Your data in the panel
The panel keeps a record of you: how you sign in, where you were signed in from, what it has told you, and what you asked it to do. This page says what that record holds, how long each part of it is kept, and how to get a copy.
Written for: Customer, Reseller, Administrator
The panel keeps a record of you: how you sign in, where you were signed in from, what it has told you, and what you asked it to do. This page says what that record holds, how long each part of it is kept, and how to get a copy.
Getting a copy
Mijn account → Your data → Download the file.
You get one file, in JSON, with everything the panel has under your name. It is the same file an administrator would get if you asked them for it — there is no shorter version for customers.
What is in it:
- Who you are. Your address, your display name, your language and theme, when the account was made and when you last signed in.
- Where you were signed in. Every session the panel still has, with the address it was opened from and the browser it used.
- How you sign in. Your passkeys by name and device, whether you have a second factor, how many recovery codes are left.
- What you may do, and for whom. Your memberships, the customers or resellers they are for, and when they were granted.
- What the panel told you. Your notifications, what you have read, and the settings that decide which messages you get and by which route.
- What you asked the panel to do. Every line in the audit log with your name on it: the operation, the object, the address you were at, and whether it was allowed.
- Conversations with the assistant, if you have had any, and what they cost.
What is not in it: passwords, second-factor secrets, recovery-code hashes, session tokens and API keys. Those are not information about you — they are the locks on it, and a file containing them would be a file that opens your account. Every one of them appears as the word redacted, so you can see the column is there and see that its value was left out.
How long each part is kept
The full table, with the exact period for every kind of record and where in the code that period is enforced, is in docs/privacy.md. In short:
| Sessions | removed a week after they could no longer be renewed |
| Hand-offs to webmail and phpMyAdmin | one day |
| One-time password links | thirty days after they are used or expire |
| Notifications | ninety days, or the newest 200 |
| Finished tasks | ninety days |
| Conversations with the assistant | your provider chooses; ninety days by default |
| The audit log | kept, and never pruned |
Everything a website itself produces — request logs, visitor reports, mail delivery records — stays on the server that serves the site and is summarised before anything reaches the panel. Visitor reports have the addresses removed before they are written.
If you would rather look through the file than scroll it, it is ordinary JSON:
jq '.places[] | select(.count > 0) | {table, count, holds}' corecp-person-*.jsonThat lists every place with something in it, and the sentence saying what that place holds.
Having your data removed
Ask your provider. There is no button for it on your own account, and that is deliberate: removing a person also removes their login, and if a hosting account still hangs off that login, removing it would take the hosting account with it. So it is done by somebody who can see what else is attached, after the account is closed or handed over.
One thing survives it, and it is worth knowing before you ask: the audit log keeps the address that acted. That log is what answers "who changed this server, and when" after an incident. It is protected against editing — each line is chained to the one before it — so a line cannot be quietly rewritten, not even to remove a name. Everything else goes.
What the panel never collects
- No analytics, no tracking pixels, no advertising identifiers.
- No fonts, scripts or images from anybody else's server, so no third party learns which panel you are using.
- Nothing is sent to an AI provider unless you ask for it in that moment.
- Mail delivery records never carry a subject or a message body.