CloakID Privacy Policy

Last Updated: September 22, 2026

1. Introduction

Welcome to CloakID. This Privacy Policy explains how CloakID (“we,” “us,” or “our”) collects, uses, and protects your personal data when you use our browser-fingerprinting protection service — a browser extension paired with a processing gateway hosted in the European Union (the “Service”). Our commitment to privacy is not just a legal obligation but a core part of our product.

  • Data Controller: CloakID is the Data Controller for your personal data, meaning we determine the purposes and means of processing.

  • Privacy contact: For any question or request about your personal data, contact us at privacy@cloakid.net.

2. Summary of Key Points (The First Layer)

We believe in radical transparency. Here’s a brief, plain-language summary of our data practices. For full details, please read the sections below.

  • We Do Not Store Your Browsing History: The core of our service processes the pages you visit on supported websites — as the website delivered them to your browser, including pages you are logged in to — to rewrite what the website can learn about you. Your login credentials and the website’s cookies are never sent to us. Websites you exclude in the extension are never sent. To build the site knowledge that will let CloakID protect you without sending the page at all, we keep one copy of each protected page’s address and content, not linked to your account, for 120 days during the pilot programme (180 days thereafter), then delete it. We do not keep a per-user record of the addresses you visit.

  • We Minimize Data: We only collect and log the absolute minimum data necessary for our service to function securely and reliably. We hash all target domains before logging to prevent the storage of your browsing history.

  • You Are in Control: We operate on the principle of explicit, opt-in consent for any non-essential data processing.

  • We Do Not Sell Your Data: We never have, and we never will. Our business model is subscription-based, not surveillance-based.

3. The Personal Data We Process

In the interest of complete transparency and to comply with GDPR, the following section summarizes our data processing activities.

a. Data provided by you:

  • Category: Contact Information
    • Data Points: Name, email address, phone number.
    • Purpose: To create and manage your account, provide customer support, and communicate with you about the service.
    • Legal Basis: Performance of a contract.
  • Category: Payment Information
    • Data Points: Transaction ID, subscription status, billing cycle dates. Payment card details are collected and processed by our payment provider (Frisbii, formerly Billwerk+) and never reach our systems.
    • Purpose: To process payments for the CloakID Pro service.
    • Legal Basis: Performance of a contract.

b. Data collected automatically:

  • Category: Usage Data
    • Data Points: Features used, session duration, interaction with the user interface.
    • Purpose: To improve the product, identify bugs, and understand user behavior.
    • Legal Basis: Legitimate interest.
  • Category: Technical Data
    • Data Points: Browser type, operating system, IP address (anonymized).
    • Purpose: To ensure the security and reliability of our service and to prevent abuse.
    • Legal Basis: Legitimate interest.
  • Category: Site-Knowledge Store
    • Data Points: Address (URL) and content of each protected page as delivered to your browser, and the time of capture — one copy per address, not linked to your account.
    • Purpose: To build the site knowledge base that enables protection without sending the page (“advice” mode).
    • Legal Basis: Explicit consent, given at enrollment; limited at any time by excluding websites in the extension.
    • Retention: 120 days during the pilot program; 180 days thereafter.

4. Lawful Basis for Processing

Our processing of your personal data is grounded in a valid lawful basis under GDPR. For processing the pages you visit (including the Site-Knowledge Store), the only basis we use is your explicit, informed, unambiguous, and freely given consent, which you provide when you sign up for and use our Service. For other data, we rely on the performance of our contract with you or our legitimate interests in maintaining a secure and functional service.

5. Data Sharing and Third-Party Sub-processors

We use a limited number of trusted third-party services to help us operate. We have verified the GDPR compliance of each vendor and have a Data Processing Agreement (DPA) in place where required. Our sub-processors are: Hetzner (hosting, EU), Auth0 (identity), Frisbii (payments), Grafana Labs (operational logs), Google (database backups), Discord Inc. (community support) and Mailchimp (waitlist emails).

Marketing and Waitlist Communications: We use Mailchimp to manage our relaunch notification list and to send updates to users who have provided explicit consent. When you sign up for our waitlist, your email address is shared with Mailchimp for the sole purpose of fulfilling these communications.

6. Data Retention

We practice data minimization and storage limitation. We only keep your personal data for as long as necessary to fulfil the purposes for which it was collected, as described above.

7. International Data Transfers

Our primary infrastructure is located within the European Union. If any data is transferred outside the EU, we ensure that legal safeguards, such as Standard Contractual Clauses, are in place to protect your data.

8. Your Data Protection Rights

Under GDPR, you have fundamental rights over your data. We have engineered our service to honor these rights. You have the right to:

  • Access: Request a copy of all personal data we hold about you.

  • Rectification: Correct any inaccurate data, such as your email address.

  • Erasure (“Right to be Forgotten”): Request the complete and irreversible deletion of your account and all associated data.

To exercise these rights, please contact us at privacy@cloakid.net. We will respond to all requests within one month.

Our website and Service may use essential cookies for functionality like authentication. We will provide a detailed Cookie Policy and obtain separate consent for any non-essential cookies.

10. Security Measures

We process your data with integrity and confidentiality as a core principle. We implement and maintain appropriate technical and organizational security measures, such as encryption and access controls, to protect your data against unauthorized processing, loss, or damage.

11. Changes to This Policy

We may update this policy from time to time. We will notify you of any material changes and ensure the latest version is always available in our public Trust Center.


For questions about this Privacy Policy, contact us at privacy@cloakid.net.