Skip to content
Gateway
Home Security Pricing Docs
Sign in

Privacy Policy

Last updated: 3 October 2026

1. Overview

This Privacy Policy explains how Gateway collects, uses, stores, discloses, and protects personal information when you use our platform and Services.

By using Gateway, you agree to the handling of information as described in this policy, subject to any rights you have under applicable law.

If you do not agree, you must not use the Services.

This policy should be read alongside our Terms of Use.

IN OTHER WORDS,

This is our Privacy Policy... exciti- you've read this before on our Terms page, haven't you?

Same deal here: we've summarised the key points on the right so you don't have to translate legal prose for fun.

This one covers what data Gateway handles, why we need it, where it can go, and what control you have over it.

2. Who We Are

Gateway is operated by Next Generation Media Limited (NZBN 9429053566256), based in New Zealand.

References to “Gateway”, “we”, “us”, or “our” in this policy refer to Next Generation Media Limited and the services it operates under the Gateway brand.

IN OTHER WORDS,

We're Gateway, operated by Next Generation Media out of New Zealand.

Now you know who's behind the curtain.

3. What We Collect

We may collect the following types of information.

Information you provide or make available to Gateway:

  • your name, email address, and other profile information supplied by a sign-in provider;
  • information about sign-in methods you link to your Account;
  • Server details, including names, hostnames or IP addresses, ports, SSH usernames, selected regions, platform information, and Server identity information;
  • Server credentials or access material you choose to provide or authorise Gateway to create and manage;
  • instructions, requests, operation inputs, and other information submitted through Gateway or an authorised Third-Party Service;
  • files and file metadata you transfer through Gateway;
  • support requests, communications, preferences, and security choices; and
  • billing, subscription, plan, dispute, and transaction information associated with your Account.

Information Gateway receives while performing work:

  • command, operation, service, system, log, file, network, package, container, storage, process, and other Server information requested as part of work performed through Gateway;
  • job status, output, results, errors, timestamps, and related operational records; and
  • information needed to maintain Activity, security, audit, and abuse-prevention records.

Information collected automatically:

  • IP address;
  • browser or user-agent information;
  • session and request metadata;
  • usage, reliability, performance, and security telemetry; and
  • technical signals used to detect abuse, fraud, unauthorised access, or service failures.

We aim to collect only information reasonably necessary for the purposes described in this policy.

IN OTHER WORDS,

We collect the basics: who you are, the servers you connect, what you ask Gateway to do, what comes back, files you transfer, and enough technical and billing information to keep the whole thing running.

Gateway administers servers, so occasionally the answer to “what data do you process?” is “the thing ChatGPT just asked your server about”.

We do not need your life story.

4. Your Data

You retain ownership of Your Data.

We do not claim ownership of information merely because it is stored by or passes through Gateway.

We use Your Data only as described in this policy, our Terms of Use, or as otherwise authorised by you or required by law.

IN OTHER WORDS,

Your data is yours, not ours.

Gateway touching it doesn't make it ours. That's not how ownership works, despite what some SaaS terms seem to imply.

5. How We Use Your Data

We use information to:

  • create, authenticate, secure, and maintain your Account;
  • provide, maintain, operate, and improve the Services;
  • connect to and perform requested work on your Servers;
  • return requested Server information and operation results to you or an authorised Third-Party Service;
  • provide file-transfer functionality;
  • process subscriptions, billing, payments, refunds, disputes, and account entitlements;
  • maintain job, Activity, security, and audit records;
  • scan transferred or submitted files for malicious content where applicable;
  • detect, investigate, prevent, and respond to fraud, abuse, security incidents, and unauthorised access;
  • troubleshoot failures and improve service reliability;
  • respond to support requests and communications;
  • comply with legal obligations; and
  • enforce our Terms of Use.

We do not sell or rent personal information.

We do not share personal information with third parties for their own advertising or marketing purposes.

IN OTHER WORDS,

We use your data to make Gateway work, let ChatGPT work on the servers you connected, move files, bill you if you're paying us, keep a record of what happened, and stop people doing silly or malicious things.

We are not building a side hustle selling lists of sysadmins to advertisers.

6. Sharing Your Data

We may disclose or make information available to:

  • Third-Party Services you choose to connect to Gateway, to the extent necessary to perform requests or return results through that service;
  • identity providers you choose to use for sign-in;
  • payment providers, including Stripe, where necessary to provide paid Services and manage billing;
  • infrastructure, storage, security, and service providers, including Cloudflare, that process information on our behalf to operate Gateway;
  • professional advisers or service providers where reasonably necessary to operate, protect, or enforce the Services;
  • a purchaser, successor, or relevant adviser in connection with a genuine proposed or completed corporate transaction involving Gateway or Next Generation Media Limited; and
  • law-enforcement agencies, regulators, courts, or other authorities where disclosure is required or permitted by law.

Where a user separately and expressly enables a feature that submits file content to an external malware-analysis provider, the selected content may be disclosed to the provider identified for that feature.

We do not sell personal information.

IN OTHER WORDS,

We don't sell your data. Ever.

We share what is actually needed with the companies that help Gateway exist - infrastructure, sign-in, billing - and with services you've deliberately connected.

If the law validly requires us to hand something over, we're not going to pretend a Privacy Policy gives us a force field against a court order.

7. Third-Party Services

Gateway may connect to Third-Party Services at your request, including ChatGPT.

When you authorise a Third-Party Service to use Gateway, requests from that service may cause Gateway to access your Servers, and information or results requested through that connection may be returned to the Third-Party Service.

The Third-Party Service's own terms and privacy policy apply to information it receives.

We are not responsible for the privacy practices of Third-Party Services.

You should review the privacy terms of services you connect to Gateway.

IN OTHER WORDS,

Connect Gateway to another service and, unsurprisingly, that service gets the information Gateway returns to it.

We built Gateway. We did not build every service it can talk to, and we don't get to write their privacy policies.

Choose your connections accordingly.

8. Server Credentials & Access

Gateway handles Server credentials and access material only to provide authorised access to Servers you connect.

Your Server credentials are not disclosed to ChatGPT as part of normal Gateway operation.

If you provide a Server password during setup, Gateway may encrypt and retain that password for up to 24 hours where necessary to complete or retry setup, after which it expires from normal use.

Gateway may create and retain other Server access material, such as SSH identity material, for as long as the Server remains connected or until that access is replaced or revoked.

If you give Gateway a secret for use by your agents, including a sudo password for a Server, Gateway stores it encrypted. A secret you choose to save is retained until you delete it. A one-time secret is deleted after the job that uses it, or within 24 hours if no job uses it. If you ask Gateway to keep your Server setup password for sudo, it is retained as a saved secret on the same terms.

We restrict access to Server credentials and access material and use them only for authorised Gateway operations, security, recovery, or other purposes necessary to provide the Services.

You should not place Server passwords, private keys, or other credentials directly into a ChatGPT conversation when Gateway provides a dedicated setup or secret-entry flow for that information.

IN OTHER WORDS,

Gateway needs keys to open the doors you deliberately gave it.

ChatGPT doesn't get handed those keys.

If you use a password to set a server up, Gateway can hold it briefly while setup finishes. Long-term server access stays with Gateway until you rotate it, remove it, or disconnect the server.

Secrets you give your agents through Gateway, sudo passwords included, are stored encrypted. One-time secrets vanish after one use or a day; saved ones stay until you delete them.

And please don't paste passwords into chat just because technically you own the keyboard.

9. Files & Malware Scanning

Files transferred through Gateway may be temporarily stored to provide file-transfer functionality.

Gateway may scan transferred files using internal malware-detection systems to protect users, our infrastructure, and third parties.

Proactive scanning of files already present on a connected Server is performed only where the relevant Account setting authorises that behaviour.

Submission of file content to an external malware-analysis provider requires separate authority and is not implied merely because ordinary Gateway file scanning is enabled.

A malware scan or absence of a detection is not a guarantee that a file is safe.

IN OTHER WORDS,

Files passing through Gateway may get checked for malware.

That does not mean “scanner didn't complain” magically becomes “this file is unquestionably safe forever”.

And scanning something on your server, or sending a sample to an outside service, needs the relevant permission first. We rather like consent.

10. Data Storage & Security

We use reasonable technical and organisational measures intended to protect information handled by Gateway, including:

  • encryption in transit;
  • encryption or other protective controls for sensitive stored information where appropriate;
  • access controls and authentication safeguards;
  • restricted internal access to customer information;
  • separation of sensitive credential handling from ordinary user-facing access; and
  • monitoring for abuse and unauthorised access.

No system is completely secure.

You are responsible for maintaining the security of your own Account, sign-in methods, Servers, and systems outside our control.

IN OTHER WORDS,

We lock things down with encryption, access controls, and monitoring, and particularly sensitive access gets treated particularly sensitively.

No system on Earth gets an “absolutely impossible to breach” sticker, though.

Keep your side of the fence locked too.

11. Data Retention

We retain different categories of information for different periods according to the purpose for which the information is required.

Current operational retention includes:

  • job output and detailed job records: generally retained for seven days after the job finishes;
  • temporary transferred-file artifacts: generally retained for up to 24 hours;
  • Server setup passwords: where supplied, retained for no more than the temporary setup period described above, generally up to 24 hours, unless you ask Gateway to keep it for sudo, in which case it is a saved secret;
  • stored secrets, including sudo passwords for a Server: one-time secrets are deleted after the job that uses them, or within 24 hours if unused; saved secrets are retained, encrypted, until you delete them;
  • Server records and durable access material: retained while the relevant Server remains connected, subject to security, replacement, and deletion processes;
  • Activity, security, abuse-prevention, and audit records: retained for as long as reasonably required for account history, service integrity, security, fraud prevention, dispute resolution, legal compliance, or other lawful purposes;
  • billing and transaction records: retained for as long as reasonably required for accounting, tax, dispute, fraud-prevention, and legal obligations; and
  • Account and identity information: retained while your Account is active and for a reasonable period afterwards where required for security, legal, billing, dispute, or operational purposes.

Removing a Server does not necessarily remove Activity, security, billing, or audit history relating to that Server.

We may retain information for longer where required or permitted by law, or for a shorter period where it is no longer reasonably required for a lawful purpose.

Where possible, information that no longer needs to identify an individual may be deleted, aggregated, or de-identified.

IN OTHER WORDS,

Different things have different shelf lives.

Job output: about a week. Files Gateway is temporarily holding for transfer: about a day. A setup password: also about a day at most. A one-time secret: one use or a day, whichever comes first. A saved secret: until you delete it.

The boring-but-important history - security, billing, disputes, and the record of what happened - can stick around longer when there's a real reason to keep it.

We don't keep personal information forever just because storage is cheap.

12. Access, Correction, Deletion & Control

You may request access to or correction of personal information we hold about you, subject to applicable law.

You may update certain Account information and security settings directly through Gateway.

You may remove connected Servers and revoke access using the controls we provide.

You may request deletion of your Account or personal information by contacting hey@trygateway.sh.

Deletion is subject to information we must or may lawfully retain for purposes including:

  • billing and accounting;
  • fraud, abuse, and security prevention;
  • audit integrity;
  • resolving disputes or enforcing legal rights; and
  • complying with legal obligations.

We may need to verify your identity before acting on an access, correction, or deletion request.

IN OTHER WORDS,

Want to see or fix your personal information? Ask.

Want Gateway off a server? Disconnect it.

Want the Account gone? Email us.

Deleting an Account doesn't give either of us a time machine, though - some billing, security, audit, or legal records may still need to exist.

13. Cookies & Tracking

Gateway uses essential cookies or similar technologies for authentication, session management, security, and user preferences.

We may process limited technical information through infrastructure and security providers for reliability, performance, fraud prevention, and abuse detection.

We do not use advertising trackers to build behavioural advertising profiles, and we do not sell behavioural data.

If we introduce non-essential analytics or tracking that requires consent under applicable law, we will provide appropriate notice and controls.

IN OTHER WORDS,

We use cookies to keep you signed in, remember the things that need remembering, and stop obviously bad traffic.

No creepy ad tracker following you around the internet trying to work out which brand of rack server you'll buy next.

14. Children

You must be at least 13 years old to use Gateway.

If you are under 18 years old, you must have any permission from a parent or legal guardian required by our Terms of Use or applicable law.

We do not knowingly offer Gateway to children under 13.

If we become aware that we have collected personal information from a person under 13 in circumstances where we should not have done so, we will take reasonable steps to delete or otherwise address that information.

IN OTHER WORDS,

You need to be at least 13 to use Gateway.

Sorry, younger server administrators. The rack can wait.

If you're under 18, make sure you've got whatever parental or guardian permission the rules require.

15. Legal Basis - EEA & United Kingdom

If the GDPR or UK GDPR applies to our processing of your personal information, we rely on one or more of the following legal bases as appropriate:

  • contract: processing is necessary to provide Gateway and perform our agreement with you;
  • legitimate interests: processing is necessary for legitimate interests such as service reliability, security, fraud prevention, abuse prevention, support, and improving Gateway, where those interests are not overridden by your rights;
  • consent: you have given consent for a particular processing activity where consent is the appropriate basis; and
  • legal obligation: processing is necessary to comply with applicable law.

IN OTHER WORDS,

For our friends in Europe and the UK: we need an actual legal reason to process your personal information.

Usually that's because we're providing the service you asked for, keeping it secure, you specifically agreed to something, or the law requires it.

16. Your Rights - EEA & United Kingdom

Where the GDPR or UK GDPR applies, and subject to the conditions and exceptions in applicable law, you may have rights including:

  • access to personal data we hold about you;
  • correction of inaccurate personal data;
  • deletion of personal data;
  • restriction of processing;
  • objection to certain processing;
  • data portability; and
  • withdrawal of consent where processing is based on consent.

To exercise these rights, contact hey@trygateway.sh.

We may need to verify your identity before completing a request.

IN OTHER WORDS,

If European or UK privacy law applies to you, you've got the usual collection of access, correction, deletion, objection, portability, and consent rights.

Drop us a line and we'll sort out what applies.

17. Data Location & International Processing

Gateway is operated from New Zealand but uses global and regional infrastructure.

Information may be stored or processed in New Zealand and in other jurisdictions, including locations where our infrastructure providers, payment providers, identity providers, connected Third-Party Services, or regional Gateway infrastructure operate.

The region selected for a Server may affect where certain Server operations or temporary file transfers are processed. Selecting a Gateway region does not necessarily mean that all Account, billing, security, or control-plane information is stored exclusively in that region.

A Private Region provides dedicated Gateway infrastructure as described by the Service, but does not create a general data-residency commitment unless we expressly agree otherwise.

Where New Zealand privacy law applies to an overseas disclosure of personal information, we take steps required by the Privacy Act 2020, including using applicable safeguards, legal mechanisms, or informed authorisation where required.

IN OTHER WORDS,

Gateway is a New Zealand company. Gateway itself, however, has passports.

Server work can happen in different regions, and the companies that help us run Gateway operate internationally too.

Choosing “Europe” for a server doesn't teleport every billing record and Account setting into Europe and lock the door behind it.

If you need a specific data-residency promise, it needs to be one we've actually made.

18. Data Controller

For the purposes of the GDPR and UK GDPR, where applicable, the controller responsible for the processing described in this policy is:

Next Generation Media Limited
NZBN 9429053566256
New Zealand

Contact: hey@trygateway.sh

IN OTHER WORDS,

For GDPR purposes, the buck stops with Next Generation Media.

There. Somebody had to own the paperwork.

19. Complaints

If you have a privacy concern, please contact us first at hey@trygateway.sh so we have an opportunity to investigate and respond.

If you are in New Zealand, you may also make a complaint to the Office of the Privacy Commissioner.

If you are in the EEA or United Kingdom and applicable law gives you that right, you may complain to the relevant local data-protection authority.

IN OTHER WORDS,

Think we've handled your information badly? Tell us.

We'd quite like the opportunity to fix a problem before everyone starts exchanging increasingly formal letters.

You can also go to the relevant privacy regulator where the law gives you that right.

20. New Zealand Privacy Act

We handle personal information in accordance with the Privacy Act 2020 where that Act applies.

This includes obligations relating to lawful and necessary collection, reasonable security, access and correction, retention, use, disclosure, overseas disclosure, and notification of notifiable privacy breaches.

IN OTHER WORDS,

It does what it says on the tin.

We're a New Zealand company, and New Zealand has a Privacy Act. We follow it.

21. Changes to This Policy

We may update this Privacy Policy from time to time.

If changes are material, we will provide reasonable notice, for example by email or through Gateway.

The updated policy will apply from the stated effective date.

Your continued use of Gateway after that date constitutes acceptance of the updated policy to the extent permitted by law.

IN OTHER WORDS,

We might tweak this policy as Gateway changes.

Big changes? We'll tell you.

Keep using Gateway after they take effect? The updated policy applies, subject to whatever rights the law says you keep regardless.

22. Contact

For privacy-related enquiries, requests, or complaints, contact:

Next Generation Media Limited
hey@trygateway.sh
New Zealand

IN OTHER WORDS,

Got questions?

Drop us a line at hey@trygateway.sh.

We're friendly, we promise.

© 2026 Next Generation Media. All rights reserved.

Security Pricing Docs Support Terms Privacy Notices

ChatGPT is a trademark of OpenAI, and Claude is a trademark of Anthropic. Gateway is an independent product and is not affiliated with, endorsed by, or sponsored by OpenAI or Anthropic.