Privacy Policy & Terms of Service
Last updated: March 11, 2026
Privacy Policy
1. Data We Collect

We collect only the information necessary to provide our backup and cloud storage services:

  • Account information: Company name, contact email, billing address, and portal login credentials.
  • Service data: Backup metadata (file sizes, snapshot timestamps, storage usage). We use this to operate the service and generate your usage reports.
  • Payment information: Processed securely by Stripe. We do not store credit card numbers on our systems.
2. Your Stored Data — We Do Not Access It
Desert Forge IT does not access, view, read, analyze, or monitor the content of your stored files or backup data.

Your data is yours. Backup data is encrypted client-side by restic before it reaches our servers — we cannot decrypt it even if we wanted to. Cloud storage files are stored in isolated, chroot'd environments with strict access controls. Our staff do not browse, inspect, or review customer file contents under any circumstances during normal operations.

The only exceptions to this are:

  • When you explicitly request our assistance with your data (e.g., a restore request, troubleshooting, or managed setup).
  • When required by valid legal process (see Section 5 below).
3. How We Protect Your Data
  • Encryption in transit: All connections use SSH/SFTP or TLS encryption.
  • Encryption at rest: Restic backups are encrypted with your repository password before they leave your system. We do not hold your encryption keys.
  • Isolation: Each customer account is stored in a separate, isolated environment. There is no shared access between customers.
  • Access controls: Server access is restricted to key-based SSH on a non-standard port. Administrative access is limited to authorized personnel only.
  • Physical security: Data is stored on enterprise-grade hardware in a professionally managed datacenter facility.
4. Data Retention & Deletion

We retain your data for the duration of your active service. If your subscription is cancelled or expires:

  • Your data will be retained for 3 days after the end of your billing period to allow for reactivation.
  • After this grace period, all stored data (backups, files, and account data) is permanently and irreversibly deleted from our systems.
  • You may request deletion of your data at any time by contacting support. Deletion requests are processed within 5 business days.
5. Law Enforcement & Legal Requests
Desert Forge IT will comply with valid legal processes including subpoenas, court orders, and lawful warrants issued by courts of competent jurisdiction in the United States.

If we receive a legally valid request from law enforcement or a government agency for customer data, we will:

  • Verify the legal validity of the request before disclosing any information.
  • Narrow the scope of disclosure to only what is legally required.
  • Notify you of the request unless prohibited by law (e.g., a gag order or sealed warrant).
  • Provide only non-content metadata (account holder name, email, storage usage, login timestamps) in response to subpoenas. Actual file contents or backup data will only be disclosed pursuant to a valid search warrant.

Important: For restic backup data, the files are encrypted with your password. We do not possess your encryption key and therefore cannot decrypt backup contents even under a warrant. Cloud storage files (SFTP) are not client-side encrypted and may be subject to disclosure under valid legal process.

6. Third-Party Services

We use a limited number of third-party services:

We do not sell, share, or provide your data to any other third parties for marketing, analytics, or any other purpose.

Terms of Service
1. Service Description

Desert Forge IT provides managed backup and cloud storage services. We store your data on our infrastructure and provide tools for you to back up, access, and restore your files.

2. Your Responsibilities
  • You are responsible for maintaining the security of your account credentials and encryption passwords.
  • You are responsible for the content you store. You agree not to store content that is unlawful under applicable U.S. law.
  • You are responsible for maintaining your own copies of critical data. While we take every reasonable precaution, no storage system is infallible.
  • You agree not to use the service for purposes that could damage, disable, or impair our infrastructure.
3. Service Availability

We strive to maintain high availability but do not guarantee uninterrupted service. Scheduled maintenance will be communicated in advance when possible. We are not liable for downtime caused by factors outside our reasonable control, including but not limited to network outages, natural disasters, or upstream provider failures.

4. Limitation of Liability

Desert Forge IT provides this service "as is" without warranties of any kind, either express or implied.

To the maximum extent permitted by law, Desert Forge IT shall not be liable for any indirect, incidental, special, consequential, or punitive damages, including but not limited to loss of profits, data, or business opportunities, arising from:

  • Data loss due to hardware failure, software defects, or any other cause
  • Service interruptions or downtime
  • Unauthorized access to your account caused by compromised credentials
  • Loss of your encryption password (we cannot recover encrypted backup data)

Our total liability for any claim arising from the service shall not exceed the amount you paid for the service in the three (3) months preceding the event giving rise to the claim.

5. Data Ownership

You retain full ownership of all data you store with us. We claim no ownership or intellectual property rights over your content. Upon termination of service, you may export your data during the retention period described in our Privacy Policy.

6. Account Termination
  • You may cancel your service at any time through the billing portal or by contacting support.
  • We may suspend or terminate your account if you violate these terms, fail to pay, or if your use of the service poses a risk to our infrastructure or other customers.
  • Upon termination, data deletion follows the schedule described in our Privacy Policy (Section 4).
7. Governing Law

These terms are governed by the laws of the State of Arizona, United States. Any disputes arising from these terms or the service shall be resolved in the state or federal courts located in Maricopa County, Arizona.

8. Changes to These Terms

We may update these terms from time to time. Material changes will be communicated via email or a notice in the portal. Continued use of the service after changes take effect constitutes acceptance of the updated terms.

Key Points
We don't look at your data
Staff never access file contents during normal operations.
Backups are encrypted by you
Restic encrypts data before it leaves your machine. We can't decrypt it.
Law enforcement compliance
We comply with valid U.S. legal process. We'll notify you unless legally prohibited.
Data deleted on cancellation
3-day grace period, then permanent deletion. Request early deletion anytime.
We never sell your data
No data sharing with third parties for marketing or analytics. Period.
Questions?

If you have questions about our privacy practices or these terms, contact us: