This Privacy Policy explains what personal data BackupXo (“we”, “us”) collects when you use BackupXo, why, and what rights you have. It is written to satisfy the GDPR (EU 2016/679) and the Turkish Personal Data Protection Law (KVKK, Law No. 6698); where local law grants you more rights, those apply.
1. Data controller
BackupXo — [email protected]. For the contents of your databases and the backups written to your bucket, you are the controller and we act only as a processor on your instructions.
2. What we collect
| Data | Why | Kept |
|---|---|---|
| Account: username, e-mail, password hash (argon2id), 2FA secret and recovery codes (encrypted) | Creating and securing your account, signing you in | Until you delete the account |
| Server and storage configurations: hostnames, ports, usernames, passwords and API keys (encrypted at rest) | Running the backups, restores, health checks and data browsing you configure | Until you delete them or the account |
| Backup metadata: object keys, sizes, checksums, timestamps, run and restore logs | Showing history, enabling restores and retention | Until you delete them or the account |
| Notification settings, including a Telegram bot token (encrypted) and chat ID | Sending the alerts you opted into | Until you remove them |
| Audit log: action, timestamp, your IP address | Security, abuse prevention, letting you review activity on your account | Deleted with the account |
| Technical logs on our servers (request path, status, IP) | Operating and securing the Service | Typically ≤ 30 days |
We do not store copies of your database dumps. They are streamed from your database server through our service into your own bucket and are never written to our disks.
3. Legal bases
Performance of the contract with you (providing the Service), our legitimate interest in keeping the Service secure and abuse-free (audit and technical logs, bot protection), and your consent where you enable optional features such as Telegram notifications.
4. Third parties we use
- Cloudflare – DNS/proxy in front of the Service and the Turnstile bot-protection widget on sign-in and sign-up. Turnstile processes your IP address and browser signals under Cloudflare’s privacy policy.
- Your storage provider (Cloudflare R2, Amazon S3, MinIO, Backblaze, Wasabi, …) – receives the backup objects. Their handling of that data is governed by your agreement with them.
- Telegram – only if you configure a bot; notification texts (job names, server names, error messages) are sent through the Telegram Bot API.
- Google Fonts – the interface loads the IBM Plex typeface from Google’s servers, which receive your IP address for that request.
We do not sell personal data and we do not use advertising or analytics trackers.
5. Where data is processed
Our servers are located in the European Union / Türkiye depending on the deployment of this instance. Your backups are stored wherever your chosen bucket lives.
6. Security
Credentials are encrypted with authenticated encryption before they are written to the database; passwords are hashed with argon2id; sessions use signed, HttpOnly cookies; all traffic is served over TLS; connections to your database servers can be encrypted; every change is written to an audit log. See the Security page for details.
7. Your rights
You can access and correct your account data in Settings, export backup metadata from the Backups page, and delete your account (Settings → Danger zone), which erases everything we hold about you except technical logs that expire on their own. You also have the right to object to or restrict processing and to lodge a complaint with your supervisory authority (in Türkiye the KVKK Board, in the EU your national DPA). To exercise any right, write to [email protected].
8. Children
The Service is not directed at children under 16 and we do not knowingly collect their data.
9. Changes
We will update this policy when our practices change and revise the “last updated” date above. Significant changes will be announced in the Service.