Legal
Privacy Policy
Last updated: September 20, 2026
Cloudy is built to be private by default. This policy explains what we collect, why, who we share it with, and the controls you have. It covers every surface: the website, the desktop app, the command-line tool, the mobile app and the editor extension.
1. What we collect
- Account data — your email address and, if you signed up with a password, a salted hash of it. No password ever reaches us in plain text.
- Sign-in data — if you sign in with Apple, Google, Microsoft or GitHub, we store that provider's account identifier for you and the email it returns, so several sign-in methods can reach one Cloudy account. We never receive your password from a provider, and we don't keep their access tokens.
- Usage data — messages sent, agent credits spent, tokens consumed, which models you pick, and timestamps, so quotas work and abuse is caught.
- Chat content — your messages and attachments, stored so your history works across devices. Chats are never used to train AI models.
- Session data — a login cookie for the website and a long-lived device token for the apps, which keep you signed in. Our apps run no advertising trackers, tracking pixels or client-side analytics; the one third-party service in the advertising path is our ad partner, described in section 4.
- No billing data — Cloudy has no paid plan for users, so we never collect payment details, card numbers, or billing addresses from users at all.
2. What happens to your messages
To answer you, your message (and any attachments) is sent to the AI model you selected, through its provider's API. Those providers process it under their own terms to generate a reply. We route only what is needed for the reply. We do not sell your conversations, and advertisers never see them: the ad request described in section 4 carries a short excerpt of your recent messages to our ad partner for the sole purpose of choosing which ad to show, and advertisers receive aggregate counts — impressions and clicks — never your words or your identity.
3. The coding agent and your files
The coding agent works only inside the folder you open in the desktop app, the CLI or the editor extension. Your files stay on your machine: they are read and written locally, and only the parts needed to answer you (a file's contents, a command's output) are sent to the model, the same way a chat message is. We never copy your repository to our servers.
If you turn on remote control, your running agent sessions report status, tool steps and approvals to the Service so your other signed-in devices can follow and answer them. That relay carries it under your own account, is off by default, and can be switched off at any time on the machine running the agent.
4. Ads and how Cloudy stays free
Cloudy is free and funded by sponsor banners, and the sponsor slot is always labelled as one. Ads are matched and served by our advertising partner, Gravity (trygravity.ai), against the conversation you are having: when a slot is filled we send Gravity a short excerpt of your recent messages — at most the last few, each cut off at 400 characters — the page you are on, an account identifier, and the device signals Gravity requires to detect fraud (your IP address and your browser or app user-agent). Gravity returns the ad and the links that record the impression and the click, which our server follows on your behalf. Nothing is written to your browser and no advertising cookie is set.
Advertisers never receive your messages or your identity; they see aggregate counts such as impressions and clicks. If you are signed out, the ad request carries no conversation and no account identifier, only an anonymous session scope. When the slot is filled from Cloudy's own inventory instead — a direct advertiser, or Cloudy's own house placement — no conversation excerpt leaves the Service at all. Clicking a sponsor takes you off Cloudy, where that site's own policies apply.
5. Your choices
- Delete — you can delete your account at any time. Deleting removes your account row, the provider sign-in rows linked to it, your device tokens and your usage ledger. Chat history is deleted with it. There is no subscription record to cancel, because there is no subscription.
- Access & export — email us and we will provide a copy of the data associated with your account in a portable format.
- Remote control — off by default, and switchable off from the machine running the agent whenever you like.
6. Security
Passwords are hashed, sessions are signed cookies, device tokens are stored in your platform keychain where one exists, and traffic is encrypted in transit. We follow industry practice for a service of this size and scope, and we limit internal access to production data. No system is perfectly secure; if a breach affects you, we will notify you and any required regulators.
7. Retention
Account and usage records live as long as your account does. Chat history lives until you delete it or your account. We hold no billing records for users, because users are never billed; advertiser campaign and payment records are kept as long as tax and accounting rules require. Backups roll off on our normal schedule.
8. Children
Cloudy is not directed at children under 13 (or the equivalent minimum age in your region), and we don't knowingly collect their data. If you believe a child has created an account, contact us and we will remove it.
9. Your rights
Depending on where you live (for example the EU/EEA, UK, or California), you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise any of them, contact us — we respond to verified requests within 30 days, and never discriminate against you for asking.
10. International transfers
We and our model providers may process data in the United States and other countries. Where required, transfers rely on appropriate safeguards such as Standard Contractual Clauses.
11. Changes
If this policy changes materially, we'll announce it in the app (and by email for significant changes) before it takes effect.
Privacy questions? Email privacy@cloudy.chat. The allowances this policy refers to are 25 messages and 70 agent credits a day, with a 3-message trial for visitors without an account.