Privacy Policy

Last updated: December 29, 2025

1. Introduction

Cloud Learn ("we," "our," or "us") is committed to protecting your personal data and respecting your privacy rights. This Privacy Policy explains how we collect, use, and safeguard your information when you use our Service in compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

2. Data Controller

Cloud Learn acts as the data controller for the personal data processed through our Service. For any inquiries regarding your personal data, please contact us at: privacy@cloudlearn.app

3. Personal Data We Collect

We collect the following types of personal data:

3.1 Information You Provide

  • Name and email address (via Google Sign-In)
  • Profile picture (from your Google account)
  • Learning preferences and progress data
  • Quiz responses and scores
  • Architecture diagrams and saved plans

3.2 Automatically Collected Data

  • Device information (browser type, operating system)
  • IP address and general location data
  • Usage data (pages visited, features used, time spent)
  • Cookies and similar tracking technologies

4. Legal Basis for Processing

Under GDPR, we process your personal data based on the following legal grounds:

  • Consent: You have given clear consent for us to process your personal data for specific purposes (Article 6(1)(a) GDPR)
  • Contract: Processing is necessary for the performance of our Service (Article 6(1)(b) GDPR)
  • Legitimate Interests: Processing is necessary for our legitimate interests in improving and securing the Service (Article 6(1)(f) GDPR)

5. How We Use Your Data

We use your personal data for the following purposes:

  • To provide and maintain the Service
  • To personalize your learning experience
  • To track your progress and generate personalized recommendations
  • To generate AI-powered content, quizzes, and solutions
  • To communicate with you about the Service
  • To improve and optimize the Service
  • To detect and prevent fraud or abuse
  • To comply with legal obligations

6. Data Sharing and Transfers

We may share your data with the following third parties:

6.1 Service Providers

  • Google Firebase: Authentication, database, and hosting services
  • AI Provider: AI-powered content generation

These providers may process data outside the European Economic Area (EEA). We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission.

6.2 Legal Requirements

We may disclose your data if required by law, court order, or to protect our rights, property, or safety.

7. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy:

  • Account data: Retained while your account is active and for 30 days after deletion
  • Learning progress: Retained while your account is active
  • Usage logs: Retained for up to 90 days for security and analytics purposes

You may request deletion of your data at any time by exercising your rights under Section 8.

8. Your Rights Under GDPR

As a data subject under GDPR, you have the following rights:

  • Right of Access (Article 15): Request a copy of your personal data
  • Right to Rectification (Article 16): Request correction of inaccurate data
  • Right to Erasure (Article 17): Request deletion of your data ("right to be forgotten")
  • Right to Restriction (Article 18): Request limitation of processing
  • Right to Data Portability (Article 20): Receive your data in a structured, machine-readable format
  • Right to Object (Article 21): Object to processing based on legitimate interests
  • Right to Withdraw Consent (Article 7(3)): Withdraw consent at any time

To exercise any of these rights, please contact us at privacy@cloudlearn.app. We will respond to your request within 30 days.

9. Cookies and Tracking

We use essential cookies to operate the Service and analytics cookies to understand usage patterns. You can control cookie preferences through your browser settings. Disabling cookies may limit some functionality of the Service.

10. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit and at rest
  • Regular security assessments
  • Access controls and authentication mechanisms
  • Secure cloud infrastructure with industry-standard certifications

11. Children's Privacy

Our Service is not intended for children under 16 years of age. We do not knowingly collect personal data from children under 16. If we become aware that we have collected data from a child under 16, we will take steps to delete such information promptly.

12. International Data Transfers

Your data may be transferred to and processed in countries outside the EEA, including the United States. We ensure adequate protection through:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions by the European Commission
  • Other appropriate safeguards as required by GDPR

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. We encourage you to review this policy periodically.

14. Right to Lodge a Complaint

If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with your local supervisory authority. For EU member states, you can find your data protection authority at: https://edpb.europa.eu/about-edpb/about-edpb/members_en

15. Contact Us

For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us at:

Email: privacy@cloudlearn.app

Data Protection Officer: dpo@cloudlearn.app