Please read this document carefully. It forms part of the terms governing Cloak and should be reviewed with the related policies.

Scope

Reports may concern the public website, forms, checkout integration, payment webhooks, activation systems, subscription management, or the Cloak browser extension. Third-party products and websites remain outside Cloak's control.

Protection boundary

Cloak is designed to reduce selected corporate tracking, browser recognition, ad-tech requests, and behavioral profiling in desktop Chrome. It is not an anonymizing proxy, VPN, endpoint-security product, malware defense, or protection against an internet provider, network operator, native application, operating system, logged-in account provider, court order served on another company, or state-level surveillance.

Browser-side defenses cannot observe or control every first-party or server-side system. A local receipt reports browser-visible actions and is not proof that a third party deleted data, could not recognize a user, selected a particular price for a particular reason, or acted unlawfully.

Good-faith testing

Limit testing to accounts and information you own or are authorized to use. Do not access or change another person's data, retain sensitive information, degrade service, use social engineering, send spam, test physical security, or perform denial-of-service attacks.

How to report

Use the Support form and choose the privacy, security, or legal category. Include the affected surface, clear reproduction steps, potential impact, and enough detail to validate the issue. Do not include passwords, full payment-card data, or unnecessary personal information.

Coordinated disclosure

Give Cloak reasonable time to investigate and remediate before public disclosure. We will aim to acknowledge a credible report, assess severity, communicate material progress when practical, and credit researchers who request recognition, subject to law and user safety.

No guarantee or bounty

This policy does not create a promise of payment, safe harbor from laws you violate, or immunity for conduct that harms users or systems. Any bounty or reward must be agreed in writing before testing beyond ordinary good-faith research.

Questions about this policy?

Use the Support form. Do not submit passwords, payment-card numbers, or sensitive browsing content.