate contractual measures offered by the provider or the local agent. We do not operate a data centre in the Russian Federation. If you use the Service from a country that requires local storage of personal data, you are responsible for whether that use is lawful for you.
Retention
We retain account, server, chat, memory, and action-log data while your account or the relevant server remains and the data is needed to provide the Service. You may delete chats or servers where the product allows. Residual backups and security logs may persist for a limited period afterwards. The server action log remains if you delete a chat. It is removed when you delete the server. Vault session material is short-lived by design.
Security measures
We apply technical and organisational measures appropriate to the data: encryption of SSH private keys at rest with credentials derived in the browser, TLS in transit, access controls on production systems, and session-scoped handling of unlocked keys. No method of transmission or storage is perfectly secure. You remain responsible for protecting your vault password, limiting who can use your account, and reviewing actions before you confirm high-impact changes.
Your choices and rights
Subject to applicable law — including the Swiss FADP and, where it applies to you, the GDPR — you may request access to, correction of, deletion of, or portability of personal data we hold about you, and you may object to or restrict certain processing. You may lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, if you are in the EEA, your local supervisory authority. You can lock the vault at any time to end live server access. To exercise these rights, email support@rootpilot.io. We may need to verify your identity before fulfilling a request.
Age
The Service is for people aged 18 or older. We do not knowingly collect personal data from children. If you believe a child has created an account, contact support@rootpilot.io and we will delete it.
Contact
Privacy and data-protection enquiries: support@rootpilot.io Unlyme SA, Route des Flumeaux 48, 1008 Prilly, Switzerland.