Privacy policy
Plain language, because that's the whole point of this project. Email hello@serverstick.com if anything here is unclear.
This website
This website has no accounts and runs no analytics script. Our hosting provider may keep ordinary access logs. The email links go straight to your own mail client, so we only see a message if you send one.
Getting a claim code
Taking a code from this site runs a Cloudflare Turnstile check. That is an “are you a person” test rather than a tracker: it sets no cookie that follows you around, and Cloudflare sees the request in order to answer it. We store the code we issued you and the IP address that asked for it, so that a script hoovering up codes can be spotted and the batch revoked. That is the only place we deliberately keep an IP, and it is not linked to anything you do afterwards.
Setting up a box
Registering a device creates a random device ID and a provisioning credential. No account, name, or email required. The subdomain you pick is the only thing we store that you chose. If you turn on mining credits (off by default), we store a pool worker name tied to that device ID, not a wallet address. If you use Hermes to send us a problem report, we store exactly what you were shown before you agreed to send it. Nothing is added, and no IP address is attached.
The managed AI tier
The local and bring-your-own-key AI tiers never touch our servers. That traffic stays on your box or goes straight to your own provider. The managed tier is different: it's proxied through our router to TokenRouter, a third-party API aggregator, to reach the underlying model, the same as any cloud AI product works. We meter token counts for billing. We do not log what's in your prompts or responses.
Your app data
Your local apps store files on your computer rather than a hosted storage platform. Content you include in a managed AI request is sent to outside providers. Remote access uses managed tunnel infrastructure, and apps you connect to outside services can send data there too.
Not total independence
The managed tunnel that gives your box a public *.serverstick.com address, and the managed AI tier, both rely on infrastructure we operate. While you use these, your device is not fully independent of us. Your subdomain points at our servers, and AI requests pass through our router. This is by design: the parts that need a public server on the internet live on ours; your data and apps live on yours.
Self-managed exit
If you prefer full independence, you can deprovision your device from the dashboard. This removes your subdomain and revokes your tunnel credentials. The box keeps running all your apps locally. After deprovisioning, remote access and the managed AI tier stop working. You can still reach your server on your local network. No data leaves your house unless you set it up to.
Deleting your data
Deprovisioning a device, built into the dashboard, tears down its subdomain, revokes its credentials, and removes it from our registry. The box keeps running everything locally, so deprovisioning only removes what we hold, not what's on your machine.
Disclaimers
No uptime guarantee
This is a small, early-stage service, not a company with an SLA. The tunnel that gives you a public *.serverstick.com address, and the managed AI tier, can go down, and there's no guaranteed response time if they do.
If this project goes away
Your public subdomain and the managed AI tier would stop working. Everything installed on your box keeps running exactly as it does today. The apps, your files, and access from your own network never depended on us to begin with. That's the design: we run the parts that need a server on the internet, your data and your apps do not.
Last updated 2026-08-13.