Privacy Policy

Last updated April 07, 2026

This Privacy Notice for Dragon Labs LLC (doing business as Lizard) ("we," "us," or "our"), describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services"), including when you:

  • Visit our website at lizard.build or any website of ours that links to this Privacy Notice
  • Use Lizard – a cloud deployment platform where users deploy applications, databases, and services via Git
  • Engage with us in other related ways, including any marketing or events

Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at team@lizard.build.

Our Role: Data Controller and Data Processor

Lizard operates in two distinct capacities depending on the type of data involved:

As a Data Controller: We act as the data controller for personal information we collect directly from you – such as your name, email address, billing information, and account details. This Privacy Notice describes how we handle this data.

As a Data Processor: When you deploy applications, databases, and services on Lizard, you may submit, store, or process data belonging to you or your end users within your Firecracker microVMs. We process this data ("Customer Content") solely on your behalf and under your instructions, in accordance with our Data Processing Addendum. This Privacy Notice does not apply to Customer Content – you, as the customer, are the data controller for that data and are solely responsible for ensuring compliance with all applicable laws and regulations with respect to your end users.

Customer Content

Definition. "Customer Content" means any data, code, or information that you or your end users submit, store, or process through the Services, including but not limited to:

  • Source code and application code pushed via Git
  • VM snapshots and build artifacts
  • Runtime logs generated by your applications
  • Environment variables and secrets
  • Database content (Postgres, Redis)
  • Files, images, and other data stored within your microVMs
  • Network traffic and data processed by your applications

How we handle Customer Content. We access or share Customer Content only as necessary to provide and maintain the Services, to comply with the law, or with your consent. We will not use Customer Content for marketing or advertising, and we will not sell or share Customer Content with third parties. If you are on a free or trial plan, we may use Customer Content to train and improve our own machine learning models. If you are on a paid plan, model training is disabled by default and requires your explicit opt-in. See our Terms of Service for details and opt-out instructions.

Employee access. Lizard employees do not access your applications, VMs, or Customer Content unless required for security or maintenance purposes, or for support reasons with your consent. Access is logged and limited to the minimum necessary.

Deployment-Specific Data We Collect

In addition to the personal information described below, we collect the following technical data as part of providing the deployment platform:

  • Build metadata. Stack detection results, build duration, build logs (excluding application source code content), and dependency information.
  • VM telemetry. CPU usage, memory consumption, boot times, snapshot sizes, and instance lifecycle events for your Firecracker microVMs.
  • Deployment metadata. Timestamps, Git commit hashes, deployment status, rollback history, and region assignments.
  • Network metadata. Request counts, response times, bandwidth usage, and SSL certificate status. We do not inspect the content of network traffic.
  • Resource usage. Compute, storage, and egress consumption data used for billing purposes.

This data is used to operate, monitor, and improve the Services, and to calculate your usage for billing. It is not Customer Content.

Shared Responsibility

What Lizard is responsible for:

  • Infrastructure security and Firecracker VM isolation
  • Network security and DDoS protection (via Cloudflare)
  • Encryption of data at rest and in transit
  • Platform availability and incident response
  • Secure handling of account credentials and payment data
  • Access controls and audit logging for employee access to infrastructure

What you are responsible for:

  • The code you deploy and the data your applications process
  • Compliance with applicable laws for data processed within your VMs
  • Managing access to your Lizard account and environment variables
  • The privacy practices of your own applications and how they handle end user data
  • Notifying your end users about data processing performed by your applications

1. What Information Do We Collect?

Personal Information Provided by You. We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, or otherwise contact us. The personal information we collect may include:

  • Names
  • Email addresses
  • Passwords
  • Billing addresses
  • Debit/credit card numbers

Sensitive Information. We do not process sensitive information.

Payment Data. We may collect data necessary to process your payment if you choose to make purchases. All payment data is handled and stored by Stripe and Coinbase. You may find their privacy notices at stripe.com/privacy.

Social Media Login Data. We may provide you with the option to register with us using your existing social media account details, like your GitHub or Google account.

Information Automatically Collected. We automatically collect certain information when you visit, use, or navigate the Services. This information does not reveal your specific identity but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, and information about how and when you use our Services. We also collect information through cookies and similar technologies.

The information we collect includes:

  • Log and Usage Data. Service-related, diagnostic, usage, and performance information including your IP address, device information, browser type, and activity in the Services.
  • Device Data. Information about your computer, phone, tablet, or other device including device and application identification numbers, location, browser type, and hardware model.
  • Location Data. Location information about your device, which can be either precise or imprecise based on your IP address.

Google API. Our use of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.

2. How Do We Process Your Information?

We process your personal information for a variety of reasons, including:

  • To facilitate account creation and authentication and manage user accounts
  • To deliver and facilitate delivery of services to the user
  • To respond to user inquiries and offer support
  • To send administrative information to users
  • To fulfill and manage your orders, payments, returns, and exchanges
  • To request feedback about your use of our Services
  • To protect our Services, including fraud monitoring and prevention
  • To identify usage trends so we can improve our Services
  • To save or protect an individual's vital interest

3. What Legal Bases Do We Rely On?

We only process your personal information when we believe it is necessary and we have a valid legal reason to do so under applicable law, like with your consent, to comply with laws, to provide you with services, to protect your rights, or to fulfill our legitimate business interests.

If you are located in the EU or UK, we may rely on: Consent, Performance of a Contract, Legitimate Interests (analyzing service usage, diagnosing problems, understanding user experience), Legal Obligations, and Vital Interests.

If you are located in Canada, we may process your information if you have given us specific permission (express consent) or in situations where your permission can be inferred (implied consent).

4. When and With Whom Do We Share Your Personal Information?

We may share your data with third-party vendors, service providers, contractors, or agents who perform services for us or on our behalf. The third parties we may share personal information with include:

  • Allow Users to Connect to Their Third-Party Accounts: GitHub account and Google account
  • Cloud Computing Services: GTHost
  • Functionality and Infrastructure Optimization: Cloudflare
  • Invoice and Billing: Stripe and Coinbase
  • Web and Mobile Analytics: Google Analytics and PostHog

We may also share your personal information in connection with business transfers (mergers, acquisitions, etc.).

Sub-processors

The following is a complete list of third-party sub-processors that may process personal information or Customer Content on our behalf:

Sub-processorPurposeLocation
GTHostCloud infrastructure & hostingUnited States
CloudflareCDN, DNS, DDoS protectionUnited States
StripeBilling & payment processingUnited States
CoinbaseCryptocurrency paymentsUnited States
GitHubOAuth authentication, Git integrationUnited States
GoogleOAuth authentication, Google AnalyticsUnited States
PostHogProduct analyticsUnited States

We will update this list when sub-processors are added or removed. We have data processing agreements in place with each sub-processor.

5. Do We Use Cookies and Other Tracking Technologies?

We may use cookies and similar tracking technologies to gather information when you interact with our Services. We also permit third parties and service providers to use online tracking technologies on our Services for analytics and advertising.

Google Analytics. We may share your information with Google Analytics to track and analyze the use of the Services. The Google Analytics Advertising Features that we may use include: Remarketing with Google Analytics, Google Display Network Impressions Reporting, and Google Analytics Demographics and Interests Reporting. To opt out of being tracked by Google Analytics, visit tools.google.com/dlpage/gaoptout.

We collect and share your personal information through: targeting cookies/marketing cookies, social media cookies, and beacons/pixels/tags.

6. How Do We Handle Your Social Logins?

Our Services offer you the ability to register and log in using your third-party social media account details (like your GitHub or Google logins). Where you choose to do this, we will receive certain profile information about you from your social media provider.

7. Is Your Information Transferred Internationally?

Our servers are located in the United States, Germany, Netherlands, Singapore, Canada, United Kingdom, and France. Your data may be processed in any of these locations depending on your selected deployment region. If you are a resident in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, we have implemented measures to protect your personal information, including by using the European Commission's Standard Contractual Clauses for transfers of personal information. Our Standard Contractual Clauses can be provided upon request.

8. How Long Do We Keep Your Information?

We will only keep your personal information for as long as it is necessary for the purposes set out in this Privacy Notice, unless a longer retention period is required by law. No purpose in this notice will require us keeping your personal information for longer than the period of time in which users have an account with us.

9. How Do We Keep Your Information Safe?

We have implemented appropriate and reasonable technical and organizational security measures designed to protect the security of any personal information we process. However, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure.

10. Do We Collect Information from Minors?

We do not knowingly collect, solicit data from, or market to children under 18 years of age or the equivalent age as specified by law in your jurisdiction. By using the Services, you represent that you are at least 18 or that you are the parent or guardian of such a minor. If you become aware of any data we may have collected from children under age 18, please contact us at team@lizard.build.

11. What Are Your Privacy Rights?

Depending on your state of residence in the US or in some regions, such as the EEA, UK, Switzerland, and Canada, you have rights that allow you greater access to and control over your personal information. You may review, change, or terminate your account at any time.

These may include the right to request access and obtain a copy of your personal information, to request rectification or erasure, to restrict processing, to data portability, and not to be subject to automated decision-making.

Withdrawing your consent: You have the right to withdraw your consent at any time by contacting us at team@lizard.build.

Cookies: Most web browsers are set to accept cookies by default. If you prefer, you can usually choose to set your browser to remove cookies and to reject cookies.

12. Controls for Do-Not-Track Features

Most web browsers include a Do-Not-Track ("DNT") feature or setting. At this stage, no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals.

13. Do United States Residents Have Specific Privacy Rights?

If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you may have the right to request access to and receive details about the personal information we maintain about you and how we have processed it, correct inaccuracies, get a copy of, or delete your personal information.

We have not sold or shared any personal information to third parties for a business or commercial purpose in the preceding twelve (12) months.

14. Do Other Regions Have Specific Privacy Rights?

Australia. We collect and process your personal information under the obligations and conditions set by Australia's Privacy Act 1988. If you believe we are unlawfully processing your personal information, you have the right to submit a complaint to the Office of the Australian Information Commissioner.

15. Do We Make Updates to This Notice?

We may update this Privacy Notice from time to time. The updated version will be indicated by an updated "Revised" date at the top of this Privacy Notice. We encourage you to review this Privacy Notice frequently.

16. How Can You Contact Us About This Notice?

If you have questions or comments about this notice, you may email us at team@lizard.build or contact us by post at:

Dragon Labs LLC
1336 NW Flanders St #312
Portland, OR 97209
United States

17. How Can You Review, Update, or Delete the Data We Collect from You?

Based on the applicable laws of your country or state of residence in the US, you may have the right to request access to the personal information we collect from you, details about how we have processed it, correct inaccuracies, or delete your personal information. To request to review, update, or delete your personal information, please email team@lizard.build.

We use cookies for essential site functionality and analytics. See our Cookie Policy.