Privacy Policy
cloakup is built so your personal details are cloaked on your own device before your message is ever sent. This page explains what that does — and, just as importantly, what it does not do — plus what we collect, why, and the rights you have.
1. In plain language
When you type a message, cloakup detects personal data in it — names, emails, phone numbers, card and ID numbers, addresses, and similar — and replaces each with a realistic stand-in token, in your browser, before anything is sent. Only the tokenised text travels onward through the CloakAPI gateway to the AI model. The gateway and the AI providers see the stand-ins, not your real details. The map that turns the tokens back into the real values is kept only on your device and is never sent to us.
Honest by design. Cloaking strongly reduces what you expose, but it is not magic. Tokenised data is not anonymous — it is still personal data, because it can be turned back into the real details on your device. And detection is best-effort (see §6). We will never tell you we "can never see anything" or that your data is "zero-risk".
2. Who we are
cloakup is operated by Klokk Nettablering (a Norwegian business), which is the data controller. cloakup runs on CloakAPI's infrastructure, hosted at Hetzner in Germany (EU).
3. What we collect
3.1 Account
- Your email address (to create and secure your account and to send sign-in links).
- Basic settings and your subscription status.
3.2 Billing
- Payments are handled by Stripe. We receive a Stripe customer reference, your plan, and invoice history. We never see or store your full card number — Stripe is the payment processor.
3.3 Your conversations
- The cloakup chat runs in your browser. When you send a message, our relay passes the already-cloaked text to the AI and streams the answer back — the relay does not store your conversation. Your chat history in the chat window lives on your device.
- If you are signed in and use saved chat history, conversations are stored in our EU database so you can return to them — and they are stored in cloaked form: the details we detected were already replaced by stand-in tokens on your device before anything reached us, and the token map that reverses them stays only in your browser.
- Because detection is best-effort, any personal detail the detector did not catch is stored or sent as you typed it. Review anything highly sensitive before you send.
3.4 Operational data
- Minimal technical logs (timestamps, error/status codes, which model was used) to run the service and bill correctly. These do not contain your prompt or response text.
3.5 What we never do
- We do not use your conversations to train any AI model — not ours, not a provider's.
- We do not sell your data, and we do not run third-party advertising trackers.
- The on-device token map (the thing that could re-identify a stand-in) is never sent to us.
4. Legal basis (GDPR)
- Providing the service — performance of our contract with you (Art. 6(1)(b)).
- Billing, invoices & tax records — legal obligation (Art. 6(1)(c)).
- Keeping the service secure — our legitimate interest (Art. 6(1)(f)).
- Optional marketing email — only with your consent (Art. 6(1)(a)), withdrawable any time.
5. Who else touches the data (sub-processors)
- Stripe — payment processing (your card and billing details).
- The upstream AI providers (e.g. Anthropic, OpenAI), reached through the CloakAPI gateway — they receive only the tokenised prompt, never the real details the engine detected (see §6 on detection's limits), and return the answer.
- Hetzner — EU (Germany) hosting for cloakup and its database.
- Amazon SES — sending transactional email (sign-in links, subscription receipts).
6. The limits — what cloaking does not protect
Being clear about the boundary is part of the product:
- Detection is best-effort. Structured identifiers (emails, phone numbers, cards, IBANs, ID numbers) are caught very reliably — close to 100%. Names are best-effort: an on-device name list catches common names, and the optional paid on-device AI name model improves coverage, but an unusual name or a non-Latin-script name can still slip through. Because of this we cannot claim HIPAA Safe Harbor or that outputs are "anonymised".
- The AI's own answer. Cloaking protects what you send; it cannot control what a model writes back or reproduces from its training data.
- Your device. Cloaking runs in your browser. Malware, a malicious browser extension, or a screen/keystroke logger on your device can see data before it is cloaked.
- Context. The shape and topic of a request still reach the AI, even when the identifiers in it are replaced.
7. How long we keep things
- Account & settings: while your account is open; deleted on account closure.
- Saved conversations (cloaked): until you delete them or close your account.
- Technical logs: a short rolling window (about 30 days).
- Invoices & financial records: the Norwegian Bokføringsloven statutory minimum of 5 years, in a minimised form, then deleted.
8. International transfers
cloakup and its database are in the EU (Germany). Some AI providers are outside the EU/EEA; when your request is routed to one, it is covered by Standard Contractual Clauses, and on-device tokenisation is the supplementary measure (in the Schrems II sense) — the identifiers are removed before the request leaves your device, so the provider receives stand-ins, not your real details.
9. Cookies
cloakup uses only essential storage — a session cookie to keep you signed in, and your browser's local storage to hold your on-device token map, settings, and receipts. No advertising or cross-site tracking cookies.
10. Your rights
Under the GDPR you can request access, rectification, erasure, restriction, portability, and can object to processing. You can delete any conversation from the interface at any time, and close your account to erase your account data. To exercise any right, email dpo@cloakapi.io — we respond within 30 days. You also have the right to complain to your data-protection authority; ours is Datatilsynet (Norway).
11. Changes
We'll post material changes here and, for subscribers, give reasonable notice before they take effect.
12. Contact
Privacy / data-protection: dpo@cloakapi.io. General: hello@cloakapi.io.