Zuvio Atlas/Privacy Policy
← Home

Privacy Policy

Zuvio Atlas is a server monitoring service. This policy explains exactly what we collect, why, how long we keep it, and who else touches it.

Effective 21 July 2026

1. Who we are

Zuvio Atlas (“Atlas”, “we”, “us”) is operated by Zuvio Systems, based in Nairobi, Kenya. Atlas is available at atlas.zuviosystems.com.

For any privacy question, or to exercise any right described in this policy, contact admin@zuviosystems.com. We are the data controller for account data, and a data processor for the telemetry you send us about your own servers.

2. What we collect

Account identity

When you sign in with Google or GitHub, we receive your name, email address, and profile picture. We request only the minimum identity scopes needed to create your account — for Google, these are openid, email, and profile. We do not request access to your Gmail, Drive, Calendar, Contacts, or any other Google service, and we cannot read them.

Server telemetry

If you install the Atlas agent on a server, it sends us operational metrics roughly every 60 seconds. This is the core of the service. It includes:

  • Resource metrics — CPU, memory, disk usage and I/O, network throughput, load average, TCP connection counts.
  • Host identity — hostname, primary local IP address, public IP address, operating system, timezone, and system clock offset.
  • Running processes — the top processes by CPU usage, including process names and command lines.
  • Services and containers — detected services, and Docker container names, states, and per-container resource usage.
  • Scheduled jobs — user crontab entries discovered on the host, and the start time, duration, and exit code of monitored job runs.
  • Log events — lines from system logs (authentication, nginx, syslog, PostgreSQL, MySQL) that match alert patterns you configure.

Command lines and log lines can incidentally contain sensitive values if your own scripts place secrets there. Atlas stores what the agent reports; it does not attempt to redact this. Avoid passing secrets as command-line arguments on monitored hosts.

Monitoring configuration

The URLs, domains, IP addresses, and hostnames you ask us to monitor, plus the destinations you configure for alerts — email addresses, phone numbers, and webhook URLs for Slack, Discord, Telegram, PagerDuty, or Opsgenie.

Billing

Plan tier, billing cycle, and subscription status. Card details are handled entirely by our payment processor — we never see or store card numbers.

Product and website analytics

Our marketing pages and the signed-in dashboard use Google Analytics, so we can see which features are actually used and where people get stuck. It records page views, approximate location, and browser type.

Because dashboard page addresses include identifiers — for example /dashboard/servers/<id> — those identifiers are part of the page address Google Analytics receives. It does not receive your metrics, logs, alert contents, or any server hostname or IP.

Analytics is never loaded on public status pages. Those pages are yours, shown to your customers, and we do not track visitors there.

What we do not collect

We do not use advertising trackers, we do not sell data, and we do not build advertising profiles.

3. Google user data — Limited Use

Atlas’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Concretely, the name, email address, and profile picture we receive from Google are:

  • used only to create and authenticate your Atlas account, display who you are in the dashboard, and send you service and alert email;
  • never sold, and never transferred to third parties except the subprocessors listed below that are strictly necessary to run the service, or where required by law;
  • never used for advertising, ad targeting, or credit assessment;
  • never read by a human, except with your explicit permission for support, or where required by law.

You can revoke Atlas’s access at any time from your Google Account permissions page. Revoking access does not delete your Atlas account — to do that, see section 7.

4. Why we use it

We process the data above only to:

  • run the monitoring service you signed up for — collecting metrics, evaluating alert rules, and detecting outages;
  • notify you when something breaks, through the channels you configured;
  • render your dashboards, reports, and status pages;
  • authenticate you and keep your account secure;
  • bill you, and enforce plan limits;
  • diagnose faults and improve reliability.

Our legal bases, where GDPR applies, are performance of a contract (running the service), legitimate interests (security, fault diagnosis, service improvement), and legal obligation (tax and accounting records).

5. How long we keep it

Telemetry is aggressively aged down. Raw, full-granularity data has a short life; only coarse averages persist long-term.

DataRetention
Raw metrics (full granularity)7 days
Hourly metric averages90 days
Daily metric averages13 months
Job run history30 days by default, configurable per monitor
Synthetic check results7 days
Status page view counts90 days
Incidents and alert historyLife of the account
Account and billing recordsLife of the account, then as tax law requires

6. Who else touches your data

We share data only with the subprocessors needed to operate Atlas. We do not sell data to anyone, for any purpose.

SubprocessorPurposeData involved
Self-hosted infrastructurePrimary application and databaseAll service data, on servers we control
Google CloudGeo-distributed uptime probesThe URLs and hosts you ask us to check
CloudflareDNS, CDN, and the corporate websiteNetwork metadata, IP addresses
TwilioSMS and voice alert deliveryPhone numbers you configure, alert text
PaystackPayment processingBilling identifiers and card data, which we never receive
Email delivery providersAlert, report, and transactional emailRecipient addresses, message content

We will also disclose data where legally compelled, or to protect the rights, safety, or property of Atlas, our users, or the public.

Atlas is operated from Kenya and uses infrastructure in the United States, Europe, and Asia. Your data will be transferred and processed outside your country of residence.

7. Your rights and choices

You can, at any time:

  • Access and correct your account details from Dashboard → Account.
  • Export your monitoring data through the public REST API.
  • Delete everything from Dashboard → Danger Zone. This permanently removes your account, servers, telemetry, monitors, and incidents. It cannot be undone.
  • Stop collection by uninstalling the agent from your servers.
  • Unsubscribe from status page notifications via the link in any such email. Alert and billing email cannot be unsubscribed while your account is active, because it is the service itself.

Depending on where you live, you may also have rights to object to or restrict processing, to data portability, or to lodge a complaint with a supervisory authority — in Kenya, the Office of the Data Protection Commissioner. Email admin@zuviosystems.com and we will respond within 30 days.

8. Security

  • All traffic is encrypted in transit with TLS.
  • Agent tokens are never stored in plaintext — we keep only a salted SHA-256 hash, and verify with constant-time comparison.
  • Tokens can be revoked instantly, and a revoked agent stops reporting.
  • The agent runs unprivileged and sandboxed, and does not require root.
  • Data is isolated per tenant, and that isolation is enforced by automated checks on every build.

No system is perfectly secure. If you believe you have found a vulnerability, please report it to admin@zuviosystems.com rather than disclosing it publicly.

9. Cookies

Atlas sets the cookies required to keep you signed in and to protect against cross-site request forgery. Clearing them signs you out.

Google Analytics sets its own cookies to recognise returning visits, on the marketing pages and the dashboard. There are no advertising cookies, and no analytics of any kind on public status pages.

We use Google Consent Mode. Advertising storage is permanently deniedand never granted by any choice you make — we run no advertising. For analytics, a banner asks on your first visit, and your answer is remembered in your browser.

Visitors in the EEA, UK and Switzerland are denied by default: nothing is measured there unless you actively accept. Elsewhere analytics starts enabled and the banner lets you turn it off. Either way you can also block it with any tracker-blocking extension — Atlas works exactly the same.

To change your mind later, clear this site’s cookies and site data in your browser; the banner will ask again on your next visit.

10. Children

Atlas is a tool for operating server infrastructure and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child has provided us data, contact us and we will delete it.

11. Changes to this policy

If we make a material change, we will update the effective date above and notify account owners by email before it takes effect. Continued use after that constitutes acceptance.

See also our Terms of Service.