Derive stores what it takes to run your workspace: an account, the content you publish, and the bare usage signals that keep the product honest with you. Nothing more, and nothing sold. Effective August 10, 2026.
Your email, name, and the handle you choose. That's what it takes to sign you in and show your name on what you publish.
The artifacts you publish, their full version history, and the comments your team leaves on them. This is the product; it's what a workspace is made of.
First-party view analytics on what you publish (who's reading and when) and one signup-attribution stamp noting which link brought you here.
No ad trackers. No third-party analytics scripts. We never sell your data, to anyone, for any reason.
A short, named list, nothing hidden behind "and our partners." Cloudflare hosts the app and serves its static pages. Neon runs the database behind your workspace: artifact records, comments, and the search index; artifact files themselves live in Cloudflare storage. Stripe processes billing events. Resend delivers transactional email like password resets and notifications. Slack and GitHub only see anything once a workspace owner explicitly connects that integration, and only for that workspace. No third-party model provider sees your content unless an opt-in feature like chat or an automation is turned on; search indexing runs on models inside Cloudflare's own infrastructure, the same host that already stores your content.
Deleting your account removes your sign-in data, your memberships, and your personal workspace container, and it permanently disconnects your name from everything you authored. It does not delete the artifacts themselves: that's a separate, explicit step. Delete an artifact and its versions and search entries go with it; do that first, then delete your account. A workspace works the same way: it has to be empty before it can be deleted, so remove or move its artifacts before you delete the workspace itself. One honest exception either way: a URL you already published and shared stays live at that link until you (or a remaining owner) take it down yourself, the same way a link you emailed someone doesn't un-send when you delete the file on your end. We won't pretend a link that's already out in the world quietly disappears.
Most of it has no clock on it, and that is deliberate: your artifacts, their version history, and the comments on them stay until you delete them. A permanent URL that quietly expired would not be permanent. The things that do have a clock, all of them enforced by a job rather than a promise: view analytics are a rolling 365-day window, pruned daily, so old traffic ages out instead of piling up forever. A page published without an account is a draft, and it is deleted 72 hours after you create it unless you claim it into a workspace. A password reset link lasts one hour. A signed-in session's access token lasts 24 hours and renews quietly until you have been away for a year. An agent app that begins connecting but never finishes the consent screen is cleared after 30 days. Self-hosting changes all of this: every window above is yours to set, and the analytics one can be switched off entirely.
Yes. Derive is fair source and runs as one container: SQLite and local disk by default, Postgres and S3 at scale, entirely on your own infrastructure. Run it yourself, and none of the infrastructure listed above ever sees your data, because none of it is in the request path.
Email hello@derive.to. We read everything ourselves, and we'd rather explain something than have you guess.
That's the point of publishing this before you have to go looking for it. Questions go to hello@derive.to.