Effective date: 17 July 2026
NUSAPOD is self-hosted GPU infrastructure software: it runs entirely on your own servers. This policy explains what data the software processes on your infrastructure, the minimal telemetry it sends to us, and what this website collects.
Data that stays on your infrastructure
The NUSAPOD control plane stores the following only on your own cluster — Nusapod has no access to it:
- Console user accounts: username, role, and a bcrypt password hash. No email address or personal profile is collected.
- Audit log entries: username, action, target, source IP address, and timestamp.
- API keys, stored as SHA-256 hashes. The plaintext key is shown once at creation and never stored.
- Usage accounting: request and token counts per API key and deployment.
Inference content is never stored. Prompts and completions passing through the model gateway are proxied to your model runtime and discarded; only token counts are recorded for rate limiting and usage reporting.
License telemetry (phone-home)
A licensed installation periodically contacts our license service to validate its license. The request contains exactly: the license token (which identifies your organization name, license ID, tier, and expiry), the software version, the number of connected nodes, and the number of GPUs. It contains no hostnames, hardware identifiers, usernames, or workload data. Our license service records the license ID, last-seen time, node/GPU counts, and version. The connecting IP address is used transiently for rate limiting and is not stored in our database.
This website
nusapod.app is a static site served through a reputable, industry-standard cloud infrastructure provider. We do not run advertising or third-party analytics trackers. The hosting provider processes standard connection logs (IP address, user agent) solely to serve and protect the site. If you email us, we keep the correspondence for as long as needed to handle your request.
Retention
- License records: for the duration of the license relationship and up to 24 months after expiry.
- Email correspondence: up to 24 months after the matter is closed.
- Data on your own cluster: under your control; you can delete users, keys, and audit data at any time.
Your rights
Under Indonesian Law No. 27 of 2022 on Personal Data Protection (UU PDP), you may request access to, correction of, or deletion of personal data we hold (in practice: your license contact details and correspondence). Contact us at hello@nusapod.app — we respond within the timelines required by the law.
Changes
We will post any changes to this policy on this page with an updated effective date.
