Privacy Policy

Last updated: 2026-05-28

Cachely is currently operated by its maintainers as a beta and is not yet incorporated. The maintainers act as the data controller for the information described below. For any privacy question, request, or complaint, email hello@cachely.dev. We aim to reply within five business days.

Information we collect

We collect only what we need to run the service and to respond to people who contact us.

  • Account data. When you sign in to the dashboard via Google, we receive your email address, display name, and Google account ID. We do not receive your Google password and do not request access to any other Google data.
  • Cache data. Build artifacts you (or your CI) upload, together with their content-addressed hashes, your workspace identifier, and the API token identifier that wrote them. We treat artifact contents as opaque blobs and do not inspect them.
  • Operational logs. Cache events (hit, miss, put), timestamps, byte counts, and the token identifier that produced them. We use these to bill, to debug, and to detect abuse.
  • Interest and contact forms. Name, email, company, and any free-text message you submit through forms on this site (for example, the beta access form) or send by email. We use this only to reply to you.
  • Server logs. Standard request metadata (IP address, user agent, URL, timestamp, response status) is processed by Cloudflare on our behalf for security and reliability. These logs are short-lived.

How we use it and our legal basis

  • To provide the service (account data, cache data, operational logs): performance of a contract, or our legitimate interest in running the service you asked us to run.
  • To reply to you (forms, email): our legitimate interest in answering inbound requests, or your consent when you initiate contact.
  • To keep the service safe (server logs, abuse detection): our legitimate interest in security and integrity.
  • For optional analytics (Google Analytics 4): your consent, freely given via the banner and revocable at any time.

What we do not do

  • We do not sell your personal data.
  • We do not share your data with advertisers or data brokers.
  • We do not read, mine, or train models on the contents of your cache artifacts.
  • We do not add you to a marketing list because you filled in a form.

Sub-processors

We use a small number of vendors to run the service. Each one is contractually bound to handle data on our behalf only.

  • Cloudflare, Inc. - hosting (Workers, D1, R2), CDN, DDoS protection, and Cloudflare Web Analytics. Cloudflare may process data in any of its global regions.
  • Google LLC - sign-in (Google OAuth) for the dashboard, and Google Analytics 4 on this marketing site (only when you consent).

Analytics on this site

We use Cloudflare Web Analytics to count page views and referrers and to measure page-load performance. It is cookie-free, does not fingerprint visitors, and runs for every visitor.

We optionally use Google Analytics 4 to understand which pages and calls to action help people decide to try Cachely. After consent, GA4 receives a sanitized page URL, page title, referrer, broad device and browser details, and events for calls to action and successfully submitted interest forms. We do not send form fields, account identifiers, workspace identifiers, or cache contents to GA4. GA4 sets cookies and is only loaded after you explicitly grant consent in the banner. You can change your mind at any time:

International transfers

Our vendors are US-headquartered and operate globally. Where data is transferred out of the EEA or UK, the transfer is covered by the relevant vendor's Standard Contractual Clauses and supplementary safeguards.

Retention

  • Cache artifacts and operational logs are retained for as long as your workspace is active, or as configured by your workspace settings.
  • Account data is retained while your account is open.
  • Form submissions and inbound email are retained for up to 24 months unless you ask us to delete them sooner.
  • Server logs are retained for a short rolling window for security and debugging.

Your rights

Subject to applicable law (including the GDPR and UK GDPR for users in the EEA and UK, and the CCPA for residents of California), you have the right to access, correct, export, restrict, or delete your personal data, to withdraw consent where processing is based on consent, and to lodge a complaint with your local supervisory authority. To exercise any of these rights, email hello@cachely.dev from the address tied to your account.

Deletion

Email us at hello@cachely.dev from the address tied to your account and we will purge your workspace within 30 days, except where we are legally required to keep specific records (for example, billing records).

Security

We use TLS in transit, encrypted storage at rest via our hosting provider, and scoped API tokens for cache access. No system is perfectly secure; if you believe you have found a vulnerability, please email hello@cachely.dev and we will respond promptly.

Children

Cachely is intended for software developers and is not directed at children under 16. We do not knowingly collect data from children.

Changes

We will update the "Last updated" date at the top of this page when this policy changes. Material changes will also be announced in-product or by email to active workspace owners.