Your box, your data
What we believe about ownership, before the legal part.
When you launch a box on Cardboard, you own it. The software image, the configuration you apply, and every file stored inside the container are yours. We provide the infrastructure; what lives in it is entirely your business.
We can see operational metadata — that your box is running, how long it has been running, and how many credits it has consumed. We use that to bill you correctly and to keep the platform healthy. We cannot see the contents of your box, and we will not attempt to.
We will never sell, rent, or share the contents of your account — credit balance, box list, stored files — with third parties for advertising or data-brokering purposes.
If your account is suspended or terminated for a violation of our terms, we will give reasonable notice before removing your boxes and their data. We understand that “reasonable notice” means something different when the violation is serious (e.g. illegal content — immediate removal) versus administrative (e.g. non-payment — you'll get a warning and a window to export). We'll try to be fair.
You can stop and delete a box at any time from your dashboard. Deletion is permanent — we do not retain snapshots after a box is deleted.
Privacy Policy
Cardboard by DataCats LLC — last updated June 2026. This is written in plain English, not legalese. It is not a substitute for legal counsel, but we have tried to be accurate and complete.
What we collect
- Account information — your email address, hashed password (we never see the plaintext), and Cognito user identifier.
- Usage data — box launch/stop events, credit balance, credit transaction history.
- Payment information — processed entirely by Stripe. We store only a Stripe customer ID; we never see or store your card number.
- Technical logs — API request logs (timestamp, endpoint, status code) and VPC flow logs for security monitoring. Retained for 90 days.
What we do not collect
We do not collect, access, or index the contents of your boxes — files, databases, application state, or anything else stored inside a running or stopped container. We do not use tracking pixels, third-party analytics SDKs, or advertising cookies.
How we use what we collect
- To operate the service — authenticate you, route API requests, bill your credits, run your boxes.
- To send transactional emails — account confirmation, password reset, and credit receipts. We do not send marketing email without your opt-in.
- To monitor service health — detect abuse, investigate outages, enforce rate limits.
Third-party services
- Amazon Web Services — all infrastructure runs on AWS. Your data is stored in US East (N. Virginia). AWS is subject to its own privacy and security certifications.
- Stripe — payment processing. When you purchase credits, you interact directly with Stripe's secure checkout. Their privacy policy governs that interaction.
Data retention
Account data (email, credit history) is retained until you request deletion. Box data is deleted immediately and permanently when you delete a box. Technical logs are purged after 90 days. After account deletion we may retain minimal records (e.g., transaction IDs) for legal and accounting purposes, as required by law.
Your rights
You can request a copy of the data we hold about your account, ask us to correct inaccuracies, or request deletion of your account and associated data. Email privacy@datacats.io and we will respond within 30 days.
Changes to this policy
Material changes will be communicated by email to registered users before they take effect. The “last updated” date at the top of this page will always reflect the most recent revision.
Contact
Questions about this policy? privacy@datacats.io