Skip to content

Legal documents

Privacy Policy

What data Cloaking.Flow collects, why it is needed, how long it is kept and what you can do with it.

Revised Aug 2, 2026

01

Who processes the data

The Cloaking.Flow service acts as the controller. Contact details for enquiries about processing are given in the dashboard and in the "Contact" section.

With respect to the data of visitors passing through the router, the service acts as a processor on the user's instructions: it is the user, not the service, who determines the composition of the traffic and the destination addresses.

02

Account data

Registration collects an email address and a password. The password itself is not stored: the database holds only the result of an irreversible cryptographic transformation (Argon2), from which the original password cannot be recovered.

In the profile a user may additionally set a display name and upload a profile picture. Both fields are optional.

An uploaded image is not stored as received. It is decoded, converted to a single format and size and written anew — only pixels end up in the file, while any accompanying data, including capture details and geotags, is lost in the process.

Technical details of sign-ins are recorded: the time, the address the sign-in came from and a device marker. This is needed to investigate cases of unauthorised access.

03

Traffic data

For every processed click the following is recorded: the visitor's address, the user-agent string, the referrer, the campaign tags from the query string, the device, browser and country derived from that data, and the decision taken together with the rule that caused it.

Addresses are stored in binary form. Their purpose is the operation of blocklists, rate limiting and fraud investigation; they are not used for marketing purposes and are not passed to third parties.

The service sets no identifying cookies for visitors and builds no cross-site profiles. The decision is made from the data of a single request.

The service neither reads nor stores the content of destination pages.

04

Why the data is needed

Account data — to provide access, offer support and settle subscription charges.

Traffic data — to perform the core function of the service: applying rules, filtering out automated requests and counting volume against the plan.

Aggregated statistics without addresses — to show reports to the user and to assess the load on the infrastructure.

The data is not used for automated decision-making producing legal consequences for visitors.

05

Legal bases

Processing of account data is based on the contract: access cannot be provided without it.

Processing of traffic data is based on the legitimate interest of the user and the service — keeping routing operational and defending against automated requests and fraud.

Separate consent is requested wherever processing goes beyond the above.

06

Retention periods

The click log is kept for as long as the user's plan provides: from fourteen to forty-five days. Once the period expires, records are deleted automatically, in whole partitions.

Aggregated statistics without addresses are kept longer — they do not allow a specific visitor to be identified.

Account data is kept for as long as the account exists and for thirty days after access ends. It is then deleted.

Sign-in records are kept for ninety days.

07

Who the data is shared with

The service does not sell data and does not pass it to advertising networks.

Data is hosted on the servers of a hosting provider engaged by the service; the provider acts on instructions and may not use the data for its own purposes.

Country lookup by address is performed locally, against a database held on the service's own server: the visitor's address is not sent anywhere in the process.

Data may be disclosed to competent authorities upon a duly issued lawful request. The user is notified of such a request unless notification is prohibited by law.

08

Data security

Access to account data is segregated: queries for data are always scoped to the owner, and another account's records are unavailable both in the interface and through a direct link.

The connection to the site and to the dashboard is encrypted. Passwords are stored only as an irreversible transformation.

Dashboard forms are protected against cross-site request forgery, and uploaded images are re-encoded, which rules out the execution of foreign code.

Absolute protection does not exist. In the event of a breach creating a risk to users' rights, the service notifies the affected users without undue delay.

09

User rights

A user has the right to obtain information about the processing of their data and to request its rectification, erasure or restriction of processing.

Profile and campaign data can be viewed and changed in the dashboard at any time.

Account deletion is carried out on request to support. Campaigns, flows, logs and address lists are deleted together with the account.

Requests concerning rights are handled within no more than thirty calendar days.

10

Children

The service is intended for professional use and is not addressed to persons under eighteen years of age. Accounts for such persons are not knowingly created.

If it becomes known that an account was created by a minor, it will be deleted together with its data.

11

Changes to this policy

A new version is published on this page with its date. The service gives advance notice of changes that materially affect users' rights.

Previous versions are provided on request to support.

12

Contact

Questions about data processing should be sent through the contact form on the site or to the support address given in the dashboard.

If the service's response is unsatisfactory, a user has the right to lodge a complaint with the competent data protection authority of their jurisdiction.