Privacy Policy

Last updated: July 23, 2026

Draft for counsel review
CloudLeek's operating entity and mailing address are still being finalized. This draft must be reviewed by qualified counsel before paid public launch. It is not legal advice.

1. Scope and controller

This Policy applies to the hosted CloudLeek Service at cloudleek.com. CloudLeek's operating entity, controller identity, and mailing address are pending formation and must be added before paid public launch. Self-hosted deployments are controlled by their operators and require their own privacy notice.

2. Information we process

  • Account and profile: email, password hash, name, username, profile fields, preferences, role, plan, and account status.
  • Learning: progress, notes, flashcards, quizzes, projects, lab sessions and output, reviews, certificates, badges, and portfolio settings.
  • AI mentor: prompts, relevant lesson context, responses, usage, and safety metadata. Do not submit sensitive or confidential information.
  • Billing: Stripe customer, subscription, payment-status, invoice, refund, and review-order identifiers; CloudLeek does not store full card numbers.
  • Security and technical: IP address, user agent, authentication and audit events, request logs, rate-limit data, diagnostics, and error reports.
  • Communications: support, privacy, security, and other messages you send, plus delivery and consent records.
  • Public information: content you choose to publish through profiles, portfolios, progress, badges, or certificates.

3. Purposes and legal bases

We process data to provide and personalize accounts and learning features; authenticate users; grade and secure labs; process payments; fulfill reviews; provide support; prevent fraud and abuse; debug and improve reliability; meet legal obligations; and protect users, CloudLeek, and others. Depending on location, our legal bases are performance of a contract, legitimate interests, legal obligation, and consent. You may withdraw consent without affecting earlier lawful processing.

4. Cookies and browser storage

We use first-party authentication and security cookies and store your theme preference locally. We do not use advertising cookies or cross-site behavioral advertising at launch. Browser controls may affect functionality.

5. Providers and disclosures

We disclose only what is reasonably needed to service providers such as AWS and RDS (hosting and database), Stripe (billing), Amazon SES (email), Anthropic (AI mentor), and server-side Sentry (error monitoring, if enabled). Providers process information under their contracts and may operate in other countries. Organization administrators may access workspace information permitted by their role. Public features disclose the information you elect to publish.

We may also disclose information to comply with law, protect safety and rights, investigate abuse, or complete a merger, financing, reorganization, or asset transfer with appropriate safeguards. CloudLeek does not sell personal data or share it for cross-context behavioral advertising at launch.

6. Retention

  • application, security, and Sentry logs: ordinarily 30 days;
  • support correspondence: ordinarily 24 months;
  • consent and withdrawal evidence: ordinarily 6 years;
  • billing and tax records: ordinarily 7 years; and
  • deleted-account data in backups: scheduled to expire within 35 days.

We may retain information longer where law, litigation holds, fraud prevention, security, or dispute resolution requires it. Account deletion may anonymize audit records, while processors and backups complete their own deletion cycles.

7. Your rights and appeals

Depending on your location, you may request access, correction, deletion, portability, a list of relevant third parties, restriction, objection, or withdrawal of consent. You may also opt out of sale, targeted advertising, or qualifying profiling; CloudLeek does not conduct those activities at launch. We do not discriminate for exercising privacy rights.

Email privacy@cloudleek.com. We may verify your identity and authorized-agent authority. We target a response within 30 days, subject to lawful extensions. If we deny a Connecticut request, reply with “Privacy Appeal”; we will explain the result and how to contact the Connecticut Attorney General. We honor legally required universal opt-out signals, including Global Privacy Control, for applicable processing.

8. Export and deletion

Settings may provide an export of covered account, profile, learning, project, review, consent, lab, and billing-identifier data. Exports exclude passwords, security controls, protected internal records, other people's data, and information we cannot lawfully disclose. Deletion is subject to required billing, tax, security, backup, and legal retention. Contact privacy support if an in-product tool does not cover your request.

9. Children and teens

CloudLeek is not directed to children under 13 and does not knowingly allow them to create accounts. Users aged 13 through 17 require legally valid parent or guardian involvement where applicable. Teen AI mentor access and public profiles should remain disabled unless the required guardian and teen choices are recorded. Contact us if you believe a minor's data was collected improperly.

10. Security and international transfers

We use administrative, technical, and organizational safeguards designed for the nature of the data, but no system is perfectly secure. Report concerns to security@cloudleek.com. Data may be processed in the United States and provider locations; we use legally required contractual or other transfer safeguards where applicable.

11. Changes and contact

We will update the date and provide additional notice or consent for material changes where required. Privacy questions and requests: privacy@cloudleek.com. Other channels appear on our contact page.