Last updated: July 2026
We store your name, email address, your password (bcrypt-hashed, never in readable form — not even the superadmin can see it), your role, and, if enabled, your two-factor authentication (2FA) secret.
The panel uses a login session cookie (HTTPS-only, not accessible from JavaScript), a language-preference cookie, and, if you check "remember this device", a 30-day cookie so you don't have to re-enter a 2FA code every time. We don't use advertising or tracking cookies.
For security and troubleshooting, we log significant actions (login, creating/deleting a website/database/domain, etc.), the associated account's email, and the IP address the request came from. Failed login attempts also record the IP address, to help defend against abuse.
Only you and the superadmin can access your own domains, websites, databases, mailboxes, and uploaded files. We keep them as long as your account is active, or until you delete them yourself in the panel.
To power the panel's features we use: Porkbun (domain DNS), Nginx Proxy Manager (self-hosted reverse proxy), Mailcow (self-hosted email), and the dedicated database engines (also self-hosted containers). These are part of the service's technical operation, not used for marketing, and we never sell or share your data with third parties for advertising.
We keep your account data as long as your account is active. If you request account deletion, the superadmin removes it along with the associated data (aside from the legally required minimum of audit logs).
For any privacy-related question or request, email info@kosinet.top.