Please read this document carefully. It forms part of the terms governing Cloak and should be reviewed with the related policies.

Scope

This Privacy Policy applies to the Cloak website, support and waitlist forms, checkout and subscription services, activation systems, and the Cloak browser extension. It does not control third-party websites, services, or payment systems that publish their own privacy terms.

Cloak is currently offered primarily to users in the United States. Information may be processed and stored in the United States, where privacy laws may differ from those in your location.

Information you provide

We collect information you choose to provide, such as a reply address, waitlist details, support category, support notes, purchase context, bug reports, and other information included in a request. Please do not submit passwords, full payment-card numbers, or sensitive page content through a form.

When you purchase a subscription, Stripe processes payment and billing information. Cloak receives limited transaction information needed to confirm payment, issue activation, manage access, provide support, process refunds, prevent fraud, and keep required business records. Cloak does not receive or store full payment-card numbers.

Technical and extension information

The website may receive ordinary technical information such as IP address, browser and device type, timestamps, referring pages, form-submission metadata, server logs, and security or reliability events.

The website does not load Google advertising tags or Vercel analytics scripts. First-party measurement respects explicit denial, Global Privacy Control, and Do Not Track in every region.

For first-party advertising measurement, Cloak may capture a random anonymous attribution ID plus Google click identifiers and campaign parameters present in the landing-page URL, including gclid, gbraid, wbraid, UTM fields, campaign and ad-group IDs, match type, device, and network. Cloak records limited funnel events such as landing, download-button click, checkout start, completed purchase, first successful activation, and refund. These records do not include page content, activation codes, full browsing history, session replay, keystrokes, or payment-card details.

The extension may process page URLs, page text, links, request information, page timing, selected browser and device signals, high-frequency interaction-event delivery, supported purchase-confirmation fields, visible product prices, and locally stored settings when reasonably necessary to provide its user-facing protection features. Chrome Web Store rules treat locally processed information as user data, so this policy describes it even when it is not sent to Cloak.

Cloak processes page URLs, browser-visible tracking signals, and supported shopping-page state locally in the browser to remove tracking parameters, reduce selected profiling signals, rate-limit covered behavioral telemetry, and compare supported purchase observations with later visible prices. Cloak does not upload browsing history, page contents, raw URLs, behavior-event contents, or local purchase observations to Cloak servers as part of these protections.

When a user enables shopping-session isolation, Cloak may remove session cookies and supported site storage for the merchant origin involved in that shopping session. This action is limited to the selected shopping site and is not used to inspect, collect, or transmit cookie contents.

When a user confirms Forget this store, Cloak asks Chrome to remove covered cookies and origin-scoped browser storage for the selected store and common www origin. This can sign the user out, empty a cart, remove recently viewed products, and reset site preferences. If the user separately enables automatic forgetting for a store, that per-store setting is kept locally and the same reset runs when Chrome next starts after a full exit. Automatic forgetting is disabled by default and does not run during ordinary shopping.

During initial activation, the user's checkout email and activation code are sent to Cloak's activation service and exchanged for an opaque entitlement token. After a successful exchange, the extension retains the token for later entitlement checks rather than retaining or retransmitting the raw activation credentials. A non-secret entitlement status snapshot may be stored locally so the extension can display current access status.

Where processing happens

Cloak separates browser-side protection from the services needed to run the business. Protection receipts, supported purchase observations, and the browser activity used to generate them are designed to remain in local extension storage. Website visits, checkout, activation, subscription management, support, advertising attribution, fraud prevention, and service security are separate flows and may involve Cloak systems and the providers identified in this policy.

Local processing is not the same as complete anonymity or zero data collection. Cloak cannot hide your IP address from websites, internet providers, or network operators; change records held by a merchant or another company; conceal your identity after you sign in; protect activity inside native apps; or control information collected through server-side systems.

How we use information

We use information to operate and improve Cloak, process checkout, confirm paid access, issue activation, respond to requests, diagnose failures, secure the service, prevent abuse, comply with law, maintain business records, and understand whether product features work as intended.

We use anonymous attribution records to measure whether an ad led to a download, checkout, paid subscription, activation, or refund; calculate campaign performance; and avoid counting the same Stripe event or activation twice. Stripe's client reference field carries only the random attribution ID. Cloak does not put email addresses, activation codes, or other sensitive values in that field.

Extension information is used only to provide or improve Cloak's disclosed privacy features. We do not use extension-processed browsing activity for personalized advertising, creditworthiness, lending, insurance, housing, employment, or similar eligibility decisions.

Disclosure and service providers

We may disclose limited information to vendors that provide payment processing, hosting, infrastructure, customer support, communications, analytics, reliability, fraud prevention, security, professional advice, and legal compliance. They may process information only for the services they provide to Cloak or as required by law.

When Google Ads server-side conversion reporting is enabled and legally permitted, Cloak may send Google a captured click identifier, event time, conversion value and currency, and a deduplication transaction ID. We do not send activation codes or browsing content. We do not send hashed customer contact information for enhanced conversions unless Cloak separately enables that feature with the required notice and consent.

We may also preserve or disclose information in response to valid legal process, to investigate abuse or security incidents, to protect rights and safety, or as part of a financing, merger, acquisition, reorganization, or sale, subject to appropriate confidentiality protections where practicable. Cloak can disclose only records it possesses or controls; local processing reduces what reaches Cloak but does not prevent legal process directed to merchants, internet providers, platforms, payment processors, or other third parties.

Sale, sharing, and advertising

Cloak does not sell personal information. Cloak does not share personal information for cross-context behavioral advertising and does not use extension browsing activity to build advertising profiles. If these practices change, we will update this policy and provide any notice or choice required by applicable law before the change applies.

Cloak does not sell, rent, trade, or transfer extension user data to third parties except where a transfer is necessary to provide or improve Cloak's disclosed single purpose, comply with applicable law, protect against fraud or abuse, or complete a user-consented corporate transaction. Extension user data is not used for personalized advertising, creditworthiness, lending, or unrelated profiling.

Chrome Web Store Limited Use

Cloak's use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Cloak requests only the permissions needed for its current user-facing privacy features. The packaged extension does not use remotely hosted extension code. We do not let humans read extension-processed browser data unless a user explicitly asks for support on specific material, or access is necessary for security or legal reasons.

Retention

We retain information only as long as reasonably necessary for the purpose collected, including providing access, answering support, maintaining security logs, resolving disputes, enforcing agreements, and meeting tax, accounting, or legal obligations. Retention periods vary by record type and may be extended when a legal hold, dispute, or security investigation requires it.

Raw advertising-attribution records are normally retained for up to 90 days. Purchase, refund, and accounting records may be retained longer when needed for subscription access, refund reconciliation, fraud prevention, tax, accounting, or legal obligations; campaign fields should be removed or aggregated when they are no longer needed.

Locally stored extension settings and proof records remain in the browser until removed by the product, cleared by you, or deleted when the extension is uninstalled, subject to Chrome synchronization settings you control. Valid supported purchase observations are eligible for local comparison for up to 30 days; Cloak keeps no more than 200 in that local record set.

Security

We use administrative, technical, and organizational safeguards designed for the nature of the information we handle. No storage or transmission method is completely secure, and Cloak cannot guarantee that unauthorized access, loss, or misuse will never occur.

Your privacy choices and rights

You may clear extension data, change browser permissions, uninstall the extension, manage cookies in your browser, cancel a subscription, or choose not to submit optional form information.

Where opt-in is required, first-party advertising measurement waits for consent. Declining measurement, Global Privacy Control, or Do Not Track prevents attribution collection regardless of location. You can reset your saved choice by clearing the cloak_measurement_consent cookie.

Where applicable, you may request access to or a copy of personal information, correction, deletion, information about collection and disclosure, or restriction of certain uses. You may also exercise applicable rights to opt out of sale or sharing and to limit use of sensitive personal information. Cloak does not currently sell or share personal information for cross-context behavioral advertising.

We will not discriminate against you for exercising a legally protected privacy right. We may need to verify your identity and authority before completing a request. An authorized agent may submit a request where permitted, but we may request proof of authorization and direct identity verification. Submit requests through the Support form.

Children

Cloak is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has submitted personal information, use the Support form so we can review and delete it where appropriate.

Changes and contact

We may update this policy as the product, vendors, or law changes. Material changes will be identified by a revised effective date and, when required, additional notice. Privacy questions and requests should be submitted through the Support form.

Questions about this policy?

Use the Support form. Do not submit passwords, payment-card numbers, or sensitive browsing content.