Privacy Policy

Privacy Policy

Last updated August 28, 2026. This Privacy Policy describes how INSTANT LTD ("INSTANT LTD," "we," "us," or "our") collects, uses, shares, and protects personal information when you use Instant Cloud, a product of INSTANT LTD, at https://instant.rw and related services (the "Services").

By using the Services, you acknowledge this Privacy Policy. For contractual terms governing the platform, see our Terms & Conditions.

1. Information we collect

We collect personal information and non-personal information to operate and improve the Services.

1.1 Information you provide

  • Account information: name, email address, optional phone number, avatar/profile image, and related profile fields when you register or update your account.
  • Authentication: sign-in via GitHub OAuth or email one-time passcode. We do not use password-based accounts.
  • Organization and billing: organization names, membership/invites, credit top-up records, ledger entries, and receipts.
  • Communications: support requests, contact forms, and product feedback you send us (including in-app feedback).
  • Configuration you store with us: application settings, environment variables and secrets, domain settings, and related deployment configuration.

1.2 Information from integrations and automatic collection

  • GitHub: when you connect GitHub for sign-in or deployments, we receive profile identifiers and, for installed repositories, repository metadata needed to list repos, clone for builds, and process webhooks (for example repository name, branch, and commit SHA). We do not keep a durable mirror of your full source tree in the control-plane database; source is cloned ephemerally on build workers and resulting images may be stored in our private registry.
  • Usage and log data: IP address, user agent, session identifiers, API and dashboard activity, build and deployment logs, resource lifecycle events, and timestamps.
  • Cookies and similar technologies: session cookies and similar identifiers to keep you signed in, secure the Services, and understand product usage. You can control cookies through your browser; disabling session cookies will prevent sign-in.
  • Payment confirmation: when you top up credits via our payment partner, we receive transaction status and related references needed to credit your organization. We do not collect or store your mobile-money PIN or full sensitive payment credentials.

1.3 Customer workload data. Content and data you run inside your applications and managed databases are your customer content. We process that content as needed to host, route, build, deploy, bill, secure, and support the Services. We do not sell it.

2. How we use personal information

  • Provide the Services: authenticate users, manage organizations, build and deploy applications, provision managed databases and domains, apply environment configuration, and operate edge routing.
  • Billing and fraud prevention: calculate usage, maintain credit balances, send receipts and billing lifecycle notices, and detect abuse.
  • Communications: send transactional email (security, billing, invites, product notices) and respond to support and feedback.
  • Improve and secure the platform: diagnose incidents, monitor errors and performance, prevent abuse, and develop features.
  • Legal compliance: meet applicable legal obligations and respond to lawful requests.

3. How we share personal information

We do not sell personal information. We share information only as needed to operate the Services or as required by law, including with:

  • Infrastructure providers: hosting for our dashboard and control plane, managed databases for product state, caches/queues, and object storage used for platform assets (for example avatars).
  • Compute and network providers: operators of the servers, networking, and related facilities that host your running workloads in our Kigali compute region.
  • GitHub: to authenticate you and to access repositories you authorize for deployment.
  • Payment partners: currently Intouch for mobile-money top-ups.
  • Email delivery: Resend to send transactional messages.
  • Observability and analytics: error monitoring (for example Sentry) and product analytics (for example PostHog and Vercel Analytics) with safeguards appropriate to each tool.
  • Organization members: people you invite to an organization can access shared resources and configuration for that organization.
  • Legal and safety: when we believe disclosure is required by law, necessary to protect rights and safety, or to investigate AUP violations.

Service providers are permitted to process personal information only to perform services for us and not for their own unrelated purposes, subject to their terms and our contracts with them.

4. Data security

We design systems with security in mind. Measures include encryption of environment secrets and managed-database credentials at rest in our control systems (AES-GCM), access controls, TLS for many service connections, and separation of platform roles (including edge vs internal networks). No method of transmission or storage is perfectly secure. You must protect your accounts, GitHub access, organization membership, and application-level security.

Authorized organization members can reveal saved secrets through product controls when they have access. Treat organization invites as access to sensitive configuration.

5. Data retention

  • We retain account and organization records for as long as the account/organization remains active and as needed for billing, security, dispute resolution, and legal obligations.
  • Build logs, deployment metadata, and similar operational records are retained to operate and debug the Services. Retention periods may change as the product matures; we may introduce shorter TTLs over time.
  • If an organization is suspended for non-payment, runtime resources and managed database volumes may be permanently deleted after the retention window described in the Terms & Conditions (currently fourteen (14) days). Control-plane history may remain.
  • When you delete applications or databases, associated runtime data is destroyed using commercially reasonable means. Some backups, logs, or replicas may persist for a limited period until expiry or garbage collection.
  • If you request account closure, we will delete or anonymise personal data we hold as controller when no longer needed, except where retention is required for legal, security, or accounting purposes. Complete self-serve deletion may be limited while we expand account-closure tooling; contact us and we will process requests manually.

6. Your rights and choices

Depending on applicable law—including Rwanda's law on protection of personal data and privacy—you may have rights to access, correct, delete, or restrict processing of your personal data, to object to certain processing, and to data portability where technically feasible. You may also have rights related to automated decision-making where it produces legal or similarly significant effects.

To exercise these rights, email support@instant.rw or legal@instant.rw. We may need to verify your identity. If you are unsatisfied with our response, you may have the right to complain to the relevant supervisory authority under applicable law.

7. Children's privacy

The Services are not directed to children under sixteen (16), and accounts require users to be at least eighteen (18) under our Terms & Conditions. We do not knowingly collect personal data from children under 16. If you believe a child has provided personal data, contact us and we will take appropriate steps.

8. Data residency and international processing

Compute plane. Applications and managed databases you provision on Instant Cloud run in our Kigali, Rwanda region (KGL-1) on infrastructure we operate with local compute providers. That design supports lower latency for African users and stronger alignment with regional data-sovereignty goals for workload data.

Control plane and vendors. Account data, authentication, billing metadata, product databases, email delivery, error monitoring, and analytics may be processed by reputable subprocessors that host or process data outside Rwanda (for example dashboard hosting, control-plane hosting, email, and observability tools). Where we transfer or make personal data available internationally, we do so to operate the Services and apply contractual and technical safeguards appropriate to the provider.

We do not claim that all categories of personal data remain exclusively inside Rwanda. If your compliance program requires exclusive in-country processing of account metadata as well as workloads, contact us before use so we can discuss feasibility.

9. Changes to this Privacy Policy

We may update this Privacy Policy as the Services evolve. Material changes will be communicated by email to your account address and/or by posting a notice on the website or in the product before they take effect, except where a shorter period is required for security or legal reasons.

10. Contact us

Questions about privacy or data requests: