unlayered

Privacy Policy

Last updated 15 August 2026

Who runs this service

unlayered.cloud is run by unlayered, an independent company that owns the brand, provides the service and holds your contract.

Who is responsible for your data

unlayered provides the service and is the controller of everything described below. It is an independent company: it runs unlayered.cloud, owns the unlayered brand, and your contract for the service is with it.

What we collect, and why

Only what the panel needs in order to work. There is no tracking pixel, no advertising network and no data broker anywhere in it.

There are no web access logs. We keep no record of which pages an account visited, or when. Nothing below is a browsing history, because none is written: the list is the working data of an account, not a trail of its activity.

  • Account. Your username, the hash of your account token, an optional email address with the date it was verified, the date you registered and the time you last signed in. This is what identifies the account and lets you back into it.
  • Credits and payments. Your credit balance and a ledger of every movement on it, covering top-ups, purchases, renewals, corrections and who made them, plus the payment records our payment provider returns for each top-up: order reference, amount, currency, status and time. Needed to bill you correctly and to answer questions about a charge.
  • Servers. For virtual servers: hostname, IP address, plan, operating system template and expiry date. For dedicated orders: plan, location, price and setup fee, the address of the machine, and the credentials you need to use it, which are the out-of-band management URL and login, plus the initial root password. Needed to run, renew and hand over the server.
  • Support. Your tickets and the messages in them, on both sides, plus internal notes staff add to your account so that whoever picks up the next ticket knows the history.
  • Sign-in and security events. Each sign-in, sign-in attempt, token replacement and email verification, with the event type, a short detail, the IP address it came from and the time. Needed to spot account takeover and abuse.
  • Sessions. A hash of your session cookie with the IP address and browser user agent it was created from, and when it was created, last used and expires. This is what keeps you signed in and lets you see and revoke your own sessions.
  • Sign-in links. When you use email sign-in, a hash of the one-time link, the address it went to, its purpose and whether it has been used.
  • Notifications. In-panel notifications and, where you asked to be told when a sold-out plan comes back, the plan you are watching.

What we never ask for

Opening an account takes a username and nothing else. There is no identity check anywhere in this service, and no stage at which one appears. We do not ask for, and have nowhere to put:

  • Your legal name.
  • A home or business address.
  • A phone number.
  • An identity document, a passport, a driving licence or a photograph of you holding one.
  • A selfie, a video call or any other biometric check.
  • Proof of address, a bank statement or a utility bill.
  • A date of birth.

An email address is optional and exists for one purpose: getting you back in if you lose your token. Leave it blank and the account still works, with nothing gated behind it.

This is not the same as being anonymous to us. Be clear about the difference before you rely on it. We see the IP address and browser your sessions and sign-ins come from, we hold the reference our payment provider returns for each top-up, and the sections above and below say exactly how long each of those is kept. Where we are legally required to disclose what we hold, we do, and only what is asked for. What we cannot hand over is an identity we never collected.

None of this changes what may run on a server. The acceptable use rules in our terms apply to every account on the same terms, and an account that breaks them is suspended whether or not we know who is behind it.

Legal bases

  • Performance of a contract. Running your account, provisioning and renewing servers, taking credits, answering tickets. Without this data there is no service to provide.
  • Legitimate interest. Preventing fraud, payment abuse and account takeover, and keeping the platform and other customers safe. This covers the sign-in event log, session metadata and abuse investigations.
  • Legal obligation. Keeping payment and credit ledger records for the periods that accounting and tax law require, and responding to lawful requests from authorities.

Who it is shared with

Nothing is sold, rented or shared for advertising. Data goes to a third party only where the service cannot work otherwise:

  • Our payment provider, which creates and settles the cryptocurrency invoice for a top-up. It receives the invoice amount and reference, and we receive its confirmation.
  • Our email provider, where email is configured. It only ever carries sign-in and verification links, to the address you gave us. No marketing mail is sent.
  • The infrastructure provider whose facilities host the servers and the network they run on.
  • The platform that hosts this panel, which processes requests to it in order to serve them.

Beyond that, we disclose data only where we are legally required to, and only what is asked for.

How long it is kept

  • Account data, which covers username, email, credits, servers and tickets, is kept for as long as the account exists. Closing the account removes it, apart from what we have to keep below.
  • An account that never gets used is deleted after 30 days, along with its sign-in records. Never used means no payment, no server, no ticket, no verified email and no second sign-in: anything at all keeps the account. Open registration attracts bulk sign-ups, and the cheapest way to hold none of that data is to not keep it.
  • Payment records and the credit ledger are kept as accounting records for the retention period the applicable tax and commercial law sets, even after an account is closed.
  • Sign-in and security events are deleted automatically after 90 days.
  • Sessions expire 30 days after their last use and are deleted when they expire or when you sign out. One-time sign-in links are deleted a day after they expire.
  • A suspended server and the data on it are deleted when it is reclaimed, five days after suspension.

Security

There are no passwords in this system at all, so there are none to leak. Your account token secret and your session identifier are stored only as SHA-256 hashes, so a copy of the database cannot be replayed as a login. The session cookie is HttpOnly, so page scripts cannot read it, and it is sent over HTTPS only.

The credentials we hand over for a dedicated server are stored so that you can retrieve them in the panel. Change them once you have taken the machine over, because that is the one secret in the system we cannot hash.

Cookies

One cookie: the session cookie that keeps you signed in. It is strictly necessary, HttpOnly, and lasts as long as the session. There are no analytics cookies, no advertising cookies and no third-party cookies, which is why the panel asks you for no cookie consent.

Nothing on any page reports your visit anywhere. There is no analytics product on this site, not even a cookieless one.

Your rights

You can ask us to give you a copy of your data, correct it, export it in a portable form, or delete it and close the account. You can also object to processing we base on a legitimate interest, and ask us to restrict processing while a dispute is being sorted out.

Use any of the channels in the Contact section at the end of this page. If you write by email, use the address on the account. We answer within one month. Requests made from an account are honoured for that account only, so we may ask you to sign in rather than prove your identity another way.

If you think we have handled your data badly, you can complain to the data protection supervisory authority of your own country of residence. We would rather you told us first, but you do not have to.

International transfers

The location of each server is shown on its plan before you order it. Our payment, email and platform providers may process data outside the country you are in, in which case the transfer relies on the safeguards set out in that provider's data processing terms, which are standard contractual clauses or an equivalent mechanism. We do not transfer your data anywhere else.

Contact

These are the ways to reach unlayered.

Telegram
@unlyrd
Support tickets
Open a ticket in the panelNeeds a signed-in account.
HomeTermsRefundsImpressum

unlayered · © 2026 All Rights Reserved