Privacy Policy
Effective date: September 14, 2026
We collect only what is needed to show you the state of your servers and keep your account safe. This page lists exactly what that is, where it lives, how long we keep it and how you can get it removed.
1. Who we are and what this policy covers
This Privacy Policy explains how AdminXO ("we", "us") collects, uses and protects personal data when you visit adminxo.com, create an account, or install the AdminXO agent on your servers. AdminXO is the data controller for the data described here.
We keep this policy short on purpose. If anything is unclear, contact us at the address at the end of the page.
2. Data you give us
- Account data: username, e-mail address and a salted bcrypt hash of your password. We never store the password itself.
- Two-factor authentication data, if you enable it: the TOTP secret and hashed one-time backup codes.
- SSH public keys that you generate in the panel or paste into the key store. Private keys generated by the panel are shown to you once and are not stored on our servers.
- Server names and any notes or settings you enter in the panel.
- Messages you send us by e-mail.
3. Data collected by the agent
The agent you install sends the following to the panel so that we can display it to you and generate alerts:
- System metrics: CPU, memory, disk and network usage, load average, uptime, hostname, operating system and kernel version, public and private IP addresses of the server.
- Security state: listening ports and the processes behind them, firewall (ufw / iptables) rules and status, fail2ban jails, SSH configuration settings, pending updates and the results of the security audit.
- Access activity: failed and successful SSH login attempts, including the source IP addresses and the usernames that were tried, and IP addresses blocked by the firewall.
- Running processes and Docker containers (names, images, ports, state).
- Log excerpts and terminal output only when you explicitly request them in the panel; terminal sessions are relayed in real time and are not recorded.
The agent does not read the contents of your files, databases or web applications, and it does not collect data about your customers or end users beyond the IP addresses that appear in SSH and firewall logs.
4. Data collected automatically on the website
- Server logs: IP address, user agent, requested URL and timestamp of requests to the panel, kept for security and troubleshooting.
- Cookies: a session cookie (adminxo_session) that keeps you signed in, and a preference cookie (axo_lang) that stores your language. We do not use advertising or cross-site tracking cookies.
- Bot protection: the registration form uses Cloudflare Turnstile. Cloudflare processes technical information about your browser and connection to decide whether you are a human; see Cloudflare’s privacy policy for details.
5. Why we process your data
- To provide the Service: authenticate you, show your servers, run the actions you request and send alerts (contract performance).
- To keep the Service secure: rate limiting, abuse detection, audit of administrative actions (legitimate interest).
- To communicate with you about the Service, for example important security notices or changes to these terms (legitimate interest / legal obligation).
- To comply with legal obligations and to establish, exercise or defend legal claims.
We do not use your data for advertising, we do not build profiles about you, and we do not sell or rent personal data to anyone.
6. Where data is stored and who can access it
Data is stored in a database operated by AdminXO on servers located in the European Union. Only the account that connected a server can see that server’s data; administrators of the Service can access data solely for operating, securing and supporting the Service.
We use a small number of service providers to run the Service: hosting and network providers, and Cloudflare for bot protection. These providers process data on our behalf under contracts that restrict their use of the data.
The connection between your browser and the panel, and between the agent and the panel, is encrypted with TLS.
7. How long we keep data
- Metrics history: 7 days.
- Commands and their output: 14 days.
- Events and security alerts: 60 days.
- Current state (ports, firewall, audit, processes): replaced on every agent report and deleted when you remove the server.
- Account data: until you delete your account. Deleting a server removes all of its data immediately.
- Request logs: up to 90 days.
Backups may hold copies for a short additional period before they are rotated.
8. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to restrict or object to its processing, and to lodge a complaint with a supervisory authority. Most of these you can do yourself: edit your account in Settings, remove servers from the panel, or remove the agent from a server. To delete your account entirely or to exercise any other right, e-mail us and we will respond within 30 days.
9. Security
We protect data with encryption in transit, hashed credentials, per-server authentication tokens, rate limiting, optional two-factor authentication and access restricted to the owning account. No system is perfectly secure; if we become aware of a breach that affects your data we will notify you without undue delay.
10. Children
The Service is not directed at children and we do not knowingly collect personal data from anyone under 18.
11. Changes to this policy
We may update this policy from time to time. The effective date at the top shows the latest revision. For material changes we will notify you in the panel or by e-mail.
12. Contact
Privacy questions and requests: [email protected].