1. Who we are
DeployKraken ("we", "us") provides build-to-store automation for game studios: we ingest game builds from connected build systems, package them, and deploy them to digital storefronts on your instruction. This policy explains what personal data we process when you use DeployKraken, why, and what rights you have. For privacy questions, contact us at privacy@deploykraken.app.
2. Data we collect
Account and workspace data
- Account details - name, email address, and password (stored hashed) for every user of a studio workspace.
- Workspace details - studio/company name, workspace subdomain, and any custom domains you connect.
- Billing data - subscription plan, billing address, and payment status. Card details are collected and processed directly by our payment provider (Stripe); we never see or store full card numbers.
Service content
- Build artifacts and packages - the game builds we ingest from your build system and the packaged deliverables we produce from them. These are your content; we store and process them solely to provide the service.
- Integration credentials - API keys and store credentials you connect (e.g. Unity Build Automation API keys, itch.io butler keys, Steam builder account credentials and Steam Guard secrets). These are encrypted at rest and decrypted only inside the deploy jobs that need them. We never write them to logs.
- Operational logs - deploy run logs, build metadata, version numbers, and store build identifiers, retained so you have an audit trail of what shipped where.
Technical data
- Standard server logs (IP address, user agent, timestamps) for security and reliability.
- Session cookies required to keep you signed in. We do not use third-party advertising or tracking cookies.
3. Why we process it
- To provide the service (contract): operating your workspace, ingesting builds, packaging, deploying, and showing logs.
- To bill you (contract / legal obligation): subscription management and invoicing.
- To keep the service secure (legitimate interest): abuse prevention, access logging, encryption of credentials.
- To communicate with you (contract / legitimate interest): transactional emails such as account, billing, and deploy notifications. We do not send marketing email without your consent.
4. Where your data lives
Each studio workspace runs in its own isolated database. Build artifacts and packaged deliverables are stored per workspace. Backups of workspace databases are created automatically and retained on infrastructure we control or contract.
5. Who we share data with
We share personal data only with the processors needed to run DeployKraken:
- Hosting and infrastructure providers - run our servers, databases, and backups.
- Stripe - payment processing and subscription billing.
- Email delivery provider - transactional email.
When you connect third-party integrations (Unity Build Automation, itch.io, Steam), we transmit data to those platforms on your instruction - for example uploading a build to your Steam depot. Their handling of that data is governed by their own terms and privacy policies. We never sell personal data.
6. Retention
- Account and workspace data: for the life of the workspace, then deleted with it.
- Build artifacts, deliverables, and deploy logs: until you delete them or your workspace is deleted, subject to your plan's storage limits.
- Billing records: as long as required by tax and accounting law.
- Server logs: up to 90 days.
When a workspace is deleted, its database, stored builds, and integration credentials are deleted; residual copies in backups expire with the backup rotation.
7. Security
All traffic is encrypted in transit (TLS). Integration credentials and Steam Guard secrets are encrypted at rest and decrypted only at the moment a job needs them; they are never included in logs or error reports. Access to production systems is restricted and audited.
8. Your rights
Depending on where you live (e.g. under the GDPR), you may have the right to access, correct, export, restrict, or delete your personal data, and to object to certain processing. Workspace owners can delete users and the workspace itself from within the product; for anything else, email privacy@deploykraken.app. You also have the right to lodge a complaint with your supervisory authority.
9. Changes to this policy
We may update this policy as the service evolves. Material changes will be announced by email or in-product notice before they take effect. The "last updated" date above always reflects the current version.