This policy describes what loscloudscollects, why it's collected, and how long it's kept. It maps to the behavior of the product today — not a generic template.
Account data from Google sign-in
When you sign in with Google, losclouds receives your Google account identifier, email, and display name. We store the email and display name so the dashboard and alerts can address you. We do not receive your Google password, contacts, calendar, or files.
Sessions and cookies
losclouds uses first-party cookies scoped to the losclouds domain to keep you signed in. Theme preference is stored locally in your browser so the public site can remember dark or light mode without an account. Session tokens are stored server-side and expire automatically. We do not use advertising cookies.
Alert destinations
When you subscribe to alerts, losclouds stores the destination address (email, Slack webhook URL, or Discord webhook URL) along with notification preferences and a verification state so we can confirm ownership before delivering alerts. Unsubscribe tokens are generated per subscription and can be rotated by editing or deleting the subscription.
API key metadata and usage
API keys created from the dashboard are stored hashed. losclouds records key metadata, last-used timestamps, and account/tier usage summaries so you can monitor consumption and revoke leaked keys. Raw key values are shown only once at creation time; keys are credentials and do not have independent quota.
User report metadata
Status reports are anonymous by construction: no account, user identifier, or email is captured with a report, even when you're signed in at the moment you submit one. To prevent abuse and deduplicate signal, each report stores a hash of the reporter IP computed with HMAC-SHA256 under a key that rotates daily; the current and previous day's keys are kept briefly to catch abuse across the rotation boundary and then discarded, so the same IP can't be linked across days once a key is gone. Coarse country and city are derived from the request IP at report time.
- Raw IP addresses are not stored alongside reports.
- Coarse country and city are used for grouping and are shown on public report feeds. Neither is ever attached to an account.
- Hashed IP plus target plus recent-window rate limiting is used to detect and reject duplicate submissions across the daily key rotation.
- Public report feeds contain user-submitted reports; local demo data is kept out of production public feeds.
Operational and observability data
losclouds logs request paths, status codes, and error traces for the purpose of keeping the service running. Access logs and error traces are retained for a rolling window and are used to debug incidents, not to profile users.
Retention, deletion, and export
Deleting your account from Account → Danger Zone immediately removes your user record, active sessions, alert destinations, and API keys. Status reports are not part of this: a report carries no account or email linkage, so there is nothing to delete or export by account — raw reports are retained indefinitely for product analytics. Request an export or ask a data question by emailing us.
Privacy questions or deletion requests? Email us at [email protected].