Monitoring Privacy Policy
Operator and scope
Individual Entrepreneur Yana Nikolaevna Subacheva (ИП Субачева Яна Николаевна), TIN 382104099251. Address for correspondence: 1 Solnechnaya Street, Molodezhny settlement, Irkutsk Region, Russia (Иркутская обл., п. Молодёжный, ул. Солнечная, д. 1).
Questions about data, access, correction and deletion: support@staybox.ru. The policy applies to staybox.ru, personal account and Monitoring applications used to monitor and manage external equipment, including the new client built on the Rust stack. The actual dataset depends on the version used and the features selected.
What data we process
Account: phone, email, profile name or label, internal identifier, contact confirmation and authorization information. This information is used for sign-in, account recovery, and granting access to equipment.
When you choose to sign in with Telegram, we receive your Telegram ID, name, username, and a link to your profile photo if Telegram provides them, as well as a signed confirmation and the time of sign-in. We use this information to verify your identity and provide access to your existing Monitoring account. We do not receive your password, Telegram login codes, or Telegram correspondence. Any phone number you enter on Telegram’s sign-in page is processed by Telegram. Signing in with a phone number or email remains a separate option.
Equipment: controller and ASIC identifiers, farm names, network addresses and parameters, hashrate, temperature, power consumption, operating status, and errors. Commands, pool settings, worker names, schedules, and any equipment credentials you provide are used for actions you choose and for diagnostics.
Support: the contents of your requests, reply history, contact details, and only the files, images, and diagnostic information you choose to attach or send. Do not send passwords or information unrelated to your issue.
Notifications and operation of the application: push token, installation ID, platform, language, version and distribution channel, launch time or return to the application. This information is used to deliver notifications, maintain compatibility, and identify the app versions in use.
Technical information: IP address, time and result of the network request, information about the browser or client, technical errors. This information is used to operate, secure, and troubleshoot the Monitoring service.
Permissions and data on the device
The camera is only needed to scan the QR code of the controller. The code can be entered manually. The camera image for scanning is not sent to the Monitoring server. Access to the camera and notifications can be denied in the device settings.
Files and photos are only transferred when you choose an attachment. The application does not request access to the entire address book, SMS, microphone or geolocation.
The login token and settings are stored on the device; the native application uses the platform's secure storage. The web version can save the session and settings in the browser storage. The native app does not use an advertising identifier or track you across apps for advertising.
Legal bases and recipients
We process data to provide the requested service and perform the contract, meet legal obligations, protect the Monitoring service and the rights of those involved, and—where the law requires—on the basis of your consent. Operating system permission does not replace consent when required by law.
The operator's server infrastructure, SMS.RU for phone verification, Salebot (mail.salebot.pro) for email verification, email infrastructure for correspondence, Firebase Cloud Messaging (Google), and Apple Push Notification service are used to provide Monitoring. Each provider receives the data needed for its function. These providers may process technical data within their infrastructure, including in countries outside your country of residence.
When you choose to sign in with Telegram, its authorization page opens and Telegram's privacy policy applies: telegram.org/privacy. Telegram receives technical information about the sign-in request. After you approve, Telegram sends a signed confirmation to Monitoring; we do not request access to your messages or contacts.
Information from requests sent to the support address is processed by the mail infrastructure used by the operator. When opening external websites, videos, messaging services, and payment pages, the respective provider’s rules apply. We do not sell personal data or share it with advertising networks for behavioral targeting.
Access to data is limited to authorized employees and contractors within the scope of their tasks; disclosure to public authorities is possible according to applicable legal requirements.
How data is protected
The exchange of a new mobile application with the Monitoring server is performed over HTTPS. The server checks the user session and the rights to the requested data and equipment. The native app stores login tokens using the platform’s secure storage. Access for employees and contractors is limited to the scope of their assigned tasks; regular backups of the Rust database are created with limited file rights. Revocation of sessions, termination of push registrations when deleting an account and rotation of technical logs are applied.
Retention and deletion
Profile information, contact details, equipment links, support requests, and settings are stored during the use of the account and are deleted when the confirmed request is completed. In the new app, you can submit the request in the “Profile” or “Settings” section → “Delete the account”. The operator completes the deletion no later than 30 calendar days after verifying account ownership and accepting the request. The app shows the status and deadline for each request.
Once the request is accepted, account access ends, its schedules are disabled, and its push registrations are removed. When deletion is completed, the account profile and contact details, sessions, equipment links, personal settings, support requests and attachments, stored equipment credentials, and command logs associated with the account are deleted. Creating a new account after deletion does not automatically restore the old equipment links.
The technical deletion receipt and security hashes used to revoke old sessions are retained for up to 32 days after deletion is completed, or until their specified expiration, whichever comes first. They are used to verify status, securely repeat the request, and prevent access to the old token from being restored.
Deleting the account does not destroy the physical equipment and does not terminate the already paid access period associated with the controller. Technical information about the equipment may be retained for its operation and troubleshooting after the account link is removed. Detailed telemetry history in the Rust service is retained in a rolling six-hour window; the current state of the equipment is stored separately.
Payment and account records necessary for settlement, performance of obligations, dispute resolution or enforcement of the law shall be retained to the extent and for the periods provided for by the respective obligations. When deleting an account, they are separated from the account used to sign in; this does not mean that legally required accounting records or information held by a payment provider are deleted.
Backups and security copies are not available through a normal interface and are removed through a rotation cycle. The routine cleanup of Rust database backups runs daily and deletes copies that are at least eight full days old; the actual deadline takes into account the time of the next successful cleanup run. Recovery from a copy requires re-applying the deletions before access is opened. Technical logs are not used to restore a deleted account profile.
For the Rust server system log, the storage limit of 14 days and the volume limit are configured. The logs of the web server are rotated daily: the current file and up to 10 archive files on the Rust server are saved, up to 5 archive files on the site server. Rotation also depends on the availability of records and file size, so the number of archives does not mean the same calendar period for each request. These logs are needed to diagnose, protect access and investigate failures.
The Firebase installation identifier and notification delivery token are different information. In app versions that support installation ID deletion, the identifier is sent to the Monitoring server so it can process an account-deletion request. The server sends deletion requests for known installations, including when the user accesses without the installed application; if the provider is temporarily unavailable, the request is repeated. On the device, cleaning is also repeated the next time you start or connect to the network. For older versions that did not transmit the installation identifier, the operator may not have the information needed to submit a targeted deletion request to Firebase.
According to the Firebase documentation, after a Firebase Installation ID is deleted through the API, removal of related data from live and backup systems of Firebase services that use that ID can take up to 180 days. See Firebase documentation. Access to the Monitoring account ends earlier; this does not mean that every copy held by the provider is deleted immediately. For data deletion from the providers involved, you can contact the Monitoring operator at the email specified in this policy.
Rights and communications
You can request information about the processing, access and clarification of data, termination of processing or deletion of the account, as well as withdraw consent by writing to support@staybox.ru. To protect your account, the operator may verify that you own it. Do not send a password or confirmation code in the letter.
You can delete an account without the installed application: the instructions are on the Account Deletion page. Uninstalling the app, signing out, or unlinking one controller does not by itself delete your account. If the retention of individual data is required by law, the operator will explain the composition and basis of such storage.
The policy is updated when the Monitoring service or processing rules change. Each revision is published at this URL with its date. Significant changes to data processing are communicated through the Monitoring service where available. Contact for privacy questions and complaints: support@staybox.ru.