What is ox?
ox Cloud, at deploywithox.com, is a deployment platform: you connect a GitHub repo and ox deploys it to your own Ubuntu server with systemd and Caddy, no Docker. It is not Open-Xchange's OX App Suite or OX Security, which are unrelated products.
What does ox store, and what stays on my server?
ox keeps only what it needs to run your account. Your app and its data stay on your server.
ox keeps:
- Your GitHub login, name, picture and email.
- The servers and projects you add, and a short record of each run.
- For a failed run, its last 40 lines of output, with secrets hidden.
- Usage numbers for the charts: one-minute points for 24 hours, then 15-minute points for 30 days.
- A log of who did what in your account, with the IP address it came from, kept for 12 months.
- Your settings, like which alerts you want.
- Your plan and its Dodo Payments subscription, never your card number.
- Tokens and keys, encrypted or stored only as a hash.
- Sign-in codes for
ox login, with the IP address that asked.
- ox's own server logs, which can name your account and hold IP addresses, kept up to 5 weeks.
- A copy of its own database every hour. The newest 24 copies stay on ox's own server, and the newest 168 copies (7 days) in a storage bucket ox owns.
Stays on your server:
- Your code, builds and releases.
- Your variables and secrets. ox shows them to you but keeps no copy.
- Your databases, files and uploads.
- Backups of your services. A copy goes to your own S3 bucket only if you add one.
- Your app's logs. ox reads them only when you ask to see them.
The privacy policy has every detail, and the security docs say it in short.
Does my app's data ever leave my server?
Only to do what you ask. Logs you open, rows you browse in Explore, and backups you download pass through ox to your screen. Your variables pass through ox when you view or save them, when ox copies them to a new staging copy or preview, and when it checks which ones a refused deploy still needs. ox does not save them.
Your server also sends ox its health, its usage numbers and the output of each run while it runs. Your code goes from GitHub straight to your server, with a short-lived, read-only token for that one repo. Alert emails go out through Resend. You choose which: a failed run or backup, a crashing process, a site or server that stops answering, high memory or CPU, a nearly full disk, or a finished deploy. Each says what happened, and for a failed run the start of its error.
ox has no analytics and loads no third-party scripts. It never reads your app's data for its own use.
What is a server, and where do I get one?
A server is a computer in a data center that you rent by the month. Companies like Hetzner, DigitalOcean, Vultr and Linode rent them for about $5–24 a month. Pick a fresh one running the latest Ubuntu LTS. We test every release on servers with 4 GB of memory.
How do I sign up?
Sign-ups are open: sign in with GitHub. Your first sign-in creates your account, and there's no password. ox is free during the beta, and nothing is charged.
Do I need to know Linux or Docker?
No. You paste one command on your server once, and everything after that happens in the dashboard. ox doesn't use Docker, and you won't need to log in to the server. If you can push code to GitHub, you can use ox.
How does ox reach my server?
Through a connection your server opens. The small ox agent on it dials out to ox over an encrypted connection, so no port is opened and ox holds no SSH key. Every command ox sends is signed, and the agent refuses anything unsigned, old or repeated. It only answers ox's fixed list of requests, so there's no way to run an arbitrary command through it.
Can my AI agent deploy?
Yes, with the ox CLI. Run ox login once and approve it in your browser. Then your AI can run ox deploy myapp --wait, read ox logs and check ox services. Every command takes --json and exits with an error when something fails.
What happens if an update fails?
Your live app keeps running. ox checks everything it can before it changes anything. If a step still fails, ox tells you which step, why, and how to fix it.
Which languages work?
JavaScript and TypeScript (npm, pnpm, Yarn, Bun), Python (uv, Poetry, pip, Django, FastAPI), Go, Rust, PHP and plain websites. ox reads your project files to pick the right versions.
Can I leave?
Yes. Your server and your data were always yours, your database backups are standard pg_dump files, and your variables live on your server. When you delete your account, ox removes only its agent from each server (or tells you the one command to run there), and your apps, databases and Caddy keep running with nothing managing them. Deleting a project instead removes its app and database, and sudo ox uninstall deletes everything ox created on the server, backups included, so download what you want to keep first. Uninstall leaves the security settings in place. How to leave lists what to copy.