Privacy
Last updated 6 September 2026.
This describes what the software actually does. It was written by reading the code, not by describing an intention.
What we collect
- Your account. The email address or Telegram username you sign in with, and the name your provider gives us. There is no password, so there is none to lose.
- Your computers. A name, the operating system, and when each was last used.
- Your profiles. The settings you create, and the logins you put in them.
- Web logs. The ordinary record a web server keeps: the address a request came from, what was asked for, and when. We use it to keep the service up and to spot abuse.
- Diagnostics. Only if you turn them on, under Account. Off by default, and nothing is sent while it is off.
We use one kind of cookie in the portal: the one that keeps you signed in. There is no advertising cookie anywhere. The website loads its typeface from Google Fonts, which means Google sees the address your browser connects from when a page loads.
How your logins are protected
Each secret you store is encrypted on its own, with its own key. That key is then encrypted with a master key belonging to the service. The database holds neither in readable form, so a copy of the database on its own opens nothing. When a browser stops, the copy on that computer is wiped.
Who can read your logins
We can, technically, and you should know that. The software has to be able to decrypt a login in order to sign a browser in with it, so the master key is a file on the same server as the database. Anyone with administrator access to that server holds both halves and could read what is stored. No amount of encryption on our side changes that; only a key we do not hold would, and we do not have that today.
What stops it being an ordinary thing that happens:
- The product has no screen and no support tool that shows a stored login to us. There is no button for it, so there is no routine way for a member of staff to read one.
- The few paths that open a secret run on behalf of your own signed-in account and check that account's permissions first.
- Every one of those paths writes a record: which account, who asked, when, and the name of the key used. The record never contains the secret itself, or its length.
- Getting at a login any other way means signing in to the server directly and running code there, which is not something the product does.
Everyone on your team can open the profiles on your account. That is what sharing an account means.
Who we share it with
We do not sell anything, and we do not share your information for anyone else's marketing. The only outside parties involved are the ones that run the product for us:
- Hetzner, who rent us the server everything runs on.
- Cloudflare, who carry traffic between you and that server.
- Sentry and PostHog, who receive error reports and usage events, and only if you have turned diagnostics on.
We will also hand over information if the law requires it, and if Clout Labs is ever sold or merged, this policy carries over with your information.
Where it lives, and for how long
Everything runs on one server in the European Union. Backups are encrypted, and copied off that server so a dead disk cannot take your data with it.
Backups are kept for 14 days, and one copy a month is kept for up to 400 days. This matters for deletion: when you ask us to delete your account we delete it from the live database, and the copies inside those backups go as each backup expires. We do not reach into a backup to remove one account, because a backup that has been edited is a backup nobody can trust to restore.
Your choices
- Turn diagnostics off, under Account.
- Remove a computer, under Devices. It loses access immediately.
- Ask us for a copy of your data, or to delete it. We do this whether or not you have a plan.
- If you are in the European Economic Area or the United Kingdom, you can also complain to your local data protection authority.
Age
The software is a business tool for adults. You must be at least 18 to use it, and we do not knowingly collect anything from anyone under 18.
Changes
We may update this page. If a change matters we will post the new version here with a new date and tell you through the portal.
Contact
[email protected], or t.me/cloutlabs.
An earlier version of this page was adapted from Automattic's Privacy Policy, published under a Creative Commons Attribution-ShareAlike 4.0 licence. This page is available under the same licence.