Cloak
Company

Privacy policy

Exactly what Cloak collects, what encrypted storage hides, when records disappear, and what we will never ask you to provide.

Cloak uses identity-free numbered accounts. Do not send identity documents or a full account number to support, abuse, security, or privacy inboxes.

Privacy commitments

  • No name, email address, phone number, postal address, or identity document is required to create an ordinary account
  • Cloak will never require KYC, a selfie, government identification, or source-of-funds documents to create, use, refund, or close an account
  • No advertising profiles, cross-site tracking pixels, data brokerage, or sale of customer information
  • Private Drive file contents and names are encrypted on the customer device and unavailable to Cloak
  • A privacy request or refund is verified by account control or a payment reference—not by collecting new identity data

Who and what this covers

This policy covers the Cloak website, numbered accounts, Drive, Object, sharing, billing, support, security reports, and abuse reports. “Cloak,” “we,” and “us” mean the provider of the Cloak service.

Cloak is the controller of account and service data covered by this policy. The service and this policy are governed by the laws of Belize, subject to privacy and consumer rights that cannot lawfully be waived where you live.

Account and session data

Your browser generates a random 16-digit account number. Signing in sets two protected cookies: one identifies your session without exposing the account number, and the other holds only the last four digits, used to show a shortened reference in the interface. Neither cookie contains your complete account number. Both last no longer than 30 days unless you sign out sooner. Cloak does not need a name, email address, profile, or password for ordinary account creation.

Anyone with the account number may be able to sign in. Cloak cannot use an identity document or payment card to reconstruct a lost number.

Arriving through a published referral link (a URL containing a ref code) sets a first-party cookie holding only that code, for up to one year, so a signup can be credited to the right link on a first-touch basis. Cloak stores an aggregate visit and signup count per referral code—never a per-visitor log, device fingerprint, or browsing history—and this cookie does not affect account security.

Storage and sharing data

Private Drive gives Cloak encrypted file content and encrypted names, plus encrypted size, timestamps, version and trash state, storage usage, share state, and other metadata needed to synchronize and return data. Object gives the gateway plaintext during a normal S3 request, along with bucket, object, permission, request, usage, and network metadata; the gateway encrypts content before the storage layer.

For a share, Cloak may process its creator, creation and expiry time, access state, revocation, request metadata, and password-verification state. A recipient or abuse reporter who gives Cloak a working link and password can make that shared content available to us.

A household plan links a member account's identifier to the owner's account, together with a label and storage limit the owner sets. Revoking a member marks the link revoked rather than immediately erasing it. Viewing a household member's account number uses the same two-minute, single-use reveal pattern as an Object secret key.

Redeeming a gift uses a 7-day cookie holding only the gift code, plus a record of the code, its plan or storage value, expiry, and—once redeemed—which account redeemed it. Cloak does not link a gift to the purchaser's identity beyond that purchase's own payment record.

Network, security, and diagnostics

A gateway necessarily receives an IP address, request time, route, protocol details, user agent or client version, response status, and request identifier while handling traffic. Cloak uses this data to deliver requests, rate-limit authentication, diagnose failures, secure accounts, measure reliability, and investigate abuse.

Cloak does not promise “no logs” while operational records exist. Security records must exclude file plaintext, file names, account numbers, recovery keys, share passwords, and secret access keys. Short-lived authentication rate-limit records expire with their stated window and are pruned from the active store.

Payments and refunds

Cloak processes plan, amount, currency, payment status, date, and a transaction or payment token. A payment provider may independently receive wallet, card, bank, email, billing, device, or network data under its own policy. Cloak sends the payment provider a separate payment token instead of the account number.

Most crypto payment methods are additionally recorded on their native public blockchain: the paying wallet address, amount, and timing are permanently visible to anyone, independent of Cloak or the payment provider. This is a property of the blockchain itself, not something Cloak or its payment provider can turn off. Choose a payment method and wallet accordingly if on-chain linkability to your identity is a concern.

Refunds never require identity verification, KYC, or source-of-funds documents. Account control plus a receipt, transaction hash, or payment token is sufficient. Accounting and fraud records are retained only for the period required by applicable law or an active dispute, then deleted or irreversibly de-linked where the law permits.

Support and reports

Telegram support stores only the ticket identifier, Telegram chat identifier, support tier, status timestamps, short-lived reply routing, and Telegram message identifiers needed to relay and delete a ticket. Cloak does not store Telegram names, usernames, profile data, or support message bodies in its ticket database. Telegram independently processes and may retain messages and account data under its own privacy policy.

Priority support confirms the signed-in account's plan through a 10-minute one-time check. A basic-support agent may send the same kind of one-time link when an account-specific question requires proof of control. These checks can't be reused or reversed, are deleted on first use or expiry, and never require a full account number or identity document. A shortened account reference and current plan are sent once to the support administrator but are not written to the Cloak ticket record.

Closed support tickets and their routing metadata are automatically deleted within 24 hours. A customer or support administrator can erase them immediately after closure. Cloak also asks Telegram to delete tracked ticket messages when the platform permits it; Telegram's own retention and bot-deletion limits remain outside Cloak's control. Security and abuse evidence is kept only as long as the investigation, remediation, appeal, or legal requirement needs it.

How we use information

  • Provide, authenticate, synchronize, share, meter, and bill the service
  • Secure accounts and infrastructure, prevent fraud, and enforce published policies
  • Answer support, privacy, abuse, and vulnerability reports
  • Measure aggregate reliability and improve the service without building advertising profiles
  • Comply with a binding legal duty and challenge demands that are defective or overbroad

Service providers and disclosure

Infrastructure, network, payment, email, and support providers process limited data only to perform their contracted service. Cloak limits each provider to the data needed for that role and uses separate payment tokens where possible so a payment provider does not receive the account number.

Cloak's @cloak.uno addresses (support, privacy, security, abuse, legal) are hosted by a third-party email provider. That provider can technically read the plaintext content of any message sent to or from those addresses under its own policies — Cloak's encryption model does not extend to email. If you are sending anything sensitive, encrypt it first with the public key published at cloak.uno/pgp.txt.

We do not sell, rent, or trade personal data. We disclose available records only with your direction, to a necessary service provider under confidentiality duties, to protect a person from an imminent threat, or when compelled by valid legal process. We seek to narrow overbroad demands and notify the affected account unless legally prohibited or unsafe.

See the Transparency page for how Cloak reviews legal demands, publishes aggregate enforcement data, and explains what encryption prevents us from producing even under compulsion.

Deletion and retention

Signing out deletes the session cookie from the browser; otherwise it expires within 30 days. Authentication rate-limit records expire after their displayed window. Routine gateway and security logs are deleted within 30 days unless they are needed for an active incident, abuse review, or legal obligation.

Deleting a file moves it through the trash and version-retention period selected in the dashboard. After permanent deletion or account closure, active encrypted content and account mappings are deleted within 30 days and encrypted backup copies expire within 90 days. Closed support tickets and routing metadata are deleted within 24 hours or immediately on request. Payment records are kept only for refunds, disputes, accounting, and periods required by Belize law; legal holds end when the underlying duty or proceeding ends.

Your choices and rights

Use the dashboard to access, export, correct, or delete account data that is available there. Email [email protected] for access, correction, restriction, objection, portability, or deletion requests available under applicable law. We verify control with the account number or a scoped proof—not a new identity dossier.

Some rights depend on where you live. Once the operating entity is published, this section will name the responsible data-protection authority and any EU, UK, Swiss, California, or other rights that apply to that operator and customer.

Children

Cloak is not directed to children under 13 and does not knowingly collect their personal information. A person who cannot legally agree to these policies in their location may use Cloak only with a parent or legal guardian who accepts responsibility for the account.

Policy changes

We publish the effective date and a plain summary of material changes. A change that materially reduces privacy applies prospectively after reasonable notice, except an urgent security or legal change. Continuing to use a paid service is not treated as consent where law requires a more specific choice.

Make a privacy request