Server Wings.
Sign inStart free
/ Legal

Privacy Policy

What we collect, what stays on your servers, who sees it, and the choices you have, in plain language.

Last updated 19 September 2026

01Scope

This policy explains how Dream Boat LLC ("Dream Boat", "we") handles personal data when you use Server Wings at serverwings.com, including the dashboard, the API and the agent. It applies alongside Dream Boat's privacy policy at dreamboats.io/privacy.

It covers data about you and your team. Data about your sites' visitors lives on your servers and is your responsibility; we do not collect it.

02What we collect

  • Account details: name, email address, password (stored hashed), and your Google account id and profile picture if you sign in with Google. If you turn on two-factor authentication, its secret is stored encrypted, along with your recovery codes.
  • Billing details: your plan, trial dates, and Stripe customer and subscription ids. Card numbers are handled by Stripe and never touch our systems.
  • Servers you connect: name, IP address, SSH port, the server's SSH host-key fingerprint, and resource metrics such as CPU, memory, disk and load.
  • Sites on those servers: domain names, WordPress version, installed plugins and themes with their versions, configuration such as table prefix and PHP version, and the results of audits, such as the list of administrator accounts.
  • Security findings: for each finding, the file path, the type of threat, a short excerpt of the flagged code, and a checksum of the file.
  • Backups: when they ran, their size, and where they are stored. The backup files themselves live where you direct them, described below.
  • Services you connect: encrypted credentials for Cloudflare accounts, storage destinations (Amazon S3, Google Drive, Dropbox), and databases the Service provisions for you. Apps you deploy: their configuration and environment variables.
  • Activity: a log of actions taken in your account, who took them, when, and from which IP address.
  • Support: tickets, messages and attachments you send us.
  • Technical data: IP address and browser type in server logs, kept for security and troubleshooting.

03What stays on your servers

Your site files and databases stay on your servers. The agent runs there and sends us the results of what you asked for, such as a plugin list, a scan finding with a short excerpt, or a backup's size, not copies of your sites.

Backup files live where you put them: on the server's own disk, or in a storage account you connect. When you download a backup or open a file in the file manager, the content passes through our servers to your browser and is not retained.

When you use the web terminal or the database console, the commands you type run on your server.

04How we use it

  • To provide, operate and support the Service, including carrying out the actions you request on your servers.
  • To bill you and to detect and prevent fraud or abuse.
  • To send service messages: receipts, alerts you have configured, security notices, and important changes to terms or pricing.
  • To keep the Service secure, for example by limiting repeated sign-in attempts and investigating suspicious activity.
  • To improve the Service, using aggregated or de-identified data where possible.

We do not sell personal data. We do not use your data, your sites or your security findings to train models or for advertising.

05Who we share it with

We share data only with providers that help us run the Service, under contracts that require them to protect it, and only what each one needs:

  • Stripe, for payment processing.
  • Resend, which delivers our email.
  • Google, for sign-in if you choose it, and Google Drive if you connect it as a backup destination.
  • Dropbox, and Amazon S3 or compatible storage, if you connect them as backup destinations.
  • Cloudflare, if you connect an account: we call its API with your token to manage DNS and proxy settings for your domains.
  • Let's Encrypt, which receives your domain names when the Service issues a certificate.
  • Hosting providers that run our control plane.
  • Professional advisers and authorities, where the law requires it.

06Access by our staff

Our staff can open a read-only support session into your account to help you. It lasts up to 30 minutes and cannot change anything. Every such session, and every administrative action on your account, is recorded in an audit trail with who did it and when.

Staff with operational access to our systems can see the data above as needed to run the Service. They are bound by confidentiality and access only what the task needs.

07Cookies

The Service uses only strictly necessary cookies: one that keeps you signed in, a short-lived one during Google sign-in, and ones that keep your session with the database console. Your theme choice is kept in your browser's local storage. We do not use analytics or advertising cookies.

08How long we keep it

We keep account and product data for as long as your account is active. To close your account, email us; we delete its data within 30 days, except billing records we must keep for tax and accounting purposes.

Backups follow the retention rules you set and live in storage you control; closing your account does not delete backups on your servers or in your own storage accounts. Security findings are replaced as new scans run. Activity logs are kept while your account is active.

09Security

Data is encrypted in transit. Credentials we hold for services you connect are encrypted at rest with a key kept separately from the database. Passwords are stored hashed, and two-factor authentication is available for every account. The agent only ever connects outward to us, and each server's SSH host key is pinned when it is first provisioned, so a changed key is refused. Administrative actions are logged.

No system is perfectly secure. If we learn of a breach affecting your data we will tell you without undue delay.

10Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict certain processing, and to complain to a data protection authority. You can exercise these rights by emailing us at the address below; we will respond within 30 days. Most account details can also be changed directly in your settings.

11Children

The Service is for businesses and adults. We do not knowingly collect data from anyone under 18.

12Changes to this policy

We will post any changes here and update the date at the top. For material changes we will also email account holders.

13Contact

Privacy questions or requests: support@serverwings.com · Dream Boat LLC, 5900 Balcones Drive, Ste 100, Austin, TX 78731, USA.

Server Wings.
PlatformPricingSign inCreate account
We accept
  • VISA
  • AMEX
  • DISCVER
  • Pay
  • GPay
ContactTermsPrivacyRefundsA Dream Boat product© 2026 Server Wings