# Introducing Private Data Pod — a hosted Solid pod provider with a free tier

**URL:** https://forum.solidproject.org/t/introducing-private-data-pod-a-hosted-solid-pod-provider-with-a-free-tier/10380
**Category:** General Discussion
**Created:** [March 18, 2026, 8:42pm UTC](https://forum.solidproject.org/t/introducing-private-data-pod-a-hosted-solid-pod-provider-with-a-free-tier/10380 "2026-03-18T20:42:39Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![pod42](https://avatars.discourse-cdn.com/v4/letter/p/5f9b8f/32.png) [@pod42](https://forum.solidproject.org/u/pod42)
#### Post date: [March 18, 2026, 8:42pm UTC](https://forum.solidproject.org/t/introducing-private-data-pod-a-hosted-solid-pod-provider-with-a-free-tier/10380/1 "2026-03-18T20:42:39Z")

</div>

I wanted to introduce Private Data Pod — a hosted Solid pod service I’ve been building and just launched.

**What it is**

A managed pod hosting service running on Community Solid Server. The goal is to lower the barrier for non-technical users to get a Solid pod without having to self-host — free to start, no credit card required.

**Free tier · Pro tier**

- **Free** — 1 GB pod, full Solid protocol support, connect any compatible app

- **Pro** — 10 GB + daily backups, $9.99/month

**Pod privacy**

One thing I spent time on: pods are private by default. The root ACL is set to owner-only at creation, with a separate explicit public ACL on the profile/card so WebID resolution works correctly for Solid authentication. Happy to discuss the ACL setup if anyone has thoughts on better patterns here.

**Apps running on it**

I’ve also built two Solid apps that use pods for storage:

- **Pod Drive** — personal cloud storage (drive.privatedatapod.com)

- **Pod Resume** — professional resume builder (resume.privatedatapod.com)

**Looking for feedback**

Particularly interested in feedback from the Solid developer community on:

- Interoperability — are there apps or use cases you’ve tried that don’t work as expected?

- The onboarding flow for non-technical users — does the “what is a pod?” explanation land?

- Anything missing that would make it more useful as a pod provider

Thanks for building the Solid ecosystem — this wouldn’t exist without CSS and the work done on the spec.

---

<div class="post-metadata">

### Author: ![bourgeoa](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.solidproject.org/bourgeoa/32/291_2.png) [@bourgeoa](https://forum.solidproject.org/u/bourgeoa)
#### Post date: [March 19, 2026, 4:06pm UTC](https://forum.solidproject.org/t/introducing-private-data-pod-a-hosted-solid-pod-provider-with-a-free-tier/10380/2 "2026-03-19T16:06:01Z")

</div>

Are your apps open source ?  
Where can I report issue ? Example I cannot login with Solid NSS servers on `Pod Resume`

---

<div class="post-metadata">

### Author: ![pod42](https://avatars.discourse-cdn.com/v4/letter/p/5f9b8f/32.png) [@pod42](https://forum.solidproject.org/u/pod42)
#### Post date: [March 19, 2026, 5:07pm UTC](https://forum.solidproject.org/t/introducing-private-data-pod-a-hosted-solid-pod-provider-with-a-free-tier/10380/3 "2026-03-19T17:07:00Z")

</div>

Thanks for trying it out and the feedback. The apps are not open source at this time but that could change in the near future. I’ve added a “Get Support” link to the app, you can also email [support@privatedatapod.com](mailto:support@privatedatapod.com)

---

<div class="post-metadata">

### Author: ![sjoerdvangroning](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.solidproject.org/sjoerdvangroning/32/3031_2.png) [@sjoerdvangroning](https://forum.solidproject.org/u/sjoerdvangroning)
#### Post date: [March 20, 2026, 1:28pm UTC](https://forum.solidproject.org/t/introducing-private-data-pod-a-hosted-solid-pod-provider-with-a-free-tier/10380/4 "2026-03-20T13:28:31Z")

</div>

Excellent you are providing this service.

I think it is fundamental for a POD provider to put on the website of the service who you are and where data is hosted.

---

<div class="post-metadata">

### Author: ![pod42](https://avatars.discourse-cdn.com/v4/letter/p/5f9b8f/32.png) [@pod42](https://forum.solidproject.org/u/pod42)
#### Post date: [March 20, 2026, 4:58pm UTC](https://forum.solidproject.org/t/introducing-private-data-pod-a-hosted-solid-pod-provider-with-a-free-tier/10380/5 "2026-03-20T16:58:56Z")

</div>

Thank you for the recommendation, I’ve added those details to the site.

---

<div class="post-metadata">

### Author: ![ewingson](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.solidproject.org/ewingson/32/454_2.png) [@ewingson](https://forum.solidproject.org/u/ewingson)
#### Post date: [March 21, 2026, 12:02pm UTC](https://forum.solidproject.org/t/introducing-private-data-pod-a-hosted-solid-pod-provider-with-a-free-tier/10380/6 "2026-03-21T12:02:52Z")

</div>

@sjoerdvangroning

I have that info already for years in the terms, but they are in textfiles on a different server:

[https://serverproject.de/files/solidweb\_org\_terms.txt](https://serverproject.de/files/solidweb_org_terms.txt)

[https://www.serverproject.de/files/solidweb\_me\_terms.txt](https://www.serverproject.de/files/solidweb_me_terms.txt)

[https://www.serverproject.de/files/teamid\_live\_terms.txt](https://www.serverproject.de/files/teamid_live_terms.txt)

because of openness and transparency I have noted my name, pod and data location also to the respective startpages [https://solidweb.org](https://solidweb.org) [https://solidweb.me](https://solidweb.me) [https://teamid.live](https://teamid.live)

I thought this is the right behaviour in spirit of open source. wdyt ?

---

<div class="post-metadata">

### Author: ![A\_A](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.solidproject.org/a_a/32/786_2.png) [@A\_A](https://forum.solidproject.org/u/A_A)
#### Post date: [March 21, 2026, 3:53pm UTC](https://forum.solidproject.org/t/introducing-private-data-pod-a-hosted-solid-pod-provider-with-a-free-tier/10380/7 "2026-03-21T15:53:43Z")

</div>

Hi, I’ve sent you an email with some security concerns.

In general: when hosting CommunitySolidServer (or NSS) always use the [Content-Security-Policy: sandbox](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Content-Security-Policy/sandbox) header and if possible do not serve files with the html or svg content types. Allowing arbitrary html files makes it easily exploitable.

Here is some background information (though it does not show the complete attack surface): [Prevent or sanitise HTML on write by default for unauthenticated users · Issue #1596 · CommunitySolidServer/CommunitySolidServer · GitHub](https://github.com/CommunitySolidServer/CommunitySolidServer/issues/1596) & [Solid Security Considerations](https://solid.github.io/security-considerations/)
