Hosting Privacy
How Bitbolt handles your data when we host your server. Last updated: 30 August 2026.The short version
If we host your server, we hold your business data. That is the deal — it is what managed hosting is — and it is the opposite of what our mobile app does. We store it, we back it up, and a small number of named people can reach it in order to operate and support the service. We do not sell it, mine it, or use it to train anything.What we hold
Everything you put into it: your records, documents, attachments, messages and the accounts of the people who sign in. It lives in a database created for you and used by nobody else. It is not pooled with other customers’ data.We also hold the things needed to run the account itself — your company name, the subdomain you chose, your billing contact, and how many seats you hold.Where it is
On Microsoft Azure infrastructure in the South Central US region, which is where both the running database and its backups sit today. If your organization needs data held in a particular jurisdiction, ask before you sign up — we would rather tell you no than surprise you later.Who can reach it
jayBird staff operating the service. Access is for running and supporting your tenant — investigating a fault you have reported, restoring a backup, performing an upgrade — not for reading your business.Support access to a tenant happens through a dedicated, separately authenticated route that creates its own clearly-marked account rather than borrowing yours, so it is visible in your own system who came in and when.Backups
Your database and its files are backed up nightly and stored in Azure Blob Storage in the same region. Each backup is kept for a year, moving to cheaper storage after the first month.Backups are test-restored rather than assumed to work — the restore reads real attachment bytes back and checks them against their recorded checksums, because a database restored without its files has perfect row counts and every attachment broken. A backup nobody has restored is a guess, not a backup.Who else is involved
These are the services your data passes through or rests on. We do not add one without a reason.| Service | What it does | Where |
|---|---|---|
| Microsoft Azure | The servers and storage your database and files live on, and the nightly backups. | South Central US |
| Microsoft Entra External ID | Sign-in. It verifies who you are; it does not receive your business records. | Microsoft global identity infrastructure |
| Cloudflare | DNS for your subdomain, TLS, and the tunnel your traffic reaches us through. | Global edge network |
| Stripe | Payments. Stripe collects and holds your card details; we never receive them. | Stripe global infrastructure |
Keeping it, and deleting it
We keep your data for as long as you are a customer. If your subscription lapses or a trial ends without payment, your server is suspended rather than deleted — it stops answering, and the data stays. Your database is then kept for 30 days, so you can pick it back up or ask us for an export.After that window it is deleted. If you want it gone sooner, say so and we will do it — deletion is a deliberate operation somebody performs and confirms, not an automatic sweep.You can ask for an export of your data at any time while it exists.Your own users
The people you add are your users, and their records are your data. You decide who has access and you are their first point of contact — to them, this is your system, and your own privacy policy governs what you do with what they put in it.Payments
Card details are entered on Stripe’s own pages and held by Stripe. They do not pass through our servers and we could not produce your card number if you asked us to. We keep what Stripe tells us about the subscription: who is billed, for how many seats, and whether it is paid.If something goes wrong
If we find that your data has been exposed or taken, we will tell you without undue delay, and within 72 hours of becoming aware of it. We will tell you what we know at the time rather than waiting until we know everything: what happened, which of your data was involved, what we have done, and what we advise you to do. If we are still establishing the facts, we will say so and follow up.We would rather tell you about something that turns out to be nothing than be quiet about something that turns out to matter.Data protection terms
You are the controller of the data you put in your system; we are the processor. A Data Processing Addendum is available on request — email support@jybrd.io and we will send it before you sign anything.Be aware of where things are: your database, its backups and the people who administer them are in the United States, in Azure's South Central US region. There is no EU or UK region today. If you are subject to GDPR or UK GDPR, that means a transfer out, and the DPA covers it with the European Commission's standard contractual clauses and the UK addendum. If you need your data to stay in the EU or UK, we cannot do that yet, and we would rather say so here than in a procurement questionnaire.Changes
Material changes to this policy will be published at this address with a new date at the top. If a change affects where your data lives or who can reach it, we will tell you rather than rely on you noticing.Contact
jayBird, LLC — support@jybrd.io. Data questions, export requests and deletion requests all go here.For the Bitbolt mobile app, which hosts nothing, see the app privacy policy.© 2026 jayBird, LLC · Bitbolt is developed by jayBird, LLC