How OpsMinder handles your data.
OpsMinder keeps lists of chores, releases, IP addresses and SSH public keys for your team. That means it holds some personal data. This page says what, why, where, and for how long.
Last updated 2 May 2026
1. Who we are
OpsMinder is operated by Tocabi Software B.V., Arnhem, the Netherlands, registered with the Dutch Chamber of Commerce under number 78396026. We are the controller for the data described here. Questions go to privacy@opsminder.sh.
2. What we store
Account data. Your name, email address, team name and login details. For paying teams, the billing name and address on the invoice.
Registry data. The IP addresses and SSH public keys your team registers, with the owner's name and the label they gave it. We do not store private keys, passwords, API keys or credentials of any kind. Where a runbook tracks a key rotation, we store the runbook's name, dates and comments, not the key.
Runbooks and deploy logs. Runbook steps, notes and links, who completed each run and what they wrote about it. Releases with the environment, repository name, commit hash, version and who deployed. If you connect GitHub or GitLab, the commit messages and author names between releases.
Waitlist. The email address and optional team size you gave us. Kept until you join or ask us to remove it.
Technical data. Server logs with IP address, browser and time of request, kept for 30 days. Error reports when something breaks.
3. Why we store it
To run the service you signed up for: keeping the lists, sending reminders, answering your pipeline when it asks about a freeze, and showing your team what shipped. That is the contract between us (GDPR art. 6(1)(b)).
To invoice you and keep the records Dutch tax law requires (art. 6(1)(c)).
To keep the service working and fix errors (art. 6(1)(f), our legitimate interest). We do not sell data, build advertising profiles or share it with anyone who is not listed below.
4. Where it lives and who else touches it
Your data is hosted in the Netherlands by TransIP. The following companies process data on our behalf, each under a data processing agreement, and only for the purpose named.
5. Cookies
The app sets one cookie to keep you logged in. That is the only cookie. The website sets none, and there are no analytics or advertising cookies, so there is no consent banner.
6. How long we keep it
For as long as your account is active. When you cancel, or stop paying, your data stays readable and exportable for six months, then it is deleted. You can ask us to delete it sooner.
Invoices are kept for seven years, as Dutch tax law requires. Server logs are kept for 30 days. Waitlist entries are removed when you join, or when you ask.
When a team member is removed, their registry entries, run comments and release records stay in the team's history with their name, because the team needs to know who did what. Their login is deleted.
7. Your rights
You can see, export, correct and delete your data. Most of this you can do yourself in the app; the rest by emailing privacy@opsminder.sh. We answer within 30 days.
If you think we are handling your data wrongly, tell us first. You can also complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens.
8. Keeping it safe
Data is encrypted in transit and at rest. Access inside Tocabi Software is limited to the people who need it to run the service. If something goes wrong that affects your data, we tell you and, where required, the authority within 72 hours.
9. Changes
If this policy changes in a way that matters, we email account owners before it takes effect. The date at the top shows the current version.