We collect what is needed to run your account and your devices, and nothing for advertising.
To run your account and devices, to charge for the service, to detect payments on the blockchain, to keep the platform secure, to answer support requests, and to send the emails the service needs: sign-up confirmation, password reset, receipts, low-balance and stop notices, team invitations. We do not send marketing emails and we do not sell or share data for advertising.
Providers act on our instructions and only for these purposes. Servers are located in the European Union and the United States; by using the service you agree to your data being processed there.
We use a session cookie to keep you signed in and, if you choose, a "trusted browser" cookie so the two-factor code is not asked every time. No analytics or advertising cookies are set.
Account and billing records are kept while the account exists and for as long as the law requires afterwards (financial records: up to 7 years). Device data is deleted when you delete the device or the account. Sign-in attempts are kept for 15 minutes for rate limiting; server logs for up to 30 days; crypto invoices that were never paid are purged periodically.
You can see and change your email and password in Account settings, see all billing records in Billing, and delete your account (with all devices) yourself. You can ask us for a copy of your data, a correction, or deletion at support@clousd.com; we answer within 30 days. If you are in the EU/EEA or UK you also have the right to complain to your local data protection authority.
Passwords are hashed, sessions are protected against fixation and brute force, two-factor sign-in is available, and the site is served over HTTPS only. Devices are isolated from each other. No system is perfectly secure; if we learn of a breach affecting your data we will notify you by email.
We may update this policy; the date at the top changes when we do, and material changes are announced by email or in the dashboard.