Privacy Policy
Version and effective date:
This Privacy Policy explains how personal data is processed when you use the Instance Control application, account service, or Instance Control website. Support requests and files selected for Support are described separately in the Support Privacy Notice.
1. Controller and Contact
The controller responsible for Instance Control personal data is Oleksandr Beschasnyi.
For privacy questions, information about international-transfer safeguards, or requests to exercise data-protection rights, contact [email protected].
2. Personal Data Processed
Depending on the features you use, Instance Control processes:
- Account and profile data: email address, optional first and last name, optional display name, activation state, account identifiers, and account-access status.
- Plan and feature entitlement data: information about the plan or feature entitlements assigned to or calculated for an account, including whether the account has free Legacy, promotional, Provider-assigned, or other available account-connected access. This information is used to provide, limit, or change access to account-connected features.
- Authentication data: a password hash rather than the plaintext password; passkey public-key credential data where you add a passkey; session identifiers, hashed session credentials, expiry, and revocation state.
- Legal evidence: the exact Terms version accepted, Privacy Policy version acknowledged, server-generated time, and whether the action occurred during registration or a later legal review.
- Device data: device identifier and display name, platform, application version, device kind, public signing and transfer keys and fingerprints, registration time, last-seen time, and revocation state.
- Runtime summaries: the device and IDE-instance status that you synchronize to the account service, including display labels, available action identifiers, timestamps, and operation state.
- Security data: authentication method, security-event type and outcome, risk reasons, related device or session identifier, coarse IP prefix, ASN and country where available, User-Agent, and timestamps.
- Approximate alert context: country and city labels supplied by the trusted network proxy where available and used to make a sign-in alert understandable.
- Transfer and action data: selected source and target device identifiers, action or transfer state, expiry, acknowledgements, integrity information, and encrypted transfer payloads where you initiate a remote transfer.
- Website and network request data: source IP address processed in transit, request time, requested path, browser or User-Agent information, protocol and header information, and security signals needed to deliver and protect the website and official Instance Control artifacts made available there. Cloudflare processes this information at the network edge. The Instance Control website does not load audience-analytics or application error-reporting scripts. Cloudflare may nevertheless receive network, security, and service information for proxied traffic, including browser-generated network error reports used to diagnose delivery failures.
- Website visual settings: a random seed and timing values stored in your browser's local storage to keep the animated background consistent. These values remain on the device, are not account identifiers, and can be removed by clearing the website's stored data. The Instance Control page does not set advertising or analytics cookies.
- Email delivery and correspondence data: the account email address, message type, subject, message content, delivery state, and provider response identifiers for activation, sign-in confirmation, recovery, and security messages; and the sender address, subject, content, timestamps, and attachments you choose to include when contacting the privacy or complaint address.
- Telegram integration data: when the optional integration is connected, Telegram user and chat identifiers, public account information supplied by Telegram, supported commands and button callbacks sent to the Instance Control bot, limited project or action identifiers, requested Start, Stop, or Restart action, action state and result, outbound notification content, timestamps, and delivery state.
- Webex integration data: when the optional bot integration is used, the Instance Control profile email and the Webex person, direct-room, and message identifiers needed to authenticate and route the interaction; supported slash-command text; limited Device and project selectors; confirmation and action state; bot replies; and selected lifecycle or security notification text. Instance Control retains only bounded security, selection, action, and delivery state. It does not retain Webex response bodies or outbound provider message identifiers.
- User-initiated external request data: ordinary HTTPS and network information sent directly from your device when you request a supported third-party Java runtime or browser-driver download, or open a Guidewire Cloud page and its organization-selected sign-in service. These direct requests do not include Instance Control account profile data or project content.
3. Sources, Purposes, and Legal Bases
Data comes from information you enter, devices and optional services you connect, features you invoke, and request context supplied by the application, operating system, network connection, and trusted reverse proxy. Privacy acknowledgement records review of this notice; it is not consent for unrelated processing.
Website delivery and protection
Main data: website and network request data. Purpose: deliver static pages and official artifacts, maintain availability, and detect abusive or malicious traffic. Legal basis: Article 6(1)(f) GDPR. The legitimate interests are providing a reliable public website, protecting it from abuse, and maintaining network and service security. Retention: the origin application does not intentionally create a per-request access log for ordinary static page requests; external service retention is described in Sections 6 to 8.
Account registration, activation, authentication, and sessions
Main data: account, credential, activation, session, device, plan and feature entitlement, and basic security data. Purpose: create and activate an account, authenticate the user, maintain sessions, provide account access, and manage account-connected features and feature availability. Legal basis: Article 6(1)(b) GDPR, to take steps requested before entering into the Terms and to perform the resulting contract. Retention: see the account, pending-registration, and session periods in Section 8.
Registered devices, runtime summaries, remote actions, and encrypted transfers
Main data: device identity and keys, limited synchronized runtime state, action state, transfer routing information, integrity information, and ciphertext. Purpose: provide the device, remote-action, and project-transfer features selected by the user. Legal basis: Article 6(1)(b) GDPR. Retention: device records remain with the account unless removed earlier; action and transfer periods are described in Section 8.
Optional Telegram and Webex integrations
Main data: the Telegram or Webex data listed in Section 2. Purpose: authenticate supported bot interactions, present limited account-device state, route allowlisted remote actions for local revalidation, and provide the notification features requested by the user. Legal basis: Article 6(1)(b) GDPR. Connecting or using an optional service is a product choice, not consent for unrelated marketing or analytics. Retention: Instance Control keeps only the binding, security, selection, action, notification, and delivery information required for the connected feature; specific Webex command-state periods are listed in Section 8. The external service may retain data under its own rules.
Sign-in protection, abuse prevention, security history, and reliability
Main data: coarse IP prefix, ASN and country where available, User-Agent, device and session context, risk reasons, event outcome, and timestamps. Purpose: detect unauthorized access, require additional confirmation when appropriate, enforce rate limits, investigate security events, protect remote-action integrity, and diagnose failures. Legal basis: Article 6(1)(f) GDPR. The legitimate interests are protecting accounts from unauthorized access, preventing abuse, maintaining service security and reliability, and preserving the integrity of requested remote actions. Retention: pending sign-ins, sessions, and security events follow the separate periods in Section 8.
Legal-document evidence, legal compliance, and claims
Main data: exact document version, action, account identifier, source, and server time, together with other records relevant to a specific obligation or claim. Purpose: show which document version the user reviewed, administer the contract, comply with a specific legal obligation where one applies, and establish, exercise, or defend legal claims. Legal basis: Article 6(1)(b) GDPR; Article 6(1)(c) GDPR only where a specific legal obligation applies; and Article 6(1)(f) GDPR for the legitimate interest in maintaining reliable evidence and handling legal claims. Retention: legal history remains with the account under the current account-deletion behavior.
Support processing is covered by the separate Support Privacy Notice.
4. Approximate Security Context, Not Precise Location
Instance Control does not use macOS Core Location for account security, does not request location permission, and does not receive GPS coordinates through this flow. The service derives only approximate request context from the network: a coarse IP prefix and, when the trusted proxy provides them, ASN, country, and city labels.
Country and ASN may be stored with sessions, pending sign-ins, and security events to detect an unusual network or approximate sign-in location. A city label may be included in the immediate security notification but is not stored in session, pending-sign-in, or security-event records. Network-derived labels can be missing or inaccurate and are not proof of a person's physical location.
5. Local and Server Processing
Most project operations run on the selected device. Account features send only the data required for the chosen account, device, action, notification, or transfer workflow. Instance Control does not automatically upload an entire project to the account service merely because the project appears in the local application.
When you initiate a project transfer, the relay stores the encrypted payload and the limited information needed to route, verify, expire, and acknowledge the transfer. The relay is not intended to receive readable project content. The receiving device verifies and decrypts the transfer before applying it.
6. Service Providers and Recipients
Controller-operated systems
The account database, account service, and encrypted-transfer storage are operated directly by the controller. They are not treated as a separate external recipient. Local system notifications remain an operating-system feature on the device and do not by themselves send a message to an external notification service.
The controller operates the account service, account data store, encrypted-transfer storage, website origin, official artifacts served from the website, and service logs. Encrypted transfer payloads and their routing and integrity information remain on those systems until acknowledgement or expiry. The current deployment does not use a separate hosting, database, storage, monitoring, or application error-reporting provider.
Processors supporting Instance Control
- Cloudflare provides the reverse proxy and Tunnel that carry HTTPS traffic for the public website and account-service routes to the controller-operated origins. Cloudflare processes source IP addresses, request paths, protocol and header information, network-security signals, and browser-generated network error reports as a processor under its Data Processing Addendum.
- Resend (Plus Five Five, Inc.) delivers account activation, sign-in confirmation, recovery, and security email. It receives the recipient email address, message content and type, and delivery metadata as a processor under the Resend Data Processing Addendum.
User-enabled external services
- Telegram: Telegram is an independent external service for its platform, and the integration is optional and user-enabled. When a user connects Telegram with Instance Control, Telegram may receive the limited request, supported command, callback, action status or result, and notification information needed to provide the configured remote-operation and notification features. Remote operations are limited to the allowlisted Start, Stop, and Restart actions; the integration does not provide arbitrary command execution, upload an entire project, send AI conversation bodies, or request unrelated conversation content. Telegram processes the interaction under its own Privacy Policy and Bot Platform Terms. Disconnecting the integration prevents new Instance Control bot operations through that binding but does not control Telegram's own retention.
- Cisco Webex App Messaging: the optional integration uses a Webex bot for authenticated direct-room slash commands and for selected lifecycle and security notifications to the Instance Control account profile email. Supported commands can show limited account-device state or request only the allowlisted Refresh, Start, Stop, and Restart operations. Stop and Restart require a short-lived confirmation, and the selected Device revalidates the exact local target and current capability before acting. The integration does not provide arbitrary command execution or read unrelated Webex conversation content. Disabling Webex notifications prevents new configured notifications but does not remove messages or other records retained by Cisco.
- User-initiated downloads: official Instance Control artifacts made available on the website are served from the controller-operated origin through Cloudflare and are covered by the website and network request disclosure. When a user asks the application to obtain a third-party Java runtime or browser driver, the device contacts the selected public download host directly. That host receives ordinary HTTPS and network information; Instance Control does not add account profile data or project content to the request. These direct connections are not recipients to which the Instance Control account service sends personal data.
- Guidewire and organization-selected sign-in services: when you open a configured Guidewire Cloud or APD page, the device connects directly to Guidewire and may follow the organization's sign-in flow through Okta or Microsoft. Those providers process the browser request, cookies, and sign-in data under the user's or user's organization's relationship with them, not as Instance Control processors.
Correspondence service
Instance Control may use the contact address published for legal, support, and complaint communication. Apple processes email delivery and mailbox data under its own privacy terms. Apple iCloud Mail is not application infrastructure and is not required for account functionality. Files submitted through the separate Support workflow remain covered by the Support Privacy Notice.
User-selected devices
A selected device may receive limited synchronized state, remote-action requests or results, and encrypted project-transfer data. A device under the user's control is separate from an external service provider or legal recipient.
Legal and professional recipients
Relevant data may be disclosed to public authorities, courts, legal advisers, or other necessary parties where required by law or where supported by a valid basis for the establishment, exercise, or defence of legal claims.
7. International Transfers
The controller-operated origins do not use an external hosting or storage provider. Cloudflare and Resend may process personal data outside the European Economic Area under the provider-specific safeguards identified below. Optional external services may also process data in other countries under their own terms and privacy documentation when a user enables or contacts them.
- Cloudflare — website and account-service network delivery. Role: processor. Data: IP address, request path, headers, protocol information, network-security signals, and browser-generated network error reports. Processing locations: Cloudflare's global network, including processing in the United States and other countries when needed to provide the service. Transfer safeguard: Cloudflare's Data Processing Addendum states that transfers to the United States rely on the EU-U.S. Data Privacy Framework and that other restricted transfers rely on the European Commission's Standard Contractual Clauses. Further information: Cloudflare Privacy Policy and Data Processing Addendum.
- Resend — transactional account and security email. Role: processor. Data: recipient email address, message content and type, and delivery metadata. Processing locations: the configured sending domain routes outgoing email through Resend's Ireland region. Resend states that account data, including email metadata, logs, and API records, is stored in the United States regardless of the sending region. Transfer safeguard: Module Two of the European Commission's Standard Contractual Clauses under the Resend Data Processing Addendum. Further information: Resend Data Processing Addendum, subprocessor list, and data-residency guidance.
- Telegram — optional remote operations and notifications. Role: optional user-enabled external service and controller for its platform; Instance Control remains responsible for the bot data it receives and uses. Data: Telegram account and chat identifiers, public account data, supported commands, callbacks, limited action information, results, and notification content. Telegram processes this information under its own Privacy Policy and Bot Platform Terms, which describe its processing and international-transfer practices.
- Cisco Webex App Messaging — optional remote operations and notifications. Role: user-enabled external service. Data: the Instance Control profile email; Webex person, direct-room, and message identifiers; supported slash commands; limited Device, project, confirmation, action, result, and reply information; and selected lifecycle or security notification text. Webex processes this information under Cisco's applicable service terms and privacy documentation. Instance Control accepts only authenticated direct-room commands from an allowlisted Webex identity whose provider-supplied email matches an Instance Control account; it does not accept arbitrary commands or retrieve unrelated conversation content. Further information: Webex App and Messaging privacy data sheet and Cisco General Privacy Disclosure.
- Apple iCloud Mail — legal, support, and complaint correspondence. Role: independent email and mailbox service. Data: sender and recipient addresses, subject, message content, timestamps, and attachments you choose to send. Apple processes email delivery and mailbox data under its own Privacy Policy, which describes its processing and international-transfer practices. Apple iCloud Mail is not part of Instance Control application infrastructure.
- Guidewire Cloud and organization-selected Okta or Microsoft sign-in. Role: user-selected enterprise services, not Instance Control processors. Data: browser request, cookies, and the sign-in information provided directly to those services. Processing locations and safeguards: determined by the user's organization and its service configuration and agreements. Further information: Guidewire Privacy Policy, Okta Privacy Policy, and Microsoft Privacy Statement.
Contact [email protected] to request further information or a copy of an applicable safeguard where it can be provided without disclosing confidential terms.
8. Retention
Account, profile, device, passkey, and legal history
Account, profile, legal-history, passkey, and device records are retained while the account exists unless the relevant feature removes them earlier. Revocation makes a credential or device unusable but may preserve its record for account security history. Deleting the account removes its associated records from the active account service under the current implementation.
Pending registration
An uncompleted registration remains usable only until its activation deadline. Expired pending registrations are removed. After successful activation, sensitive pending fields are removed after the account is activated and the accepted document versions are recorded.
Sessions
Access credentials expire after 15 minutes and refresh credentials after no more than 30 days. Expired sessions are removed during scheduled cleanup. Revoked session rows are retained for up to 30 days so they can be shown and audited, then deleted.
Security events
Security events are stored for at most 90 days and are limited to 1,000 events per account. Events older than 90 days or exceeding that account limit are deleted during scheduled cleanup.
Pending sign-in decisions
A sign-in code expires after 10 minutes, and the pending authorization expires after 30 minutes. Expired pending sign-in records are removed during scheduled cleanup while the service is running, or at the next service startup following downtime.
The separately stored security-event history does not retain the sign-in code or applicant secret and follows the security-event period above.
Encrypted transfer payloads
Prepared ciphertext is retained for no more than 24 hours and is removed after acknowledgement or expiry.
Webex command state
Replay protection retains only a hash of an incoming provider event identifier for up to seven days. The selected-Device record is keyed by a hash of the Webex person and direct room and is retained for up to 30 days after selection. A pending Stop or Restart confirmation is retained for no more than 90 seconds and stores only the bounded target and state needed for exact revalidation. A queued action can be delivered for no more than five minutes. Its bounded action record, including the incoming message and room identifiers needed to prevent duplicate routing and send a safe completion reply, remains with the account Device under the current implementation and is removed when that Device or account is removed.
Website settings and external services
The website's visual-background values remain in browser local storage until the user clears site data. External services may retain their own operational, backup, or residual records under their applicable policies and account settings.
Support
Support messages, selected files, delivery records, and their separate retention limitations are described in the Support Privacy Notice.
9. Required and Optional Data
An email address, authentication credential, required legal-document evidence, and basic security context are required to create and protect an account. Normal network request processing is required to load the website. Names, display names, passkeys, additional devices, Telegram, Webex, and Support files are optional. If required data is not provided, the corresponding account or website feature cannot operate. This necessity is not consent.
10. Automated Security Processing
Automated checks compare device and approximate network context, apply rate limits, validate signatures and credentials, and may require an additional sign-in confirmation or reject an invalid request. These checks protect the account and do not use GPS data. They do not make decisions based solely on automated processing that produce legal or similarly significant effects within the meaning of Article 22 GDPR.
11. Your Rights
Subject to applicable law, you may request access, correction, deletion, restriction, or portability of your personal data. You may also complain to the supervisory authority in your country. In Poland, information is available from the President of the Personal Data Protection Office.
Privacy Policy acknowledgement records that the current notice was presented; it is not blanket consent. Where processing does not rely on consent, there is no consent to withdraw. You can disconnect Telegram, disable Webex notifications, and remove a connected Device using the available settings. A Webex remote action occurs only after you send a supported direct-room command and, where required, its confirmation; opening, reading, or copying a bot message is not an action request.
12. Right to Object
Where Instance Control relies on legitimate interests, you may object on grounds relating to your particular situation. This may apply, for example, to certain account-security, abuse-prevention, reliability, or website-security processing. Contact [email protected] to submit an objection.
Instance Control will stop the relevant processing unless there are compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is required for the establishment, exercise, or defence of legal claims. This right does not turn processing required for the contract or a legal obligation into consent-based processing.
13. Security
Instance Control uses password hashing, short-lived access credentials, hashed stored session credentials, passkey public-key authentication, device signatures, encrypted transfer payloads, rate limits, and account security-event controls. No method eliminates all risk; protect your email account, device login, credentials, and connected-service accounts.
14. Changes to This Policy
This Policy may be updated, and each current version has an explicit identifier. A material update is presented in the application for review before a new acknowledgement is recorded. Opening, copying, or dismissing the document does not acknowledge it. Terms acceptance and each Privacy acknowledgement remain separate legal-history events and are not overwritten.
If personal data will be used for a materially different purpose, the updated information will be provided before that processing begins. Acknowledgement of an updated notice is not blanket consent; where consent is the actual legal basis, it will be requested separately for that specific purpose.