Security, privacy and compliance, written down.
How we protect accounts, servers and the network; where data lives and for how long; which certifications apply and which are in progress. Everything here is also in the legal documents it summarises.
Controls you can check against the policy.
Where it lives, how long it stays.
| Data | Where | Retention |
|---|---|---|
| Server disks and snapshots | NVMe in the region you chose | Deleted within 30 days of termination |
| Account, billing, support | India, encrypted backups in Singapore | Profile deleted within 30 days of closure; invoices 8 years (tax law); tickets 3 years |
| Login and API logs | India | 90 days |
| Server telemetry | Region of the server | Live 5 min; series 15 min; daily aggregates 13 months |
| Flow records | Border routers | 30 days |
| Payment data | Razorpay, PayPal, card processor, BTCPay | Joy receives reference, amount, method, last four digits only |
Delegated to processors
Razorpay, PayPal, the card processor and BTCPay hold PCI scope. Joy never receives or stores full card numbers.
IN PLACEIn progress
Formal certification is under way. Security questionnaires and architecture walkthroughs are available now through Sales.
IN PROGRESSValid requests only
Customer data is disclosed only on a valid legal request under the laws of the country where the data is held; affected customers are notified unless prohibited.
Three, all first-party
A session cookie on login, a currency cookie, a theme preference in local storage. No analytics or advertising cookies.
Report
Email support@joycloud.services with reproduction steps.
Acknowledged in 48 hours
A human confirms receipt and severity.
Fixed and credited
Confirmed issues are fixed promptly; researchers get public credit or wallet credit.