HolyCode Cloud — Privacy & Data Handling Note
Last updated: August 14, 2026. HolyCode Cloud is operated by TigerPoint Technologies LLC ("we," "us"), a New York limited liability company. Contact: support@holycode.cloud · https://holycode.cloud. This note explains, in plain language, how we handle your data.
This note covers the paid HolyCode Cloud product, and visits to this website. Our separate waitlist is handled separately.
The short version
HolyCode Cloud gives you a persistent, always-available Linux coding workstation in the cloud (it suspends when idle to save resources and wakes from idle in about 1 second). To run it, we hold three things: your account email, your billing details through our payment processor, and the data inside your workspace (the code and files you put there). We do not upload or centrally store your AI API keys, and we do not sell your personal information.
Where your data is processed. HolyCode Cloud is offered internationally and TigerPoint Technologies LLC is a United States company. Your account data and billing data are processed and stored in the United States. Your workspace data — everything on your workstation's disk — stays in the region you choose when you set your workstation up, which may be outside the United States. If you are in the European Economic Area or the United Kingdom, your account and billing data are transferred to the United States; choosing Frankfurt or London keeps your workspace disk in the EU or the UK. We are not currently certified under any cross-border transfer framework; if that matters for your use case, please consider it before subscribing, and write to us at support@holycode.cloud with any questions.
What we collect and why
| Data | Why we have it |
|---|---|
| Account email | To create your account, deliver your workspace, and contact you about your service, billing, or support. We also add it to our mailing list and use it to send you product updates — new features, releases, and changes to the workstation. Every one of those emails carries an unsubscribe link, and opting out costs you nothing: account, billing and support email is service rather than marketing, so it keeps coming. |
| Billing information | To take payment. Card details are handled by Whop, our merchant of record — we do not see or store your full card number. We keep the record of your plan, subscription status, and the processor's customer/subscription IDs. |
| Workspace data (your code, files, and anything you save on the workstation) | This is the core of the service. Your workspace runs on a persistent disk so your work survives restarts and idle suspends. We store it because that is what running your workstation requires. |
| Workspace access credentials | Access to your workstation is controlled by your HolyCode Cloud account. Your workstation itself never stores your account password; it only verifies that your signed-in session came from us. |
| Basic operational logs | Standard system and platform logs (e.g., machine start/stop, errors) used to keep the service running and troubleshoot problems. We do not use these to inspect the contents of your code. |
For California residents: this section serves as our notice at collection. We collect the categories above for the purposes described and retain them as explained under "How long we keep it."
Visiting this website
We count arrivals to this site so we can tell whether anyone is finding it. We do not use Google Analytics or any third-party analytics service, and nothing here follows you anywhere else.
What we record about a visit
- The time you arrived
- Which of our links brought you (the
?ref=tag we minted, if any) - Your country, from our network provider
What we do not record
- Your IP address
- Your browser or device
- Any cookie, session ID, or fingerprint
- Which pages you looked at
- Anything that could identify you, now or later
The honest consequence, since it cuts both ways: because we store nothing that identifies a visitor, we genuinely cannot tell one person from another. If you visit twice, that is two arrivals to us and we have no way of knowing it was the same person. We count arrivals, never people — and we would rather say that than describe a number as something it is not.
We keep an arrival record for 90 days, and a daily total (just a date and a count) for longer, because a count with no detail cannot identify anybody.
What we do not do
- We do not upload or centrally store your AI keys. HolyCode Cloud is Bring-Your-Own-Key (BYOK). When you add your Anthropic, OpenAI, or Google API key or subscription, it lives on your own workspace disk. We do not upload or centrally store your keys, and we do not access them. Because we operate the machine your workspace runs on, our infrastructure credentials can technically reach that disk. We use that access only when you ask us to, or when we must act on a security, abuse, or legal emergency, and we record it when we do. Your keys are never written to our logs. The honest limit of that promise: your workspace disk is encrypted at rest, but we operate the machine it is attached to, so our infrastructure credentials can technically reach it. We use that access only at your request or in a security, abuse, or legal emergency, and we record it when we do. Your keys never appear in our logs. Because we never hold your key, your AI usage is billed to you directly by your AI provider — we never resell AI tokens or see your AI bills.
- We do not sell your personal information, and we do not use your code or files to train AI models.
- We do not share your data except with the service providers listed below (who process it on our behalf) or where we are legally required to.
Who processes data for us (subprocessors)
We use a small number of trusted providers to run the service:
| Provider | What they handle |
|---|---|
| Fly.io | Hosts your workstation and stores your workspace data on their infrastructure. |
| Whop | Merchant of record for your purchase: takes payment, stores billing/card details, and handles transaction tax. |
| Resend | Sends account, support and product-update emails, and holds our mailing list. |
Each provider processes data on our behalf under its own terms and data processing agreement, and we rely on their security and privacy practices for the parts of the service they run. This list may change as the product grows; we will keep it current.
Where your data is stored
You choose where your workstation runs when you set it up, and your workspace disk is created in that region: Chicago, Ashburn or San Jose in the United States, London in the United Kingdom, Frankfurt in Germany, or Sydney in Australia. Your account record is held separately, in the United States, and your billing details are held by Whop, our merchant of record. This section previously said every workspace was in a United States region; that was wrong — non-US regions have been available since customers could choose one, and the disk is created where you picked.
Who can access your workspace
Workstations are created automatically. HolyCode Cloud is run and supported by a solo founder, who may have administrative access to your workstation in order to support or troubleshoot it. We do not routinely look at the contents of your code or files, and we access a workspace only when needed to provide the service, respond to a support request you make, or comply with the law.
How long we keep it
- While you're a customer: we keep your account email, billing record, and workspace data for as long as your subscription is active.
- Backups: the Service does not include backups, and you should not rely on us to recover anything. Your workspace runs on a persistent disk, and a persistent disk is not a backup: it protects you from a machine restarting, not from you deleting the wrong directory. What does exist, and we would rather you heard it from us than assumed either way: our infrastructure provider takes automatic daily snapshots of your volume with a short retention window (about five days). Those snapshots are the provider's rather than ours, are volume-level rather than per-file, and carry no guarantee of being available or usable when you need one. If you lose something important, ask us the same day: the window is days, not weeks, and once it closes there is nothing behind it. Please keep your own copies of anything critical.
- When you cancel: you get a 14-day window to export your workspace data — 24 hours if you were on a trial that never converted. After that window, we initiate deletion of your workstation and its data. Residual copies in our providers' systems (for example, provider-level snapshots and logs) are purged on their normal rolling cycle, up to 30 days. We cannot promise instant, irreversible deletion of every copy the moment you cancel.
- Billing records (the exception): separately from your workspace data, we and our payment processor may retain payment and transaction records — plan, amounts, dates, processor IDs — after your workspace is deleted, where we need them for tax, accounting, or legal reasons. These records do not contain your code or files.
Your choices and rights
You can:
- Access / get a copy of your account information.
- Export your workspace data at any time while active, and during the export window after cancellation (14 days, or 24 hours for a trial that never converted).
- Delete your data — cancel your subscription to trigger the export-then-deletion process above, or email us to request deletion.
- Opt out of product updates — use the unsubscribe link in any update email, or email us and we will take you off the list. This does not touch your service: account, billing and support email is not marketing and continues either way.
If you are a California resident, you can also ask us to disclose or delete the personal information we hold about you, and you will not be discriminated against for exercising these rights. As noted above, we do not sell your personal information.
Because your BYOK AI keys live on your own workspace (not with us), you control them directly — add, rotate, or remove them on your workstation at any time.
To make a request, email support@holycode.cloud. We may need to verify your identity (for example, confirm you control the account email) before acting.
Security
We take reasonable steps to protect your data, including securing workspace credentials and relying on our providers' platform security. No online service can be guaranteed 100% secure. HolyCode Cloud is an early-access product; please keep your own backups of anything critical.
Data-breach notification. If we learn that your personal data has been materially compromised, we will notify affected customers without undue delay and describe what happened and what you can do about it.
Not for children
HolyCode Cloud is intended for adults. You must be at least 18 years old to use it. It is not directed at anyone under 18, and we do not knowingly collect data from anyone under 18. If we learn we have collected data from someone under 18, we will delete it.
Changes to this note
We may update this note as the product changes. If we make a significant change, we will let account holders know by email or on https://holycode.cloud.
Contact
Questions or requests: support@holycode.cloud · TigerPoint Technologies LLC, 31 Covert Ave Unit #5252, Floral Park, NY 11001, United States · New York
Governing law: New York.