Legal

Privacy Policy

Last updated: July 7, 2026

Who we are

Cloady is a cloud application platform operated by NeptoLab("we", "us"). This policy explains what data we collect when you use cloady.com and the services deployed through it, why we collect it, and the choices you have. Questions go to hello@cloady.com.

What we collect

  • Account data — your email address and display name. If you sign in with Google or GitHub, we receive your name, email, and avatar from that provider; we never see your password for those accounts.
  • Billing data — payments are processed by Stripe. We store a reference to your Stripe customer and subscriptions; card numbers never touch our servers.
  • Workspace and application metadata — workspace names, members, application configuration, environment variables (values you mark as secret are encrypted at rest), domains, and deploy history.
  • Your deployed content — the code, containers, and data volumes of applications you deploy. This is your content; we host it and access it only to operate the platform or when you ask us to help.
  • Integration tokens — if you connect the GitHub App, we store the grant needed to list repositories and clone the ones you deploy.
  • Operational logs — build logs, container status, and request logs needed to run and debug the platform.

What we don't do

  • We don't sell your data or share it with advertisers.
  • We don't use third-party advertising or cross-site tracking cookies. The only cookies we set are the ones that keep you signed in.
  • We don't read the contents of your deployed applications except to operate the service, investigate abuse, or at your request.

How we use data

To provide the service: authenticate you, run your deployments, route traffic to your applications, issue TLS certificates, bill your subscriptions, send transactional email (sign-in links, invitations, alerts), and keep the platform secure and reliable.

Sub-processors

We rely on a small set of providers to run Cloady:

  • Stripe — payments and subscription management.
  • Google / GitHub — optional sign-in and the deploy-from-repository integration.
  • Infrastructure providers (OVH, Contabo, Hetzner) — the servers your applications run on, located in the region you choose.
  • Porkbun — DNS for cloady.io application URLs.
  • Better Stack — uptime monitoring and our public status page.

Where your data lives

You choose the region your applications and their data run in when you activate it — currently across Europe, North America, and Asia-Pacific. Application data stays in the region you picked. Control-plane data (accounts, workspace metadata, billing references) is stored on our infrastructure in the United States and Europe.

Retention and deletion

  • Deleting an application permanently removes its workloads and its data volumes.
  • Deactivating a region cancels its subscription; it requires the region to be empty first.
  • Account deletion (requested through support) removes your personal data and workspaces you solely own. Billing records are retained as long as tax and accounting law requires.

Your rights

You can access, correct, export, or delete your personal data. Most of it is directly editable in the dashboard; for anything else, email hello@cloady.comand we'll respond within 30 days. If you're in the EU/EEA or UK, these rights follow the GDPR, including the right to lodge a complaint with your supervisory authority.

Security

All traffic is encrypted in transit with TLS. Secret environment variables and integration credentials are encrypted at rest. Workspaces are isolated from one another at the infrastructure level. API tokens are stored as one-way hashes and can be revoked at any time.

Changes

We'll post any changes to this policy here and update the date above. For material changes we'll notify you by email or in the dashboard before they take effect.