privacy
privacy
Effective 30 July 2026.
who we are
Icearp Consulting LLC, registered in the State of Tennessee, United States, operates discocloud.io and the Disco Cloud hosted service. Contact: privacy@discocloud.io.
what this website collects
This site is a set of static files served from a content delivery network. It sets no cookies, runs no javascript, embeds no third-party resources, and has no forms. There is nothing here that can identify you to us beyond the request itself.
The delivery network records standard server access logs:
- ip address
- originating ip address and source port, where the request reaches us through a proxy or vpn
- user agent string
- requested host, path and http method
- query string, where the url has one — this is where the campaign tags on a marketing link appear
- response status and byte count
- referring url, where the browser sends one
- timestamp
- the edge location that served the request, which indicates region only roughly
- connection and delivery metadata: tls version and cipher, http protocol version, cache result, timings, and the response content type and size
These are written to storage we control, retained for 180 days, then deleted by an automated lifecycle rule. We query them in aggregate to understand traffic volume, find broken links, watch cache and latency health, see which crawlers visit, and see which tagged campaigns sent people. We do not join them to any account, build profiles from them, or share them.
We do not use analytics software of any kind. If you block trackers, you will find nothing here to block.
what the product collects
The hosted application at app.discocloud.io is a separate surface with its own data handling. Rather than restate it here and let the two versions drift apart, we publish it straight from the settings the application itself enforces:
- the trust page — subprocessors, every category of data collected, the retention window for each, and the security posture including what is not yet implemented
- /.well-known/trust.json — the same thing, machine-readable, generated at build time
The short version: we store your email address, session and audit metadata, the cloud account ids and principals you connect, and the scan results themselves. We never store cloud credentials, and we never store passwords — sign-in is by emailed magic link.
subprocessors
The full list, with the purpose and data category for each, is on the trust page. This website adds only amazon s3 and amazon cloudfront.
your rights
Data export and account deletion are both self-service inside the product — you do not need to email anyone or wait on a ticket. Export returns your own data as json. Deletion signs you out immediately, holds the data for a 14-day recovery window, and then a nightly job removes it permanently.
Two exceptions. If you are the only administrator, you are asked to promote someone or delete the organization first. And an organization can turn self-service deletion off for its members, in which case the product tells you to contact your administrator instead of failing quietly.
For anything the in-product controls don't cover, write to privacy@discocloud.io.
regulatory specifics
Our data-processing agreement, lawful-basis statement, and international transfer terms are being finalized with counsel and are not published yet. If you need them for a vendor review before they land, email privacy@discocloud.io and we will tell you exactly where they stand rather than send you a placeholder.
changes
Material changes will be reflected here with a new effective date. The machine-readable manifest carries a build sha, so you can diff it.