In short: we only collect the account, billing, and connection metadata needed to run the service. The data on the SSD of the dedicated Mac mini you rent is yours alone — M4Rent never reads, scans, or backs it up unless you explicitly turn on snapshots.
01What We Collect
M4Rent collects only the three categories of data listed below. Each is collected at the moment the corresponding action takes place — we don't gather anything beyond that.
| Category | Fields | Collected When |
|---|---|---|
| Account information | Email address, salted password hash, two-factor authentication status, interface language preference | At sign-up and when account settings change |
| Billing information | Order number, machine model and region, billing cycle, payment gateway receipt reference (never the full card number), invoice details (if requested) | At checkout, renewal, or invoice request |
| Connection logs | Source IP, timestamp, target port, protocol type, and session duration for Portal logins and SSH/VNC sessions | Every time a connection is established |
Connection logs record metadata only — never session content. We don't log the commands you run over SSH, don't capture VNC screen output, and don't inspect the payload of your host's inbound or outbound traffic. Sensitive payment details such as card numbers and CVVs are handled entirely by the payment gateway; M4Rent's servers never see or store them.
02Host Data Boundary
This is the single most important point in this policy. Every Mac mini you rent is dedicated hardware — there's no hypervisor layer, and therefore no technical path for the platform to transparently read your disk. Specifically:
- Ownership: everything on your host's SSD during your rental term (code, certificates, keys, build artifacts) belongs to you. M4Rent claims no rights over it whatsoever.
- No access: our ops team doesn't hold login credentials for your host. You replace the initial delivery password on first login, and the platform keeps no copy of it.
- No backups: by default, the platform makes no copy of your disk in any form. The one exception is the daily snapshot feature you can opt into from the Portal — snapshot data is encrypted and stored in the same regional storage cluster as your host, and you can delete it anytime from the Portal; it's purged from the storage cluster within 24 hours.
- Faulty hardware replacement: if replacing a faulty component requires physical access to the machine, we'll notify you by email in advance. If the SSD itself is replaced, the old drive is handled per the wipe process in Section 5.
03How We Use Data
Data we collect is used only for the three purposes below, each mapped to a specific data category:
- Billing and fulfillment: order and billing data drives charges, invoicing, expiration reminders, and renewal settlement.
- Abuse prevention and security: connection logs help us flag anomalies like credential-stuffing attempts or port scanning. When risk controls trigger, we analyze connection patterns (frequency, source, target port) — never session content.
- Service notifications: we use your email to send delivery credentials, incident notices, and expiration/wipe countdown reminders. Marketing emails are off by default — you have to opt in from the Portal, and every message includes a one-click unsubscribe.
M4Rent never sells, rents, or trades your personal data to third parties. Data is shared externally only in two situations: the minimum necessary sharing to fulfill the service (payment gateways processing charges, email providers delivering notifications), or in response to a legally binding, properly issued order from an authority with jurisdiction over the entity operating this platform — in which case we provide only the minimum data set the order requires and notify you where the law permits.
05Data Retention & Deletion
Wipe timeline after host expiration
Once your rental term ends, data is handled on the timeline below, with an email notification at every step:
At expiration: host goes offline
SSH/VNC access is closed and the host is disconnected from the network. Data stays intact on disk, and renewing restores access immediately.
72-hour grace period
Renew within 72 hours of expiration and your data comes back fully intact — no extra charges during this window.
Past the deadline: full wipe
Starting at hour 72, we run a full-disk overwrite wipe and reinstall the OS. The data is unrecoverable, and any associated snapshots are deleted at the same time.
Platform-side retention periods
- Connection logs: kept for 180 days on a rolling basis, then automatically deleted — except for records tied to an open security investigation, which are deleted within 30 days of the investigation closing.
- Billing records: retained for the minimum period required for financial records under the law applicable to the entity operating this platform, then deleted.
- Account closure: once you submit a closure request in the Portal, your account information and connection logs are deleted within 30 days. Every host under your account goes through the wipe process above. Only billing records that must be legally retained are kept, for the period noted above, and are stored decoupled from your identity.
06Cross-Border Transfer & Data Location
M4Rent's dedicated hardware nodes are located across four regions: Singapore, Tokyo, Seoul, Hong Kong, and Silicon Valley. Data location follows two rules:
- Host data never leaves its region: the data and snapshots on your Mac mini's disk always stay in the region you chose at checkout — the platform never migrates it to another jurisdiction. If you switch regions, you're responsible for migrating the data yourself.
- Platform data is centrally stored: account and billing information is stored in a data center located in the jurisdiction where the entity operating this platform is based. No matter where you access the Portal from, all data in transit is encrypted end-to-end with TLS 1.3.
Choosing a region means you understand your host data will be stored in — and subject to the data regulations of — that region's jurisdiction. The exact storage location for each region is listed on the Portal's order page.
07Your Rights & How to Exercise Them
You can exercise the following rights over your personal data held by us at any time: access (export a copy of all account and log data we store), correction (fix inaccurate account or invoice information), deletion (close your account and delete associated data), and restriction (opt out of non-essential notification processing). Submit a request through any of these channels:
- Email support@m4rent.com with "Data Rights Request" in the subject line;
- Open a ticket in the Portal under the "Privacy & Data" category;
- Submit the form on our Contact page with "Other" selected as the topic.
We confirm receipt within 3 business days and complete processing with an emailed outcome within 15 business days. To prevent impersonation, export and deletion requests must be verified through your registered email address.
08Policy Updates
This policy may be updated as the service and applicable regulations evolve. Updates are handled at two levels depending on impact:
- Material changes (expanded data collection, new use cases, longer retention periods): all users are notified by email at least 14 days before the change takes effect, and this page will display an old-vs-new version comparison at the top. Continuing to use the service after the effective date counts as acceptance; if you disagree, you may close your account before that date.
- Non-material changes (wording clarifications, updated contact channels): this page is updated directly, along with a refreshed version number and effective date.
This policy is governed by, and any disputes arising from it are subject to the exclusive jurisdiction of the competent courts in, the jurisdiction where the entity operating this platform is based. Previous versions are available on request by emailing support@m4rent.com. Current version v1.2, effective Jul 20, 2026.