RootPilot
Back to home

Privacy Policy

Last updated: July 2026

Purpose of this policy

This Privacy Policy explains how RootPilot (“we”, “us”) processes personal data when you create an account, connect servers, unlock the vault, or use the AI agent and terminal. We design the product so that sensitive credentials stay under your control: the vault password never leaves your browser, and SSH private keys are stored only as ciphertext except during an unlocked session.

Who is responsible

RootPilot is developed in Switzerland (Prilly / Lausanne area). For privacy questions related to the service, contact us at support@rootpilot.io. Depending on how you use RootPilot, we may process data as an independent controller (for example, account administration) or as a processor acting on your instructions (for example, executing commands on infrastructure you connect).

Data we process

Account data: email address and a password hash (we do not store your account password in plaintext). Server connection metadata: display name, host, port, SSH username, public SSH key material, and the encrypted private key package (ciphertext, salt, and IV). Service activity: chat messages, agent tasks and related status, command output shown in the product, and server profile / memory data derived from inspections you run. Technical logs needed to operate and secure the platform (for example authentication events, error diagnostics, and abuse prevention), retained only as long as reasonably required.

Data we do not keep as a matter of design

Vault password: entered and used only in your browser to encrypt and decrypt keys locally. Server root or host password after onboarding: used once to install RootPilot’s SSH key, then discarded; it is not retained for ongoing access. Plaintext SSH private keys in our primary database: long-term storage is ciphertext only.

Vault sessions

When you unlock the vault, the decrypted SSH key is held in Redis for the active session so the agent and terminal can connect to your servers. The key is removed when you lock the vault, when the session expires, or when the TTL ends. While the vault is locked, RootPilot cannot run commands on your servers.

Why we process data

We process data to provide and improve the service: authenticate users, store connection settings you submit, run agent workflows when the vault is unlocked, display live terminal output, maintain product reliability and security, and respond to support requests. We do not sell personal data. We do not use your vault password or plaintext private keys for advertising or unrelated profiling.

Processors and disclosures

We use infrastructure and service providers strictly necessary to host and operate RootPilot (for example cloud hosting, databases, and email delivery). They process data under contractual obligations and only on our instructions. We may disclose information if required by applicable law, a binding legal process, or to protect the rights, security, or integrity of users and the platform. Where legally permitted, we will notify you of such a request.

Retention

We retain account, server, chat, and task data for as long as your account remains active and the data is needed to provide the service. You may delete servers, chats, or your account where the product allows; residual backups and security logs may persist for a limited period thereafter. Vault session material in Redis is short-lived by design.

Security measures

We apply technical and organisational measures appropriate to the sensitivity of the data, including encryption of SSH private keys at rest with credentials derived in the browser, TLS in transit, access controls on production systems, and session-scoped handling of unlocked keys. No method of transmission or storage is perfectly secure. You remain responsible for protecting your vault password and for reviewing actions before confirming high-impact changes.

Your choices and rights

Subject to applicable law, you may request access to, correction of, or deletion of personal data we hold about you, and you may object to or restrict certain processing. You can also lock the vault at any time to revoke live server access. To exercise these rights, email support@rootpilot.io. We may need to verify your identity before fulfilling a request.

Contact

Privacy and data-protection enquiries: support@rootpilot.io Postal correspondence: Route des Flumeaux 42, 1008 Prilly, Switzerland.