Last updated: 15 September 2026
Who we are
Cloudline (trycloudline.space) is an independent product operated by Om Yaduvanshi, an individual based in India (“Cloudline”, “we”). For your Cloudline account and early-access request, we decide how data is used (we are the data controller, or data fiduciary). For analytics about the visitors of a website that uses Cloudline, we process data on behalf of that website’s owner.
Visitors of websites that use Cloudline
When someone visits a site with the Cloudline script, we record one anonymous event with only:
- the page path and query (for example
/pricing?utm_source=newsletter), without the fragment or the domain, and with any value that looks like an email address removed; - the referring website’s hostname only (for example
google.com); - the browser window size (for example
1440x900); - for engagement events only: seconds the page was visible, scroll depth (25/50/75/100%), or the label of a tracked button;
- the day and time the event arrived.
Events aren’t linked to each other, to a person, or across websites.
What is never collected
- No cookies, local storage or anything else is placed on visitors’ devices.
- No IP addresses, raw user-agent strings, fingerprints or device identifiers are stored.
- No names, emails or form contents from the sites being measured.
People who use Cloudline
- Early-access requests: your email address, the page you requested access from, when you asked, and whether you’re approved.
- Your account: your email address and a securely hashed password, or, if you choose “Continue with Google”, the basic profile details Google shares (such as your name, email and profile picture link). This is managed by our authentication provider.
- Your sites: the domains and names you add, and their analytics as described above.
- In your browser: your sign-in session and a few dashboard preferences, kept in local storage. No cookies. See the Cookie Policy.
- Security and audit logs: errors and security events, such as rejected sign-ins, admin actions and sites added or deleted, with email addresses shortened (for example
om***@gmail.com). - Emails you send us: whatever you choose to include, used only to answer you.
This website measures its own traffic with Cloudline, under exactly the rules above. The sign-in page is not measured.
Why we use it
- To provide Cloudline (account, sites, dashboard, sign-in emails): necessary to perform our agreement with you.
- To keep it secure and working (logs, alerts, backups, abuse prevention): our legitimate interest in protecting the service and its users.
- To manage early access (reviewing requests, emailing you when you’re approved): at your request.
- To meet legal obligations, when the law requires it.
We don’t sell data, don’t use it for advertising, don’t make automated decisions about you, and don’t use it to train AI models.
Who processes data for us
- Supabase: database and authentication.
- Vercel: website hosting and the application servers.
- Our email delivery provider, connected to our authentication system: sends invite, sign-in and password emails.
- Telegram: delivers notifications to the operator about new early-access requests (including the requester’s email address) and operational alerts.
- GitHub: runs automated checks and stores encrypted nightly database backups.
- Google: only if you choose “Continue with Google”.
Each provider processes data only to deliver its service to us.
Where data is stored
Cloudline’s database and application servers run in Singapore. Our providers may also process data in other countries, including the United States and the country where you are, to deliver their services. Where the law requires it, these transfers rely on the providers’ standard contractual safeguards.
How long we keep it
- Analytics events: about 13 months, then deleted automatically.
- Deleting a site removes all of its events immediately.
- Encrypted backups: kept for 30 days, then deleted automatically.
- Application and security logs: kept by our hosting provider for a short period, then deleted.
- Early-access and account data: until you ask us to delete it, or we close the service.
Security
All traffic is encrypted (HTTPS with HSTS). The database is reachable only from our servers, with row-level security switched on, and every dashboard request is checked against your account so nobody can see another user’s sites. Backups are encrypted, admin access is limited to the operator, and suspicious activity triggers alerts. No system is perfectly secure; if a breach affects your personal data, we will tell you and the relevant authorities as the law requires.
Your rights
Depending on where you live (for example under the GDPR in the EU and UK, or India’s Digital Personal Data Protection Act), you can ask us to:
- give you a copy of your data, or send it to you in a portable format;
- correct or update it;
- delete it;
- stop or restrict certain uses, or withdraw consent you gave;
- nominate someone to exercise these rights for you.
Email omyaduvanshi98@gmail.com. We reply within 30 days, and it’s free. You can also complain to your data protection authority. If you visited a website that uses Cloudline, we can’t identify you from its analytics; please contact that website’s owner.
If you run a website with Cloudline
Mention your analytics in your own privacy notice, and don’t put personal data in page URLs or click labels. We process your visitors’ analytics only to provide the service to you, under our Terms of Service. Need a data processing agreement? Email us.
Children
Cloudline is not meant for anyone under 18, and we don’t knowingly collect their data. If you believe a child has given us personal data, email us and we will delete it.
Changes to this policy
We’ll update the date above when this policy changes, and email account holders about significant changes before they take effect.
Contact and grievances
Privacy questions, requests and complaints go to Om Yaduvanshi, who is responsible for data protection at Cloudline: omyaduvanshi98@gmail.com.