ไทยErawan

Privacy Policy

31 August 2026

Erawan provides a cloud hosting platform for applications built by developers and AI coding agents. This Privacy Policy outlines the personal data we collect, how and why we process it, where it is stored, and the rights you hold under Thailand's Personal Data Protection Act (PDPA), which is the law this service is operated under.

Information We Collect

Data Protection Principles and Exclusions

Cookie Policy

Our platform uses only two strictly necessary first-party cookies: a secure session cookie to maintain your authenticated state, and an anti-CSRF token echoed by the console to prevent unauthorized cross-site actions. Both cookies are automatically invalidated upon signing out. We also store one identifier outside of cookies, described next.

Browser Storage and Visitor Measurement

Our website and console each store a single random identifier (erw_aid) in your browser's local storage, so that repeat visits are counted as one person rather than several. It is generated in your browser, contains nothing about you, and is never sent to any third party. Because our website and our console are separate sites, the identifier travels between them in the link you follow and is removed from the address as soon as the page loads. We use it only to understand where our own signup flow loses people. Clearing your browser's site data removes it, and everything continues to work without it.

Website Analytics

We count page views on our website and console with Umami, an open-source analytics tool that we run ourselves, on our own servers, at analytics.erawan.cloud. The measurement never leaves our infrastructure, no third party receives it, and the tool’s own product telemetry is switched off. Umami sets no cookie and stores nothing in your browser. A visit is counted from a value derived from your IP address and browser identification mixed with a secret key that changes every month, so the record cannot be traced back to you and does not follow you into the next month. Your IP address itself is never stored: what is kept is the page you visited, the site that referred you, and the country, browser, operating system, language and screen size your browser reports. Session recording and behaviour replay are switched off.

Cookie Scope on Hosted Applications

Applications operating on default subdomains under erawan.app share a registrable domain in browser scope. Consequently, cookies set without domain restrictions may be accessible to neighboring applications on the same domain. We strongly recommend configuring a custom domain for any application implementing user authentication, ensuring complete domain and cookie isolation.

Third-Party Sub-processors

We share data exclusively with trusted infrastructure providers required to operate the service:

Data Storage and International Transfers

Platform infrastructure, servers, and primary storage systems are hosted in enterprise data centers located in Thailand and Singapore. Applications and their data are served from Thailand; account records and the recovery copy are held in Singapore. If you access the service from outside these regions, your data is transferred and stored in compliance with international data security and privacy standards.

Data Retention and Account Deletion

Personal data is retained for the duration of your active account. If an account is suspended due to non-payment, data is preserved for a grace period of ninety (90) days before permanent removal.

When an application is deleted, its container images, environment variables, and runtime logs are purged immediately. Email dispatch records and audit logs are retained until the parent account is closed.

You may terminate your account at any time via Account Settings. Account closure immediately and permanently deletes all associated applications, databases, files, and system logs with no restorable backup copies.

Your Legal Rights

Under Thailand's PDPA — and we extend the same to everyone, wherever they are — you have the right to request access to, rectification of, portability of, or erasure of your personal data, as well as the right to restrict or object to processing. To exercise any of these rights, contact us at hello@erawan.cloud.

Technical and Organizational Security Measures

Account passwords are hashed using Argon2. Environment variables and database credentials are encrypted at rest. Agent tokens are hashed and can be revoked instantly via the console. Application code and repository histories are backed up offsite daily with strong encryption. For your application's private database contents, we recommend maintaining regular independent exports of critical data.

Amendments to this Policy

Material changes to this Privacy Policy will be communicated via your registered email address prior to their effective date.

Contact Us

For inquiries regarding privacy, data protection, or compliance, please reach out to hello@erawan.cloud.


Privacy · Terms · Security · Report abuse · hello@erawan.cloud