Legal
Privacy Policy
What CloudService collects, what it does not, and how it handles your data while proxying AI requests and running your prepaid account at cloudservice.services.
This document is provided for transparency; contact our support page with questions. CloudService is operated by CloudService (independently operated online service) and is designed to collect as little personal data as it needs to run your prepaid account.
1. What we collect
We collect the limited data needed to issue keys, process payment, meter usage, and support you:
- Account identifiers: your chosen username and, where you provide one, an email address used for account and support communication.
- API key material: we store a one-way hash of each key and a short non-secret display prefix. The recoverable key secret is held in encrypted form so you can retrieve it; the raw key is never stored in plain text.
- Usage metadata: per-request records such as timestamp, model, token counts, computed cost, request status, and rate-limit counters — used for billing, quotas, abuse prevention, and the usage views in your dashboard.
- Payment and fulfillment records: order and payment references, amounts, currency, billing type, processor status, and — when required by PayU or returned by Razorpay or PayPal — the contact email and phone number used for fulfillment, fraud review, support, and payment disputes. Provider evidence is reduced to the fields needed to reconcile the transaction.
- Technical and trial anti-abuse data: the IP address and network bucket seen by our edge, plus basic request metadata such as user agent, used for security and rate limiting. When you request a free trial, your browser also combines its user agent, language, platform, processor count, device memory, screen dimensions, color depth, and canvas rendering into a one-way SHA-256 fingerprint. Only the resulting fingerprint hash is sent to CloudService; the individual browser values and canvas image are not sent separately. We store the hash with the trial email and network information to detect repeat trial claims. Before a trial is issued, we also validate the email domain and may send only that domain (the part after
@, not the mailbox name or full email address) to our configured DeepSeek provider for a disposable-domain risk classification. - Support correspondence: the content of messages you send to support, including the order IDs and details you choose to share.
2. Prompts, requests, and conversations
For API requests you send to the gateway, CloudService proxies your prompt and the upstream response between your client and the upstream AI provider. That request and response body pass through our systems transiently to complete the call and are not retained as part of your usage history; what we keep for a proxied API request is the usage metadata described above (model, token counts, cost, status), not the message content.
For Web Chat and Studio, your conversations are a saved feature: to show your chat history and let you continue a thread, the messages you send and receive in those surfaces are stored, scoped to your workspace and key, until you delete them or the conversation. If you do not want a conversation retained, delete it, or use the API directly instead of the stored-chat surfaces.
Separately, upstream AI providers receive your request in order to generate a response and handle it under their own privacy and data-use policies, which are outside our control.
3. What we do not collect
- No card numbers or payment credentials. Checkout is handled by the enabled third-party processor you select, which may include PayPal, Cryptomus, PayU, or Razorpay. We never see or store your card number, bank or UPI credentials, wallet keys, or recovery phrase. We do retain the bounded payment, order, and contact records described in section 1.
- No plain-text API keys. We store only a hash and an encrypted secret; we do not keep a plain-text copy of your key.
- No account passwords, because CloudService authenticates by API key rather than by password.
- No cross-site advertising profiles of you. We do not sell your personal data or your prompt content.
5. Third parties
We share data with a small set of providers only as needed to run the service:
- Upstream AI providers. Your request content is sent to the upstream provider that serves the chosen model, so it can generate a response, under that provider’s policies.
- Trial fraud classification. For trial signup only, the email domain may be sent to our configured DeepSeek provider to classify known temporary/disposable mailbox services. The full email address, IP address, and browser fingerprint are not included in that classifier request.
- Payment processors. PayPal, Cryptomus, PayU, and Razorpay may handle checkout when shown as enabled. They return the bounded transaction evidence needed for fulfillment and reconciliation; your payment credentials stay with the selected processor.
- Administrative payment notifications. A server-configured notification service may receive a bounded purchase summary — amount, order reference, key type and prefix, username, and checkout email or phone — in the fixed private operator account used for fulfillment follow-up. When a new key is first fulfilled, its recoverable secret may also be sent once to that same protected operator chat for delivery support; top-up alerts do not resend an existing full key.
- Administrative support notifications. When a new support ticket is created, the same private operator notification service may receive only the ticket number, whether it came from a signed-in or public flow, and its routing priority. The ticket subject, message, name, username, email, order details, and API-key material stay in the authenticated CloudService dashboard.
- Infrastructure and content delivery. Hosting and network providers (including Cloudflare at the edge) process requests to deliver the service.
- Google (advertising and analytics measurement). The public marketing site loads a Google tag for conversion measurement and optional GA4 page analytics, with advertising and analytics storage denied by default as described in section 4. Data the tag transmits is handled by Google under its own privacy policy.
We do not sell your personal data. We may disclose data where required by law, to enforce our terms, or to protect the security and integrity of the service, its customers, and its upstream providers.
6. Retention
Retention follows the purpose of each record rather than one blanket period:
- Proxied API bodies: pass through transiently and are not retained after the request completes.
- Web Chat and Studio content: remains available until you delete the conversation/project or close the associated account, subject to bounded operational backups.
- Usage, billing, processor, and audit ledgers: remain for the statutory accounting, fraud, chargeback, and dispute period applicable to the transaction. These immutable records may outlive account closure.
- Trial anti-abuse records: remain while needed to enforce the one-trial rule and investigate abuse; deleting them immediately would allow the same trial to be claimed again.
- Support tickets: remain while open and afterward while needed to resolve the request or a related transaction dispute.
Ask our support page for the retention basis that applies to a specific record or request account closure. We will delete or de-identify eligible data and explain any record we must retain.
7. Your choices and rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can already:
- View your usage and billing history from your dashboard.
- Delete stored Web Chat and Studio conversations.
- Rotate a compromised key and request account closure.
To exercise a right that is not self-service, contact us at our support page. Some records — such as those needed for billing, security, and legal compliance — may be retained even after a deletion request, to the extent the law allows.
8. Security
CloudService uses layered technical and administrative controls appropriate to a prepaid API gateway:
- HTTPS protects traffic in transit across public CloudService endpoints.
- API keys are matched by one-way hash; a recoverable copy is encrypted rather than stored as plain text.
- Signed-in sessions use opaque server-validated tokens in HTTP-only cookies, and workspace routes verify membership before reading customer data.
- Rate limits, audit records, scoped provider entitlements, and payment-webhook signature checks reduce abuse and unauthorized fulfillment.
- Administrative credentials and provider secrets are server-side configuration and are not returned in customer APIs.
No service can guarantee absolute security. If you believe a key or account is compromised, rotate or suspend it and contact support without sending the full secret.
9. Changes
We may update this policy as the service evolves. When we do, we will revise the “Last updated” date above. Continued use of CloudService after a change constitutes acceptance of the updated policy.
10. Contact
Privacy questions and requests can be sent to support page. Never include a full API key, wallet secret, recovery phrase, or private status link in a message — share only your CloudService order ID and the details requested.