1 minute read

Lock

Data minimization is a foundational principle of CloakID’s design: we collect only the minimum data necessary to operate the service. Privacy

Updated August 2026: this post has been revised to describe CloakID’s current architecture — a browser extension paired with a secure EU processing gateway.

How does it work?

CloakID is a browser extension paired with a secure processing gateway hosted in the EU. The extension presents supported sites with a common, consistent persona instead of your unique fingerprint; the gateway processes page content to support those protections. Data minimization is applied as an engineering principle throughout — see our Privacy Policy for exactly what is processed and why.

How can I be sure?

Shield We won’t ask you to take our word for things we haven’t proven. We describe what is protected and what is not, the extension shows its real protection state per site, and a working “forget me” gives you complete deletion of your account and data on request. We have engaged an independent security firm at the scoping stage; a full third-party audit has not yet been performed — and we won’t claim otherwise.

Why the EU?

Because jurisdiction is part of the design. No law requires us to keep your connection or browsing data — the EU’s highest court has repeatedly struck down blanket data-retention mandates, and the GDPR requires us to minimize and delete. We are an EU company on EU infrastructure, outside the reach of extraterritorial access laws like the US CLOUD Act. Data that was never kept cannot be handed over later: a legal order can only reach forward, never backward.

Everybody collects data today. What data is collected?

Only the minimum needed to run and improve the service, and any non-essential data processing is strictly opt-in — disabled by default, under your explicit consent. Our Privacy Policy is the authoritative description of what is collected and why.