Read

Privacy policy

What TempMV stores, where, why, for how long, who else is involved, and how to exercise your rights.

Last updated: 2026-10-10. This policy explains how TempMV (https://tempmv.cloud) handles personal data, under the EU General Data Protection Regulation (GDPR) and Spain's Organic Law 3/2018 (LOPDGDD). For anything in it, write to support@s4nchzz.com.

The short version

  • The virtual machines run entirely inside your browser. Their memory, their disk contents and any disk image you load from your computer never reach our servers — the one exception is a persistent disk you choose to create with an account: its contents are stored on our own server for a few days (see below).
  • You can use much of the site without an account. An account is optional and free. If you create one, we store your email, your profile, the progress and machine recipes you sync, and what you post, send or create in the community, using Supabase (EU) as our processor.
  • Movi, the AI assistant, sends what you write to it — plus, if you are signed in, a short summary of your machines, networks and groups — to Groq, Inc. in the United States to generate the answer.
  • Ads (Google AdSense, on reading pages only) and usage analytics (Microsoft Clarity) are loaded only if you accept. News emails are sent only if you tick a separate, unticked box.
  • We do not sell your data, and you can download or delete your account data yourself from your account page.

Who is responsible

The data controller is Iyan Sanchez, Asturias, Spain, a private individual who runs TempMV. Contact: support@s4nchzz.com. No data protection officer has been appointed, as none is required for an operation of this size; write to the same address for any privacy request.

What stays in your browser

Running virtual machines, their memory and their disk contents live only in the page's memory and are destroyed when you close or reload the tab. Disk images, ISOs and files you load from your computer are read on your device and are never uploaded. The following is kept in your browser's local storage, session storage or IndexedDB on your device; the cookie policy lists every key. You can erase it at any time by clearing this site's data in your browser.

WhatWhy
Settings and interface preferences (language, theme, sidebar, defaults)So the app looks and behaves the same next time.
Saved machine templates, personal virtual networks, the JSON editor draftSo what you configured can be recreated later.
Course progress, achievements, daily-challenge history, local activity logSo your progress survives a reload, with or without an account.
Screenshots you take (IndexedDB)So you can see them in the gallery. They stay on your device unless you upload one to a post.
Your cookie/consent choiceSo you are not asked on every visit.
Movi guest conversation (signed out only): a random id and your last 12 turnsSo the conversation survives a reload and the guest message limit can be applied.
Sign-in session and a random device id (only if you have an account)So you stay signed in and synced items can be told apart per device. The session is removed when you sign out.

What reaches a server even without an account

  • Web and image requests. The site and the disk images of the online machines are served from servers operated by the controller (tempmv.cloud and images.tempmv.cloud). Some catalog images and any URL you paste are downloaded directly from their origin, for example the copy.sh mirror. Like any web request, these reveal your IP address and browser details to whoever serves the file. No account information is attached.
  • Fonts. The Inter and JetBrains Mono typefaces are loaded from Google Fonts, which receives your IP address and browser details when the page loads.
  • Error reports. If the app crashes, it sends the error message, the code location, the page path (without query string), the app version and your browser's user agent to our log, plus your account id if you are signed in. No form contents are sent.
  • Online counter. On community pages, a random per-tab key is announced over a live channel so the site can show how many people are online. Nothing is stored, and you can turn it off with “Count me as online” in settings.
  • Site announcements and update notices. Your browser keeps a connection open to receive announcements published by the site owner and the notices shown while a new version is being published. When an update is live, it also downloads the public changelog (/changelog.json) to tell you what changed. No data about you is collected by that channel.
  • Networking inside a machine. If you give a machine internet access, web requests made by the guest system are performed by your browser directly to the destination site, or go through a relay server you configure yourself. Our servers do not see them.
  • Movi as a guest (described below), and ads and analytics only if you accept them.

The optional account

Creating an account is never required to boot a machine. If you create one, sign-in is handled by Supabase Auth with your email and password (or a one-time email link), and the following is stored on our backend so it can follow you across devices and power the community features.

WhatWhyWho can see it
Email address, password (stored only as a hash by the authentication service), sign-up and last sign-in dates, email confirmation statusTo create and secure your account and send account emails.You, and the site owner and administrators for support and moderation. Never shown publicly.
Two-step verification (TOTP) factors, if you enable themTo protect your account.Only the authentication service. Administrators can only reset them.
Username, display name, avatar image, bio, preferred language, sign-up dateYour public profile in the community.Everyone (your public profile). The avatar file is publicly reachable by its link.
Account flags: administrator or owner role, ban, suspension or deactivation, with the reasonTo run and moderate the community.Administrators. The administrator badge and whether an account is banned are shown on profiles.
Email preferences (news, streak reminders, email language), with the date and policy version of your news consentTo send only the emails you want and prove your consent.You and administrators.
Synced progress: course lessons and exams, achievements and XP, daily-challenge results, app settings, bookmarksSo your progress follows you across devices, and for leaderboards and certificates.You. Totals (XP, level, badges, rank, lessons completed) appear on leaderboards, the activity feed and your profile unless you switch that off.
Machine recipes: library templates, the machines in your room and your personal virtual networks — configuration, notes and references to remote or blank media onlySo your machines come back, powered off, on any device. Disk contents, RAM and files uploaded from your computer are never sent. You can turn this off with “Keep my machines on this account”.Only you.
Forum threads and replies, reactions, showcase entries, and the screenshots or machine recipes you attachTo publish what you post.Everyone, including who reacted. Uploaded screenshots are publicly reachable by their link.
Follows, certificatesSocial features and proof of course completion.Follows are public. A certificate shows your name and username to anyone with its link.
Friends, private messages (including machine recipes you attach), machines you share with someoneTo let you talk to and share with people you choose.Only you and the other person. A message you delete is hidden but its text stays stored until the conversation or an account is deleted.
Groups: membership, role and permissions, group chat, invitations, group machines and networks, the activity log of group machines (boot, stop, join…)To let groups work and learn together.Members of that group, and site administrators for moderation. Network traffic between machines of a shared group network is relayed live between members' browsers and is not stored.
Notifications, reports you fileTo tell you about activity that concerns you and to handle moderation.Notifications only you; reports you and administrators.

You can turn off “Show me on leaderboards” in your account to keep your XP, badges and progress out of rankings, the activity feed and your public profile. The same switch controls the “live” strip of recent activity on the home page and the machine room: it shows events of the last 7 days (a new account, a machine of a given system, a network and its number of devices, a disk and its size, a new Movi chat, a lesson or certificate) with your username only if you appear on leaderboards — otherwise as “someone” — and never names, contents or anything else you made.

Movi, the AI assistant

Movi answers questions about TempMV and, after you confirm, can create machines, networks and groups for you. Answers are generated by a language model run by Groq, Inc. (United States). Each time you send a message, our server forwards to Groq the assistant's instructions and the conversation so far; Groq does not receive your name, email or account id.

  • Signed in: your chats, Movi's replies, the actions it proposed and their result, and the chat summaries are stored on our backend so you can come back to them. With each request Groq also receives a snapshot of your workspace: the names, operating system, memory, status and network settings of up to 40 machines, the names, subnets and device labels of up to 20 networks, and the names of up to 20 groups with your role. Limits: 300 requests a day, 30 messages per chat, 300 chats.
  • Signed out: you can send 3 messages. The conversation is kept only in your browser and is sent with each message so Movi has context; it is not stored on our servers. To enforce the limit, the server keeps daily counters keyed by the random id your browser generated and by a salted SHA-256 hash of your IP address — the IP itself is never stored — and deletes them after about 7 days. If you then sign in, you can move the guest conversation into your account.
  • You can delete any chat at any time; deleting your account deletes all of them. Do not share passwords, keys, health data or other sensitive personal information with Movi.
  • The site owner can read your Movi chats (questions, answers and the actions proposed) to give support, investigate abuse and improve the assistant; every chat opened this way is recorded in the audit log. Administrators can turn Movi off for an account that misuses it, with a reason you will see in the chat.
  • Movi does not take decisions about you. It only proposes actions, which run when you confirm them.

Public API tokens

If you create a personal access token for the API, we store its name, its first characters (so you can recognise it), the scopes you chose, its expiry date, when it was last used, how many requests it has made and a short rate-limit counter. The token itself is shown to you once and stored only as a SHA-256 hash. If you paste a token into the “try it” box of the API docs, it is kept in your browser's session storage until you close the tab.

Persistent disks

With an account you can create up to 3 persistent disks (5 GB in total) and attach them to your machines. A persistent disk is the machine's hard disk saved on a server we operate ourselves in Spain (it is not a third-party cloud): whatever the guest system writes to it is uploaded there when you save, power off the machine or every few minutes while it runs, and downloaded again the next time it boots.

  • What is stored: the disk image itself — which contains whatever you or the guest system put on it, including any personal data you choose to store there — and its details: name, size, used space, partition table, the machine it is attached to (id and name), creation, last write and expiry dates and whether you postponed it.
  • Who can access it: you, through your signed-in session (every request is checked against your account). Transfers use HTTPS. Administrators can see a disk's details (name, size, used space, the machine it is attached to and when it expires) and can rename it, make it permanent or delete it for support or moderation; every such change is recorded in the audit log. The disk files themselves are stored on our server and could technically be reached by the site owner when maintaining that server; we do not look inside your disks and would access one only if the law requires it or to stop clear abuse of the service.
  • How long: a disk is deleted a set time after it is created (30 minutes by default; the exact time and countdown are shown on the disk's page). You can extend it once during its last minutes, which gives it more time (60 minutes by default); when they start we warn you in the app and by email. A disk is also deleted when you delete it or your account. Deleted disks are removed from the server and are not kept in any backup — they cannot be recovered. For administration we keep a short text record of each disk — its name, size, dates, the machines it was attached to, the most space it used and why it was deleted, never its contents — for 12 months after it is deleted, or until you delete your account.
  • Do not store passwords, health data or other sensitive information on a persistent disk. You can download a disk or any of its files at any time from the Disks page.

Emails and support

  • Account emails — confirming your address, sign-in links and codes, password resets, email changes and security notices — are sent whenever they are needed. They are part of the service and can't be switched off.
  • News, tips and challenges (a weekly digest and occasional announcements, which may include product news and offers) are sent only if you tick the separate, unticked box at sign-up or switch them on later. We record when you agreed and which version of this policy was in force. You can withdraw at any time.
  • Streak reminders — at most one email on a day your daily-challenge streak is about to break — are on by default for account holders and can be switched off in your account or from any reminder.
  • Every non-account email carries an unsubscribe link that works in one click, without signing in. We keep a log of the emails sent to you (type, subject, delivery status) to detect delivery problems. Emails are sent in English from no-reply@s4nchzz.com through IONOS, our email provider in the EU.
  • Sign-up notice. When an account is created, the site owner receives an email with its username, display name, email address, language and whether it accepted news emails, to keep track of new accounts and spot abuse. It is sent from no-reply@s4nchzz.com through the same provider.
  • Support. Messages you send to support@s4nchzz.com are read from that mailbox and stored as support tickets: your email address and name, the recipients, the subject, the text of the message and the names and sizes of any attachments (the attachments themselves are not copied). If your email matches an account, the ticket is linked to it. Only administrators can read tickets.

Security, moderation and logs

  • Every table is protected by row-level security, so each person can only read what is theirs or what is public. Passwords and API tokens are stored only as hashes, and you can enable two-step verification. Administrator powers require two-step verification on accounts that have it.
  • A technical log records errors and significant events (sign-ups, email delivery, moderation actions, server errors) with your account id where relevant, a request id and, for browser errors, your user agent. Email addresses in the log are masked (for example a***@example.com) and IP addresses are not recorded. Only the site owner can read it.
  • Every administrator action on an account (edits, suspensions, bans, password or two-step resets, deletions) is recorded in an audit log with the reason, visible only to administrators.
  • For support and moderation, administrators can see the machine recipes, templates, persistent disks and personal virtual networks saved in your account, and how many Movi chats you have, and can rename, adjust or delete them. They cannot see private messages. Every such change is recorded in the audit log.
  • To prevent abuse, requests are rate-limited automatically (for example error reports, Movi messages and API calls). This does not produce decisions with legal or similarly significant effects on you.
ProcessingLegal basis (GDPR)
Account, sync, community, messages, groups, Movi, API tokens, persistent disks and their expiry notices, account emailsPerformance of the service you ask for — the terms you accept (art. 6.1.b).
Movi as a guestProviding the answer you request (art. 6.1.b); the abuse counters, our legitimate interest in keeping the service available (art. 6.1.f).
News, tips and challenges emails; Microsoft Clarity; Google AdSenseYour consent (art. 6.1.a GDPR and art. 22.2 LSSI-CE), which you can withdraw at any time.
Streak remindersLegitimate interest in helping you keep a streak you started (art. 6.1.f), with a one-click opt-out.
Security, error reports, technical log, audit log, rate limiting, moderation (including administrator access to saved items and the owner reading Movi chats), the sign-up notice to the owner, support tickets from people without an account, Google Fonts, the online counter, update noticesLegitimate interest in running, securing and improving the service and answering you (art. 6.1.f). You can object by writing to us.
Keeping records where the law requires itLegal obligation (art. 6.1.c).

How long data is kept

DataRetention
Browser storage on your deviceUntil you clear it or remove the item in the app.
Account, profile, synced data, machines, networks, posts, messages, groups, Movi chats, API tokensWhile your account exists, or until you delete the item. Deleted machines are kept as a deletion marker so your other devices learn about it.
Persistent disks (contents and details)A set time from creation (30 minutes by default), plus one extension (60 minutes by default); earlier if you delete it or your account. No backups. The details of a deleted disk are kept for up to 30 more days, without its contents.
Movi guest countersAbout 7 days.
Technical log30 days for informational entries, 90 days for warnings and errors, deleted automatically.
Email delivery log, support tickets, audit log, moderation reportsOnly as long as needed to handle the matter and to defend against claims, and at most until the applicable limitation periods expire; then deleted or anonymised.
Encrypted database backups kept by SupabaseOverwritten within 7 days.

Who else processes your data

ProviderWhat forWhere
Supabase, Inc. — processorDatabase, authentication, file storage, live channels and server functions for everything account-related, Movi and the API.EU (Frankfurt region). Privacy policy.
Our own server (no third party)Storing persistent disks, the profile pictures and screenshots you upload, and saved machine states; serving the site and the catalog's disk images.Spain.
Groq, Inc. — processorGenerating Movi's answers and chat summaries from the content described above.United States. Privacy policy.
IONOS — processorSending emails and hosting the support mailbox.EU.
Google — independent controllerAdSense ads on reading pages (only with consent); serving the Google Fonts typefaces.EU and United States. Privacy policy.
Microsoft — ClarityUsage analytics (only with consent).EU and United States. Privacy statement.
Origins of third-party disk images (e.g. copy.sh) and of images the site owner links in announcements or sponsor bannersYour browser downloads the file directly from them and they see your IP address.Depends on the origin.

We do not sell personal data or share it with data brokers. We may disclose data to public authorities only when legally required.

Transfers outside the EU

Groq processes Movi content in the United States, and Google and Microsoft may process data there too. Supabase stores our data in the EU, but it or its sub-processors may access it from other countries for support and operations. These transfers rely on the safeguards each provider offers: the EU-U.S. Data Privacy Framework adequacy decision where the provider is certified under it, or otherwise the European Commission's Standard Contractual Clauses. You can ask us for more information about these safeguards.

Advertising

Reading pages — the home page, the guides, the glossary, the course lessons, the forum, the showcase, profiles, the feed, leaderboards and these legal pages — can show ads served by Google AdSense. The advertising script is not loaded at all until you accept, and it is never loaded on the app screens (the machine room, the console, the wizard, the JSON editor, settings, chat, groups, the network designer, your account or the admin panel). App screens may show a plain sponsor link, which loads no tracking script.

If you accept, Google may set cookies and process your IP address, browser details and the pages you view in order to select and measure ads. Google acts as an independent controller for that processing. You can manage your ad settings at Google Ad Settings and withdraw consent at any time from the cookie policy page.

Usage analytics (Microsoft Clarity)

If you accept cookies, the site (in production) loads Microsoft Clarity, which records how pages are used — clicks, scrolling and mouse movement — to produce heatmaps and session replays that help us improve the design. Form fields are masked by Clarity, and personal pages (your account, the admin panel, sign-in and sign-up, messages, friends, notifications, groups and two-step verification) are hidden from the recordings entirely. We don't send your name, email or account id to Clarity. If you decline or later withdraw consent from the cookie policy page, Clarity is not loaded, or is told to stop.

Your rights

You have the right to access, rectify and erase your personal data, to restrict or object to its processing, to data portability, and to withdraw any consent at any time without affecting what was done before. Without an account, almost everything lives in your browser, so most of these are exercised by clearing this site's data. With an account, you can do most of it yourself:

  • Correct your profile and email preferences on your account page, and edit or delete your posts, messages, machines, networks, Movi chats and API tokens where they appear.
  • Download a JSON file from your account page. It contains your account and profile, synced progress, settings, library templates, bookmarks, forum posts, reactions, reports, follows, showcase entries, certificates, notifications and a summary of the emails sent to you. It does not yet include room machines, networks, friends, private messages, machine shares, groups, Movi chats, API tokens or support tickets: you can see those in the app, and we will send you a complete copy if you ask.
  • Delete your account from your account page (see below).
  • Withdraw consent for news emails in your account or from any email, and for cookies on the cookie policy page.

For anything else, write to support@s4nchzz.com from the email linked to your account (or tell us how to verify that the data is yours). We answer within one month, extendable by two more for complex requests, as the GDPR allows. For advertising, you can also contact Google directly. If you are not satisfied, you may complain to the Spanish Data Protection Agency (Agencia Española de Protección de Datos, aepd.es) or to the supervisory authority where you live.

Deleting your account

When you delete your account, the following is erased immediately: your sign-in account (email, password hash, two-step factors), your profile, avatar and uploaded screenshots, synced progress and settings, library templates, room machines, personal networks, showcase entries, follows, certificates, notifications, friendships, private conversations (for both participants), machine shares, group memberships, Movi chats and summaries, API tokens and email preferences. Your persistent disks are removed from our server shortly after (normally within an hour).

Some things are kept without being linked to you, so other people's conversations keep their context: forum threads and replies keep their place but their text is replaced with “[deleted]” (a thread's title remains), group chat messages remain without an author, groups you owned remain for their members, and reports you filed remain without your name. Support tickets, the email delivery log and the audit log are unlinked from your account but keep what they recorded (for example your email in a ticket) for the periods above; notifications already delivered to other people may still mention your old username. The technical log keeps your account id until its entries expire (30 or 90 days), and Supabase's backups may hold a copy for up to 7 days. Data in your browser stays until you clear it.

Children

This site is not directed at children under 14. Accounts are only for people aged 14 or over (the age of digital consent in Spain, art. 7 LOPDGDD), and by signing up you confirm that you are. If we learn that an account belongs to someone younger, we will delete it. Parents or guardians can write to us for that.

Changes

If this policy changes materially, the date at the top changes, signed-in users are told in the app, and consent is requested again where it matters.