Privacy Policy
Last updated September 2026
DockerHub has no accounts and no servers of its own. Everything it shows you is read live from machines you already control, and the details it needs to reach them are kept on your device.
Server details and credentials
When you add a server, DockerHub stores what it needs to reach it: the address, the port, the username, and a password or private key. Passwords and keys are written to that device's keychain. Everything else is written to a local database on the device.
None of it is transmitted anywhere except to the server you are connecting to, at the moment you connect to it. There is no DockerHub account, no sign-in, no sync service, and no server of ours in the middle of the connection.
Removing a server removes its stored secrets from the keychain along with it.
What DockerHub reads from your servers
Container names, images, logs, statistics, environment variables and file contents are read from your own servers over your own SSH connection and displayed on screen. They are not uploaded, copied to any service, or retained after the screen showing them is closed, beyond ordinary caching on the device so a list does not have to be refetched on every glance.
Nothing is installed on your servers to make this work. DockerHub speaks to Docker over an ordinary SSH session, the same way the official command-line tool does.
Analytics
Analytics is off unless you turn it on. If you do turn it on, it records anonymous counts of which features are used and which errors occur, so that time is spent fixing what is actually broken.
It never records the things that would identify you or your infrastructure:
- No server names, addresses, hostnames or ports
- No usernames, passwords or keys
- No container, image or volume names
- No log lines, command output, environment values or file contents
Alerts while away
DockerHub can optionally run a small watcher on one of your servers that reports container events to a webhook address. That address is one you choose and enter yourself — it might be your own notification service, or a third party's.
The events sent to it include container names and image names, because an alert that omitted them would be useless. Where those events go is therefore your decision and your responsibility. DockerHub never picks a destination for you and never sends a copy anywhere else. Leaving the feature switched off means nothing is sent at all.
Diagnostics export
The diagnostics export produces a file describing your app and server setup, for attaching to a support request. It is only created when you ask for it, and it goes wherever you choose to share it — nothing is sent automatically.
Values that look like secrets are hidden before the file is written, and the export shows you exactly what it hid. That redaction is deliberately over-eager, but it is a set of rules rather than a guarantee: it can only hide what it recognises. Read the preview before sharing the file with anyone.
What DockerHub does not do
Some things are easier to state as absolutes:
- No account is required, and none is offered
- No data is sold, rented or shared with data brokers
- No advertising identifiers are used and no tracking across other apps or websites takes place
- No location, contacts, photos, microphone or camera access is requested
- No copy of your servers, containers or files is kept off your device
Children
DockerHub is a tool for people who administer servers. It is not directed at children and does not knowingly collect anything from them.
Changes to this policy
If this policy changes, the updated version ships with the app update that changes the behaviour, and the date at the top of this page changes with it. A change that would send data somewhere new will be called out in the release notes, not buried here.
Contact
DockerHub is published by Elite Performance Exclusive. Questions about this policy can be sent to the support address on the Support page, which also explains what to include.