Sidebox

Data handling

Last updated 30 September 2026

What is stored

Sidebox stores account records, projects and their links, validated brand values, private asset metadata and bytes, provider credentials, bounded provider snapshots, activity, and billing entitlement metadata needed to operate the workspace.

Provider credentials are encrypted. Provider snapshots are read-only and minimized to fields required by shipped features. Payment snapshots do not include customer personal information from Stripe or Polar.

Retention

Workspace data is retained while the account exists. On confirmed account deletion, account-owned database rows are hard-deleted. Private object cleanup is queued in a deletion manifest and retried by a scheduled job every three hours. Cleanup can remain pending while retries continue.

Operational billing event metadata may be retained for idempotency and support operations without webhook payloads or payment personal data.

Deletion and backup restoration

Deleting an account terminates its billing customer before local deletion; if provider termination fails, local deletion is aborted. Private objects are deleted asynchronously after the account row is gone.

A separate opaque deletion ledger is used by the restore reconciliation process so accounts deleted after a backup was taken can be deleted again after restoration. The ledger contains no email or other direct personal information.

Export and downloads

Individual private assets can be downloaded from their project or the workspace Library. There is no self-service bulk export. Contact contact@sidebox.dev for personal data requests under applicable law.

Subprocessors and connected providers

Infrastructure and service processing includes Cloudflare, Neon, Polar, transactional email providers, Sentry for scrubbed web-app error reports, PostHog for consent-based product analytics, and the provider services you connect: GitHub, Vercel, Google Search Console, PostHog, and Stripe. Connected providers receive authorization only when you choose to connect them.

Contact support · contact@sidebox.dev