What we collect, and who else sees it.
This describes what Antideploy actually does with your data today. Every claim on this page matches how the platform is built, not how we would like it to sound.
1. Who we are
Antilayers Private Limited operates antideploy.com. In this policy "we", "us" and "Antideploy" mean Antilayers Private Limited, and "you" means the person using the service.
Registered office: C/o Yogendra Kumar, Phase-2, Yamnotri Enclave, Dehradun City, Dehradun, Dehradun- 248001, Uttarakhand
CIN: U62099UT2026PTC021581
Contact: support@antideploy.com
2. What we collect
2.1 Account information
You sign in with GitHub or with Google. We never ask you for a password, and we do not store one.
- GitHub. Your numeric GitHub user id, your username, your display name, your avatar image URL, and your email address where GitHub releases it. GitHub does not always release an email address, and the service works without one.
- Google. Your Google account identifier, email address, name and profile
picture. The permission we request is exactly
openid email profile. We do not request access to Gmail, Drive, Calendar, Contacts, or anything else in your Google account.
2.2 Your code and files
- Repositories. Signing in with GitHub does not give us access to your code. Access comes only from installing the Antideploy GitHub App and choosing which repositories it may see. We read the contents of those repositories in order to build and deploy them.
- Uploaded folders. If you upload a folder, we store its files so the deployment can be built and rebuilt.
2.3 Environment variables and secrets
Values you save as secrets are encrypted before they are written to our database, using AES-256-GCM. They are decrypted only when a deployment runs and needs them. The console shows you which keys exist, never their values.
2.4 Deployment records and logs
We record what was deployed, when, whether it succeeded, and how long it took. We hold the build output and the runtime logs of your applications, because those are the things you need when a deploy fails.
2.5 Databases we provision
When you ask for a Postgres database we create one with our infrastructure provider and give you its connection details. What you store in that database is yours. We do not read it, and we do not analyse it.
2.6 Billing
Payments are taken by Razorpay. We never see, receive or store your card number, UPI ID, bank details, CVV or any payment credential. Those go directly to Razorpay. What we keep is the subscription identifier Razorpay gives us, which plan it is for, its status, the date the paid period ends, and the notification messages Razorpay sends us about it.
3. What we do not collect
This is a short list and we intend to keep it short.
- No analytics. There is no analytics product on this site. No Google Analytics, no Plausible, no PostHog, no Mixpanel, nothing of that kind.
- No tracking pixels, no advertising cookies, no profiling.
- No session recording and no heatmaps.
- We do not sell your personal data, and we do not share it with advertisers or data brokers.
4. Cookies
We set two cookies, and both are strictly necessary for signing in. There is no consent banner on this site because there is nothing optional to consent to.
| Cookie | Purpose | Lifetime |
|---|---|---|
__Host-ad_session |
Keeps you signed in. HttpOnly, Secure, SameSite Lax, so it cannot be read by JavaScript and cannot be set by any other subdomain. | 30 days |
ad_oauth_state |
Protects the sign-in round trip against cross-site request forgery. | Minutes, during sign-in only |
5. Who else sees it
Running this service means other companies process some of your data on our behalf. This is the complete list.
| Provider | What it does | What it can see |
|---|---|---|
| Google Cloud Platform | Runs your applications, builds them, stores your uploaded files and our logs | Your code, your files, your logs |
| Neon | Hosts our database and the Postgres databases we provision for you | Account records, and the contents of your database |
| Cloudflare | DNS and the edge proxy in front of the platform and your deployed applications | Request metadata, including IP addresses |
| Resend | Sends transactional email, such as a failed deploy notice. Resend delivers through Amazon SES | Your email address and the message |
| Razorpay | Takes payments | Your payment details, which we never see |
| GitHub | Sign-in, and repository access where you have installed our App | Your identity and the repositories you selected |
| Sign-in with Google | Your identity |
fonts.googleapis.com and fonts.gstatic.com. That means Google
receives your IP address and browser details when you view a page here, whether or not you
have an account. We mention it because it is the only third party that sees you before you
sign in.
6. Where it is kept
- Applications, builds, uploaded files and logs are held in Google Cloud's
asia-southeast1region, in Singapore. - Our database, and the databases we provision for you, are held with Neon in
aws-ap-southeast-1, also in Singapore. - Cloudflare operates a global network, so request metadata may be handled at an edge location near you.
If you are in India, this means your data is processed outside India. By using the service you agree to that transfer.
7. How long we keep it
- Your account is kept until you ask us to delete it.
- An application you delete is removed properly. We delete the running service, the database we provisioned for it, the files we stored for it, and its records in our database. This is a real deletion, not a hidden flag.
- Logs are held for 30 days and then deleted automatically.
- Billing records are kept for as long as Indian tax and company law requires us to keep our books of account, which is currently eight financial years.
8. Your rights
Under India's Digital Personal Data Protection Act, 2023, you may ask us to:
- tell you what personal data of yours we hold and who we have shared it with,
- correct or complete anything that is wrong or out of date,
- erase your personal data where we no longer need it,
- nominate someone to exercise these rights if you die or become incapacitated,
- raise a grievance about how we have handled any of this.
9. Grievance Officer
If something about your data has gone wrong, this is the named person responsible for answering you.
Akkshatt Shah,
CEO
Antilayers Private Limited
C/o Yogendra Kumar, Phase-2, Yamnotri Enclave, Dehradun City, Dehradun, Dehradun- 248001, Uttarakhand
support@antideploy.com
We will acknowledge your grievance and respond within thirty days.
10. Security
What we actually do:
- Everything is served over HTTPS.
- Secrets you store are encrypted at rest with AES-256-GCM.
- The session cookie is HttpOnly, Secure, and carries the
__Host-prefix, so an application deployed on a neighbouring subdomain cannot set or read it. - Secret values are never written to logs and never sent to a browser.
- Payment credentials never reach our systems at all.
No service can promise that nothing will ever go wrong, and we will not pretend otherwise. If a breach affects your personal data we will tell you and the Data Protection Board as the law requires.
11. Children
Antideploy is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us personal data, email us and we will delete it.
12. Changes to this policy
If we change this policy we will update the date at the top of the page. If a change materially affects how we handle your personal data, we will email account holders before it takes effect.
13. Contact
Antilayers Private Limited
C/o Yogendra Kumar, Phase-2, Yamnotri Enclave, Dehradun City, Dehradun, Dehradun- 248001, Uttarakhand
support@antideploy.com
Our Terms of Service cover the commercial side of using Antideploy.