CloudSynth Ltd ("we", "us") operates cloudsynth.dev. This policy explains what personal data we collect, why, and your rights. CloudSynth Ltd (Company No. 17369736), 128 City Road, London, EC1V 2NX, United Kingdom, is the data controller. We are UK-based and we design for the UK GDPR and EU GDPR; our application data is hosted in the EU (AWS, eu-central-1 — Frankfurt).
What we collect
- Account data — when you sign in with GitHub or Google, we receive your name/username, email address, and avatar from that provider. We never see your provider password.
- Learning data — your progress, the code you submit to exercises, verification results, hints you've revealed, and your language preferences. This is the product working as expected: it's how we grade your work and let you pick up where you left off.
- Billing data — purchases are processed by Stripe. Stripe collects and processes your payment details; we receive only what we need to grant access and meet our own tax obligations as the seller (e.g. what you bought, when, its status, and billing address) — never your card details.
- Technical data — logs (IP address, browser, pages visited) for security, debugging, and abuse prevention.
Why we process it (lawful bases)
- To provide the Service (contract): accounts, grading, progress, purchases.
- To keep the Service secure (legitimate interests): sandbox abuse prevention, rate limiting, logs.
- To communicate (contract / consent): transactional email always; product news only if you opt in, with unsubscribe in every message.
- To meet legal obligations: tax and accounting records tied to purchases.
Who we share it with
We don't sell personal data. We share it only with processors that run the Service:
- Amazon Web Services — hosting and application data, in eu-central-1 (Frankfurt).
- Stripe — payment processing, tax calculation, and receipts (Stripe acts under its own policies for the transaction; payouts to CloudSynth itself are handled separately via Wise, which never receives your personal data).
- GitHub / Google — sign-in (they provide your profile to us; their policies govern their side).
Where a processor is outside the UK/EEA, transfers rely on appropriate safeguards (e.g. adequacy decisions or standard contractual clauses).
How long we keep it
Account and learning data: for as long as you have an account. If you delete your account, we delete your personal data, except records we must keep for legal reasons (e.g. purchase records for tax) which are retained for the statutory period and then deleted.
Your rights
You can access, correct, export, and delete your data. Two of these are built in: Settings → Account → Export your data and Settings → Account → Delete account. For anything else — objection, restriction, or a complaint — email support@inbound.cloudsynth.dev. You also have the right to complain to the UK Information Commissioner's Office (ICO) or your local supervisory authority.
Cookies
We use strictly-necessary cookies for sign-in sessions. We don't run third-party advertising cookies. If we add analytics, we'll use a privacy-respecting configuration and update this policy.
Children
The Service is not directed at children under 16 and we don't knowingly collect their data. If you believe a child has created an account, contact us and we'll remove it.
Changes and contact
We'll update the effective date above when this policy changes, and notify you of material changes. Questions: support@inbound.cloudsynth.dev · CloudSynth Ltd, 128 City Road, London, EC1V 2NX, United Kingdom.