Privacy policy

Last updated: September 2026

In plain English

1. Who we are

Asternodis is a product of Irruptiv Software Solutions LLC ("we", "us"), a limited liability company registered in Georgia, United States, and the data controller for the personal data described here. To reach us about privacy (including any request under section 8), email privacy@irruptiv.com.

2. This website

We set no cookies, and store nothing on your device at all. There is no analytics, no tag manager, no advertising pixel, and no cross-site tracking of any kind on the Asternodis website. Nothing is written to your browser's storage and nothing is read from it.

That is also why you were not asked to accept anything. European rules require consent for storing or reading information on your device, and this site does neither, so a consent banner would have had nothing to ask about. We would rather remove the tracking than ask permission for it.

One exception, named rather than glossed: our staff admin console at admin.asternodis.com signs in with Google and keeps that sign-in session in your browser's local storage, as any logged-in application must. It is an internal tool for our own staff: if you are not one of us you cannot sign in, and nothing there is set on your device by visiting the public site. That session data is strictly necessary to keep someone logged in, is never used for analytics or tracking, and is cleared when you sign out.

Pages load no third-party resources. Fonts, styles, scripts and images all come from this site's own servers, so viewing a page does not announce your visit to anyone else. Our typefaces were served by Google Fonts until September 2026 (which meant every page view sent your IP address to Google), and we now host them ourselves specifically to end that.

One thing does remain, and it is worth naming rather than glossing: server logs. The site is served by Firebase Hosting (Google), which keeps standard request records including IP address, user agent, and the URL requested. These are operational and security records, not a profile of you.

3. When you contact us or join the extended evaluation

The contact form and extended-evaluation signup collect your name, email address, and whatever you write in the message. We use them to reply to you and, for the extended evaluation, to send you access and release information. The lawful basis is your consent and our legitimate interest in answering people who ask us questions. We don't add you to a marketing list from a support enquiry.

4. When you buy a license

Payments are processed by Stripe. Stripe collects your payment card details, billing address, and email directly: we never see or store your card number. Stripe's own privacy policy governs that processing.

What we keep is the licence record: your email address, Stripe customer and subscription identifiers, the plan purchased, and its issue and expiry dates. We need these to issue and renew your key, to let you retrieve it from the "My licenses" page, and to meet our tax and accounting obligations. The lawful basis is performance of our contract with you, and legal obligation for the accounting records.

The "My licenses" page uses a sign-in link, not a password. You give us your email address and we send a link containing a temporary access token. The page sets no cookie and stores nothing on your device: the token is read from the link and kept in memory for that visit only, so closing the tab ends the session.

Because the token travels in the link's address, it can be recorded in your browser history and in our host's standard request logs (see section 2). Treat one of these links like a password: it expires two hours after we send it, but until it does, anyone holding it can see the licences for that email address. Don't forward it. If you think one has gone astray, tell us: the tokens are self-contained and signed, so we cannot revoke a single link, but we can rotate the signing key, which invalidates every outstanding link at once.

5. What the software reports

A licensed Asternodis controller checks in with our activation service to validate and renew its offline token. That check-in is deliberately narrow. It sends:

  • •your licence key and a random installation identifier (a UUID generated on your controller, not derived from your hardware, network, or name);
  • •counts only: how many DR Site Pairs, protected guests, and protected Proxmox nodes the installation has;
  • •two version strings: the Asternodis build and the Proxmox VE version it manages.

It does not send guest names, hostnames, IP addresses, storage layouts, configuration, logs, credentials, or any content of your virtual machines or containers. Your replicated data never leaves your own infrastructure: it moves directly between your two sites and never touches our servers.

We use the counts to match a licence against its entitlement (for example, to notice a clearly commercial deployment running on a non-commercial Home Lab key). The lawful basis is our legitimate interest in enforcing our licence terms.

If your controller cannot reach the internet, it keeps working from its offline token. Licensing is designed never to be a single point of failure during a disaster.

6. Who processes data for us

We use a small number of providers, each for one job:

Provider What for
Google (Firebase)Website hosting, the activation service, and the database holding licence records
StripePayment processing and subscription billing
ResendSending your licence key and transactional email
CloudflareDNS for asternodis.com

These providers process data on our instructions. Some are based in the United States, so data may be transferred there; we rely on their standard contractual clauses and equivalent safeguards for those transfers. We do not sell or rent personal data to anyone, ever.

7. How long we keep it

  • •Licence and billing records: for the life of the licence and then as long as tax and accounting law requires.
  • •Contact and extended-evaluation enquiries: until the conversation is finished and for a reasonable period after, then deleted.
  • •Check-in counts: kept as a rolling operational history against the licence, not against you personally.
  • •Server logs: retained on our host's standard schedule.

8. Your rights

Depending on where you live (and in particular under the UK/EU GDPR and the CCPA), you have the right to ask for a copy of the personal data we hold about you, to have it corrected or deleted, to object to or restrict how we use it, and to receive it in a portable form. You can also withdraw consent at any time, and complain to your local data protection authority.

Email privacy@irruptiv.com and we will respond within the time the applicable law allows. There is no charge for a reasonable request. Note that deleting a licence record may end the licence it represents.

9. Security

Traffic to this site and to the activation service is encrypted in transit. Licence records are held in access-controlled storage reachable only by our own server-side code. Your replicated workloads move over a mutually-authenticated, encrypted channel between your own sites and are never routed through us. No system is perfectly secure, but we hold as little as we can, which is the most reliable protection there is.

10. Children

Asternodis is a product for system administrators and is not directed at children. We do not knowingly collect personal data from anyone under 16.

11. Changes

If we change what we collect or who processes it, we will update this page and move the date at the top. Material changes affecting existing customers will also be sent by email.

Asternodis is not affiliated with Proxmox Server Solutions GmbH. See also our terms & conditions and license terms.