Introduction
Corebyte Solutions LLC ("Corebyte", "we", "us", or "our") is a Wyoming limited liability company that operates Servbyte, a software-as-a-service platform for server monitoring and AI-assisted incident diagnostics. This Privacy Policy explains what information we collect, how we use it, how long we keep it, and the choices you have.
This policy applies to the servbyte.io website, the Servbyte dashboard and APIs, and the Servbyte monitoring agent installed on your servers (collectively, the "Service"). By creating an account, installing the agent, or otherwise using the Service, you acknowledge that you have read this policy and agree to the practices described in it. If you do not agree, please do not use the Service.
The Service is intended for use by professionals aged 18 or older. Accounts are secured with an email address and a password of your choosing.
Account Data
When you register a workspace or are invited to one, we collect the information required to create, secure, and administer your account:
- Full name
- Email address (used as your sign-in identifier)
- Password, stored only as a salted cryptographic hash — we never store or transmit your password in plain text
- Workspace name
- Team member email addresses
- Assigned role for each team member (owner, admin, or member)
- Notification preferences and timezone
Account records are kept for the life of your account and removed within 30 days after account deletion, subject to the legal and tax exceptions described in Section 06.
Billing Data
Payment processing is handled entirely by Stripe, Inc., a PCI DSS Level 1 certified provider. Card details are submitted directly from your browser to Stripe. Corebyte never receives or stores full card numbers, CVV codes, or bank account numbers.
The billing metadata we do store includes:
- Card brand and the last four digits of your card
- Billing name and billing address
- Selected plan, billing cycle, and payment history
- Stripe customer ID and subscription ID
This metadata is used to display invoices, reconcile payments, provide receipts, and meet our tax and accounting obligations.
Server & Monitoring Data
The Servbyte agent runs as an unprivileged process on the hosts you choose to monitor and transmits a limited set of operational telemetry to Servbyte over TLS. Specifically, the agent collects:
- System metrics — CPU utilization, memory use, disk I/O and capacity, network throughput, load average, and swap activity
- Process information — top processes by CPU and memory, aggregate process counts, and basic process state
- Service health — status checks for services such as nginx, PostgreSQL, and Docker, plus TCP port and HTTP endpoint probes you configure
- System metadata — hostname, operating system and version, kernel version, uptime, and agent version
- Scoped log snippets — short, contextually relevant excerpts of log output captured only when AI diagnostics are triggered for an incident. Servbyte does not continuously stream or ingest your full log files.
- SSL/TLS certificate metadata — issuer, subject, validity window, and fingerprint for certificates you ask Servbyte to monitor
What Servbyte does NOT collect
- The contents of your application databases
- End-user data flowing through your applications
- Environment variables, secrets, or API keys
- SSH keys or credentials of any kind
- Source code or full file contents from your servers
- Personal data belonging to your end-users or customers
How We Use Your Data
We use the information we collect for the following purposes:
- Service delivery — running your monitoring workspace, ingesting agent telemetry, rendering dashboards, and delivering alerts
- Anomaly detection — computing baselines and thresholds against your own telemetry to surface unusual behavior
- AI-assisted diagnostics — generating assistive incident summaries and probable-cause analysis when you trigger diagnostics for an incident
- Billing and account management — invoicing, subscription changes, receipts, and support
- Product improvement — aggregated and anonymized usage patterns to inform product decisions
- Communications — transactional messages (security notices, billing, incident notifications) and optional product updates. You may opt out of non-essential messages at any time.
- Legal compliance — meeting our obligations under applicable law and responding to lawful requests
AI model boundary
We do not use customer telemetry to train general-purpose AI models. AI diagnostics run per-account in isolation and are never shared across accounts. Diagnostic outputs are assistive and are not a substitute for engineering judgment.
Data Retention
We retain data only as long as necessary for the purposes described in this policy or as required by law.
| Data category | Retention |
|---|---|
| Account information | Life of account + 30 days after deletion |
| Billing records | Retained for applicable tax and legal periods |
| Server telemetry | Hobby 7 days · Pro 30 days · Team 90 days (rolling) |
| Incident reports & AI summaries | Same window as the underlying telemetry plan |
| Support tickets | 2 years after resolution |
| Audit logs | 1 year |
When you delete your account, permanent deletion of associated data begins within 30 days, except for records we are required to retain for tax, accounting, fraud prevention, or other legal reasons.
Security Practices
Security is central to how Servbyte is built and operated. Our program includes:
- Encryption in transit — all traffic between the agent, the dashboard, our APIs, and your browser is encrypted with TLS 1.2 or higher
- Encryption at rest — stored data is encrypted at rest using AES-256
- Access control — multi-factor authentication and least-privilege access controls for production systems, with access limited to authorized personnel
- Tenant isolation — customer workspaces are logically isolated so one account cannot access another account's data
- Ongoing review — periodic security reviews, dependency scanning, and infrastructure hardening
- Breach notification — in the event of a personal data breach affecting your account, we will notify affected customers within 72 hours of confirmation
No system is perfectly secure. We work continuously to reduce risk and encourage responsible disclosure of any suspected vulnerability to contact@servbyte.io .
Third-Party Sub-processors
To deliver the Service, Servbyte uses a small number of carefully chosen sub-processors. Each sub-processor is bound by contractual data-protection obligations.
| Provider | Purpose | Data shared |
|---|---|---|
| Stripe | Payment processing | Billing information and payment method |
| Hetzner / AWS | Cloud infrastructure and hosting | All service data (encrypted) |
| Postmark | Transactional email delivery | Email address, alert and notification content |
| OpenAI | AI diagnostics engine | Anonymized telemetry snippets, only when diagnostics are triggered |
| Plausible Analytics | Website analytics | Anonymous page views, no cookies, no PII |
We do not sell, rent, or trade your data to any third party for advertising or marketing purposes.
Your Rights
Depending on where you live, you may have some or all of the following rights with respect to your personal data:
- Access the personal data we hold about you
- Correct inaccurate or incomplete information
- Delete your personal data
- Portability — receive an export of your data in a machine-readable format (JSON or CSV)
- Restrict or object to certain processing
- Withdraw consent where processing is based on consent
You can exercise any of these rights by emailing contact@servbyte.io. We aim to respond within 30 days. Account and telemetry exports are also available directly inside the Servbyte dashboard.
Children's Privacy
Servbyte is a professional tool and is not directed at individuals under the age of 18. We do not knowingly collect personal data from anyone under 18. If we learn that we have collected such information, we will delete it. If you believe a minor has provided personal data to us, please contact contact@servbyte.io.
International Data Transfers
Servbyte is operated from the United States. If you access the Service from outside the United States, your information may be transferred to, processed in, and stored in the United States or in other countries where our sub-processors operate. Where required, we rely on appropriate contractual and technical safeguards to protect data during cross-border transfers.
Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify workspace owners by email or by posting a prominent notice inside the Servbyte dashboard at least 14 days before the changes take effect. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
Contact Information
For privacy questions, data requests, or any other matter covered by this policy, please contact us:
Corebyte Solutions LLC
30 N Gould St Ste R, Sheridan, WY 82801, United States
Email: contact@servbyte.io
Phone: +1 (307) 449-2093
