Privacy Policy
Learn how IOBend collects, uses, protects and manages personal data across its platform, developer tools and services.
1.Scope
This Privacy Policy describes how IOBend Technologies Private Limited ("IOBend", "we", "us", or "our") collects, uses, stores, protects, shares, retains, and deletes personal data when you access or use the IOBend Unified Developer Experience Platform, the IOBend command-line interface ("IOBend CLI"), developer environments, developer control planes, APIs, websites (iobend.com), and associated developer services (collectively, the "Services").
This Policy applies to individuals who visit our website, register for an account, participate in organizations or workspaces, use our developer tooling, or communicate with us. It does not apply to third-party software, repositories, or services that you may choose to integrate with IOBend.
To provide clarity to engineering teams, administrators, and compliance officers, this Privacy Policy carefully distinguishes between Personal Data (information relating to an identified or identifiable natural person) and Customer Data (proprietary source code, repository content, configuration files, container definitions, secrets, and software artifacts).
2.Who We Are
IOBend Technologies Private Limited is a private limited company incorporated and registered under the laws of India. Our primary operating jurisdiction is India.
IOBend designs its privacy practices and data protection controls to address applicable Indian legal and regulatory requirements, including the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology Act, 2000, while implementing technical safeguards aligned with international security best practices for developer platforms.
3.Information We Collect
We collect personal data only to the extent reasonably necessary to provide, secure, and maintain our developer platform. The categories of information we collect include:
Account Information
Full name, work email address, username, unique user identifier, salted and hashed authentication credentials, and user role configuration.
Billing and Transaction Information
Billing contact details, company legal name, billing address, tax identification numbers (e.g., GSTIN in India), payment method tokens, transaction history, and subscription plan records. Full credit card numbers are tokenized directly through our PCI-DSS certified payment processors.
Organization and Team Metadata
Organization name, workspace identifiers, team hierarchies, assigned role-based access control (RBAC) permissions, and project membership associations.
Technical and Authentication Information
IP addresses (used for edge routing, security inspection, and rate limiting), browser user-agent, operating system details, device type, authentication session tokens, and security event logs.
Usage and Diagnostics Information
Feature engagement counts, API request rates, platform response latencies, error codes, and operational telemetry required to maintain infrastructure stability.
Support and Communication Information
Inquiries, support ticket contents, diagnostic attachments provided during technical assistance, and survey responses.
4.Information You Provide
You directly provide information to us when you:
- Register for an IOBend account or authenticate via the IOBend CLI (
iobend login); - Create or configure organizations, teams, workspaces, or developer environments;
- Subscribe to paid subscription tiers or submit enterprise procurement details;
- Submit support requests, open bug tickets, or contact our engineering and legal teams;
- Participate in developer surveys, feedback sessions, or user research programs.
5.Information Collected Automatically
When you interact with our web console, documentation, or cloud APIs, our servers automatically record certain technical information in standard infrastructure access logs. This includes:
- HTTP request metadata (timestamp, HTTP verb, path requested, response status code);
- Origin IP address and approximate geographical region (country/city level);
- Client application version and protocol version (e.g., HTTP/2, TLS 1.3);
- Referrer URL and browser or client user-agent string;
- Rate-limiting keys and security telemetry used to detect brute-force attacks and abuse.
6.IOBend CLI Telemetry
IOBend is designed to minimize telemetry and avoid transmitting sensitive developer content through standard telemetry streams. Depending on the CLI version and enabled functionality, telemetry may include limited technical information such as application version, operating system, command execution timing, diagnostics and error information.
Developer Boundary & Command-Line Data
IOBend does not intentionally collect command-line secrets or source-code contents through standard telemetry.
Diagnostic inspections performed by workstation commands such as iobend doctor execute locally on your machine. Diagnostic results are displayed to the developer in the terminal output and are not uploaded to IOBend cloud infrastructure unless the developer explicitly executes a sync command or submits an error report.
7.Developer and Customer Data
IOBend does not claim ownership of Customer source code, repository contents or proprietary developer materials. All rights, title, and interest in and to Customer Data remain exclusively with the Customer.
Where IOBend processes Customer Data to provide a Service, processing is performed for the purposes described in the applicable agreement and documentation. Customer Data is processed strictly to orchestrate developer environments, maintain configuration baselines, coordinate dependencies, manage policies, and provide requested platform functionality.
8.Source Code, Repositories and Secrets
IOBend operates primarily as a control plane. In standard workstation workflows, your source code resides on your local machine and your connected remote version control provider (such as GitHub, GitLab, or Bitbucket).
Certain IOBend features may support mechanisms designed to reduce exposure of credentials and secrets, including local or in-memory handling. The availability and operation of these controls depend on the applicable product and configuration.
In-Memory Injection: Where supported, secrets can be injected directly into local container runtimes without persisting plaintext tokens to disk.
Envelope Encryption: When secrets are synchronized with cloud workspaces, they are encrypted using modern cryptographic primitives (such as AES-256-GCM) with keys managed via hardware security modules or key management services.
Developer Responsibility: Customers and developers remain responsible for managing key permissions, rotating sensitive credentials, and ensuring secrets are not accidentally committed in plaintext to public code repositories.
9.How We Use Personal Data
IOBend processes personal data for the following specific business and operational purposes:
- Account Authentication & Provisioning: To register users, verify identities, authenticate CLI and web sessions, and administer user profiles;
- Service Delivery & Control Plane Operations: To provision developer environments, execute orchestration workflows, coordinate tooling, and deliver platform features;
- Organization & Team Management: To enforce role-based access control, manage workspace memberships, and maintain organizational audit logs;
- API Operations & Developer Tooling: To maintain, route, meter, and rate-limit API calls;
- Billing & Payments: To process payments, issue invoices, calculate applicable taxes (including GST), and manage subscriptions;
- Customer Support: To investigate technical issues, respond to tickets, and provide customer assistance;
- Platform Security & Fraud Prevention: To monitor for security incidents, detect malicious activity, prevent unauthorized access, and protect IOBend and customer infrastructure;
- Troubleshooting & Reliability: To diagnose performance bottlenecks, optimize response times, and improve service stability;
- Service Communications: To send critical administrative notices, security alerts, billing reminders, and service status updates;
- Legal & Regulatory Compliance: To comply with applicable statutory obligations, tax filings, court orders, and contractual commitments.
We do not sell personal data, nor do we share personal data with third parties for cross-context behavioral advertising.
10.Legal Bases / Permitted Processing
Under applicable Indian privacy principles (including the DPDP framework) and international data protection laws, we process personal data under the following legal grounds:
- Contractual Necessity: Where processing is required to perform our contract with you (such as executing our Terms of Service or an Enterprise Agreement);
- Legitimate Uses / Legal Obligations: Where processing is necessary to comply with applicable laws, court orders, or statutory reporting mandates, or to maintain system security, auditability, and fraud defense;
- Consent: Where you have provided specific, informed consent for a particular processing activity (e.g., subscribing to elective product updates). Where processing is based on consent, you may withdraw consent at any time.
11.AI and Machine Learning
IOBend offers opt-in developer intelligence, configuration scaffolding, and diagnostic assistance features (such as iobend ai generate and web console assistance) powered by artificial intelligence models.
AI Architecture & Data Handling Principles
- No Foundation Model Training on Customer Data: Customer Data submitted through IOBend is not used by IOBend to train general-purpose foundation AI models.
- Input Sanitization: Our AI gateway includes automated credential filtering routines designed to detect and redact recognizable token formats (such as API keys and secret patterns) prior to model invocation.
- Scoped Prompts: When an AI command is initiated by a user, only the prompt text and necessary project structural metadata (e.g., framework name, dependency manifest names) are transmitted to provide the requested configuration.
- Customer Control: AI features are interactive and developer-driven. Organizations can govern and restrict AI feature usage across their teams.
Where external AI model APIs (such as Google Gemini / Google Cloud Vertex AI) are utilized to generate responses, processing is conducted in accordance with the third-party provider's enterprise API terms, which restrict the provider from using customer API inputs to train public models.
13.Integrations and Third-Party Services
The Services allow you to connect external developer tools and cloud services (such as GitHub, GitLab, Docker Hub, package registries, and issue trackers). When you authorize an integration, IOBend interacts with the third party on your behalf using the OAuth tokens or API keys you provide.
Third-party services are operated independently and are governed by their respective privacy policies and terms of service. We encourage you to review the privacy notices of any third-party service you connect to IOBend.
14.Service Providers and Subprocessors
IOBend engages verified third-party service providers (subprocessors) to support infrastructure hosting, primary database management, edge network routing, payment processing, and customer communications. Each service provider is bound by confidentiality and data protection obligations consistent with applicable law.
Our core infrastructure partners include:
- Amazon Web Services (AWS): Cloud compute, infrastructure hosting, and KMS key management;
- Cloudflare: Edge security, TLS termination, and DDoS mitigation;
- MongoDB Atlas: Managed database engine with field-level and rest encryption;
- Upstash: Redis session caching and rate-limiting infrastructure;
- Razorpay / Stripe: PCI-DSS certified payment processing and billing infrastructure;
- Google Cloud: Enterprise GenAI API processing where AI features are utilized.
A summary of third-party infrastructure and service providers is maintained on our Trust Center.
15.Data Storage and International Transfers
Personal data and account metadata collected by IOBend are stored on secured cloud infrastructure provided by our hosting partners. Depending on the deployment architecture and regional endpoint selected, data may be stored or processed in data centers located in India, the United States, or the European Union.
Where personal data is transferred across national borders, IOBend implements reasonable administrative, legal, and technical safeguards in accordance with applicable laws, including Indian data transfer regulations and contractual data protection addenda.
16.Data Retention
IOBend retains personal data for as long as reasonably necessary to provide the Services, maintain security, comply with legal and contractual obligations, resolve disputes, and enforce our agreements.
The criteria used to determine retention periods include:
- The duration of your active account and subscription;
- Statutory tax, accounting, and corporate compliance obligations under Indian law (e.g., maintaining financial and invoice records for required statutory periods);
- Security, fraud investigation, and incident response requirements;
- Applicable statutes of limitation for potential legal disputes.
17.Account Deletion and Data Deletion
Following account termination or an approved deletion request, IOBend will delete or anonymize applicable personal data within a reasonable period, subject to applicable legal, security, billing, backup, and other statutory retention requirements.
Backup and Disaster Recovery Cycles
Deleted information may remain temporarily in encrypted backups or disaster-recovery systems until those systems are rotated or overwritten in accordance with IOBend's routine backup lifecycle and retention procedures. Backup data is isolated, protected against active access, and purged as backup snapshots age out.
18.Security
IOBend implements reasonable technical and organizational measures designed to protect personal data and customer environments against unauthorized access, accidental loss, alteration, or destruction.
Data in transit is encrypted using modern TLS 1.3/1.2 protocols. Data at rest in primary datastores is encrypted with AES-256.
Principle of least privilege, multi-factor authentication for administrative access, and strict internal access auditing.
DDoS protection, automated rate limiters, web application firewalls, and regular vulnerability dependency monitoring.
Tamper-resistant security logging, automated health checks, and redundant disaster recovery systems.
While we maintain robust security controls, no internet-connected platform can guarantee absolute invulnerability. You are responsible for safeguarding your credentials, enforcing multi-factor authentication, and maintaining security hygiene within your developer workstation environments.
19.Your Privacy Rights
Subject to applicable law, you possess specific rights regarding the personal data we hold about you:
- Right to Access & Summary: You may request a summary of the personal data being processed and details about our processing activities;
- Right to Correction & Erasure: You may request the correction of inaccurate or misleading personal data and the completion of incomplete records, or request erasure of personal data that is no longer necessary;
- Right of Grievance Redressal: You have the right to register a grievance with our Privacy Contact regarding our data processing practices;
- Right to Nominate: Under Indian law, you have the right to nominate an individual who shall exercise your privacy rights in the event of death or incapacity;
- Right to Withdraw Consent: Where processing is based on your consent, you may withdraw your consent at any time without affecting the lawfulness of processing undertaken prior to withdrawal.
To exercise any of these rights, please contact us at privacy@iobend.com. We will respond to verified requests within statutory timeframes.
20.India — DPDP Framework
IOBend designs its privacy practices to address applicable obligations under India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and applicable rules notified thereunder.
Data Fiduciary & Data Processor Roles
When IOBend collects and determines the purposes for processing account information, billing details, and direct website inquiries, IOBend acts as a Data Fiduciary.
When enterprise and organizational customers configure and process developer data, environment logs, or repository assets through our B2B services, the Customer acts as the Data Fiduciary, and IOBend processes such data as a Data Processor on the Customer's behalf, governed by our Data Processing Addendum (DPA).
Notice and Consent
We provide clear, accessible notice regarding data collection and obtain valid consent where required by the DPDP framework.
Grievance Officer Contact
In compliance with Indian statutory requirements, inquiries or grievances regarding data protection under the DPDP Act may be directed to our designated Privacy Contact at privacy@iobend.com.
21.International Users / GDPR
If you access or use the Services from the European Economic Area (EEA), the United Kingdom, or other international jurisdictions, please note that your personal data may be transferred to and processed in India and other countries where our infrastructure providers operate.
Where the General Data Protection Regulation (GDPR) or UK GDPR applies to the processing of personal data, we provide contractual protections through our Data Processing Addendum (DPA), which incorporates Standard Contractual Clauses (SCCs) and appropriate technical measures for qualifying international transfers. European users may contact our privacy team for GDPR-specific inquiries.
22.Children’s Privacy
IOBend is a professional developer platform intended for engineering teams, commercial organizations, and adult developers. The Services are not directed to or intended for children under 18 years of age (or the applicable age of digital consent in your jurisdiction).
We do not knowingly collect personal data from children. If we become aware that personal data of a child has been collected without verifiable parental consent, we will take prompt steps to delete such information from our active databases.
23.Marketing Communications
We may periodically send emails regarding product releases, technical documentation, or developer events to users who have opted in to receive such communications.
You may opt out of receiving promotional and marketing emails at any time by clicking the "Unsubscribe" link included at the bottom of each marketing email or by updating your communication preferences in your account settings. Even if you opt out of promotional messages, you will continue to receive essential transactional and administrative notifications (such as password reset links, security notices, and billing receipts).
24.Changes to this Privacy Policy
We may update or modify this Privacy Policy periodically to reflect changes in our technical architecture, product features, legal requirements, or regulatory guidance.
When modifications are made, we will update the "Last Updated" and "Effective Date" at the top of this document. For material modifications that significantly affect your privacy rights, we will provide reasonable advance notice via email to registered account administrators or through prominent notices within the web console.
We encourage you to periodically review this page to stay informed about our data protection practices.
25.Contact Us
If you have questions, feedback, or grievances regarding this Privacy Policy or IOBend's data handling practices, please contact our dedicated teams:
Governing Entity: IOBend Technologies Private Limited, India.
