Zuvio Atlas is a server monitoring service. This policy explains exactly what we collect, why, how long we keep it, and who else touches it.
Effective 21 July 2026
Zuvio Atlas (“Atlas”, “we”, “us”) is operated by Zuvio Systems, based in Nairobi, Kenya. Atlas is available at atlas.zuviosystems.com.
For any privacy question, or to exercise any right described in this policy, contact admin@zuviosystems.com. We are the data controller for account data, and a data processor for the telemetry you send us about your own servers.
Account identity
When you sign in with Google or GitHub, we receive your name, email address, and profile picture. We request only the minimum identity scopes needed to create your account — for Google, these are openid, email, and profile. We do not request access to your Gmail, Drive, Calendar, Contacts, or any other Google service, and we cannot read them.
Server telemetry
If you install the Atlas agent on a server, it sends us operational metrics roughly every 60 seconds. This is the core of the service. It includes:
Command lines and log lines can incidentally contain sensitive values if your own scripts place secrets there. Atlas stores what the agent reports; it does not attempt to redact this. Avoid passing secrets as command-line arguments on monitored hosts.
Monitoring configuration
The URLs, domains, IP addresses, and hostnames you ask us to monitor, plus the destinations you configure for alerts — email addresses, phone numbers, and webhook URLs for Slack, Discord, Telegram, PagerDuty, or Opsgenie.
Billing
Plan tier, billing cycle, and subscription status. Card details are handled entirely by our payment processor — we never see or store card numbers.
Product and website analytics
Our marketing pages and the signed-in dashboard use Google Analytics, so we can see which features are actually used and where people get stuck. It records page views, approximate location, and browser type.
Because dashboard page addresses include identifiers — for example /dashboard/servers/<id> — those identifiers are part of the page address Google Analytics receives. It does not receive your metrics, logs, alert contents, or any server hostname or IP.
Analytics is never loaded on public status pages. Those pages are yours, shown to your customers, and we do not track visitors there.
What we do not collect
We do not use advertising trackers, we do not sell data, and we do not build advertising profiles.
Atlas’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely, the name, email address, and profile picture we receive from Google are:
You can revoke Atlas’s access at any time from your Google Account permissions page. Revoking access does not delete your Atlas account — to do that, see section 7.
We process the data above only to:
Our legal bases, where GDPR applies, are performance of a contract (running the service), legitimate interests (security, fault diagnosis, service improvement), and legal obligation (tax and accounting records).
Telemetry is aggressively aged down. Raw, full-granularity data has a short life; only coarse averages persist long-term.
| Data | Retention |
|---|---|
| Raw metrics (full granularity) | 7 days |
| Hourly metric averages | 90 days |
| Daily metric averages | 13 months |
| Job run history | 30 days by default, configurable per monitor |
| Synthetic check results | 7 days |
| Status page view counts | 90 days |
| Incidents and alert history | Life of the account |
| Account and billing records | Life of the account, then as tax law requires |
You can, at any time:
Depending on where you live, you may also have rights to object to or restrict processing, to data portability, or to lodge a complaint with a supervisory authority — in Kenya, the Office of the Data Protection Commissioner. Email admin@zuviosystems.com and we will respond within 30 days.
No system is perfectly secure. If you believe you have found a vulnerability, please report it to admin@zuviosystems.com rather than disclosing it publicly.
Atlas is a tool for operating server infrastructure and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child has provided us data, contact us and we will delete it.
If we make a material change, we will update the effective date above and notify account owners by email before it takes effect. Continued use after that constitutes acceptance.
See also our Terms of Service.