CloudCaive is run by Cloudcave Ltd (trading as CloudCaive), a company registered in England & Wales, company number 16477937. Our registered office address is available on request. We are registered with the Information Commissioner's Office (ICO) as a data controller, registration reference ZC198736. For anything in this policy, use our on-site contact form — a person reads it.

This page tells you exactly what we collect, where it goes, and why — system by system, because that's how it actually works.

What we collect, and why

WhatHandled byWhyLawful basis
Email address + first name Kit (our email platform) To send you the 90-day roadmap and one useful email a week. Unsubscribe with one click, any time. Consent
Persona + how you found us Kit A one-question poll after signup, plus the source of your first visit (e.g. "tiktok/bio"). It tells us who we're writing for, so the content gets better. Consent / legitimate interests
Account emails Resend (transactional email) We use Resend to send emails to your account address — passcode resets and account recovery, and (only if you opt in) spaced-review reminders. This is separate from the newsletter, which is Kit. Legitimate interests; consent for reminders
Free-beta access Us (database hosted on Cloudflare) The public beta is free for everyone from 31 August to 1 November 2026, so there is nothing to buy and no payment data involved. Access is decided on our server from your verified email address and the beta dates — we store no extra record for it, and it ends automatically when the beta does. Records from earlier paid purchases are kept as described in the rows below and in "How long we keep things". Contract
Contact-form messages Us + Resend (transactional email) To understand and reply to a question you send through the site. Please do not include passwords, access tokens or card details. Legitimate interests; contract where your message concerns a purchase
Proof-of-completion certificate Us (database hosted on Cloudflare) If you choose to create a certificate for a tier you've completed, we publish a page at cloudcaive.com/verify/… showing the name you enter, the tier and the date — nothing else. It's entirely optional, you tell us the name to display, and you can ask us to take the page down at any time and we will. Consent
Payment details Stripe To process Core Pro subscriptions. Nothing is charged during the free beta and no card is collected for it. Your card number never touches our servers — we store your plan, your Stripe references, the access window, and a record of each payment: amount, date and status, plus any refund or cancellation. See Stripe's privacy policy. Contract
Labs profile Us (database hosted on Cloudflare) Creating a profile in Labs stores a display name you choose, a passcode (stored hashed — we can't read it), and a recovery email address if you add one, so you can sign in from any device. If you sign in with Google or Microsoft, we also store which provider you linked, the account reference they use for you, and the email address they gave us. Contract / legitimate interests
Extra sign-in security Us (database hosted on Cloudflare) If you turn on two-factor codes or passkeys, we store what's needed to check them — including any name you give a device, so you can tell your devices apart. Contract / legitimate interests
Learning progress Your browser; our database if you make a Labs profile Progress, scores and review schedules live in your browser's local storage. If you create a Labs profile, a copy syncs to our database so you can pick up where you left off on another device — along with any feedback you send us from inside the Lab, which we see alongside your profile name. Our database also keeps a per-question record of your answers and checkpoint results; it's what lets us confirm a certificate is genuinely yours. No profile, no sync — it stays on your machine. Contract / legitimate interests
AI tutor conversations Our server + Anthropic Tutor messages are sent through our server to the Anthropic API to generate the reply (see Anthropic's privacy policy). We send no name or account identifier with them, and Anthropic's commercial API doesn't use them to train its models. Conversations are saved as part of your Labs progress; we also keep a usage record per profile — token counts and which question you asked about, not what you said — to limit abuse and keep costs honest. Legitimate interests
Security & performance logs Cloudflare + us The site runs on Cloudflare, which keeps standard, short-lived technical logs (like IP addresses) to keep things fast and to block abuse. We also keep short-lived attempt records (request category + IP address, and profile name for sign-in) in our own database purely to limit password-guessing and public-form abuse, and — briefly — your IP address while a Google or Microsoft sign-in completes. Legitimate interests
Website funnel events Us (database hosted on Cloudflare) To learn whether visitors understand the product and can complete the first scenario and purchase journey. We record an allowlisted event; page path; short action label and location; referring website's hostname; compact campaign tags; experiment and variant; audience; scenario and outcome; elapsed time; viewport category; build label; and a random per-tab identifier. Fields that do not match these strict formats are discarded. We do not attach an account, email, stored IP, cookie or fingerprint to browser events, and Do Not Track disables browser collection. A few milestone events (account created, beta access activated) are recorded by our server at the moment they happen rather than by your browser. Legitimate interests

Who processes data for us

The companies we use, each doing one job:

  • Kit — sends the newsletter and stores subscriber details. Its signup form runs on the roadmap page and a few learning articles, so Kit's servers see the visits to those pages.
  • Resend — sends account emails, purchase confirmations, and on-site contact messages to our mailbox.
  • Stripe — takes payments; the only one that ever sees card details.
  • Cloudflare — hosts the site, the Labs sync database, and security logs.
  • Anthropic — generates AI tutor responses from the messages you send it.

We collect only what a feature needs in order to work, and nothing to build a picture of you. We don't sell your data, and we don't share it with advertisers — we don't do advertising at all. We run no third-party analytics or advertising trackers: the only measurement on this site is the first-party funnel record described above, which stays with us, carries a per-tab identifier rather than a cross-site one, and switches off if your browser sends Do Not Track. Beyond the companies named on this page, each doing one job for us, we only share information with our professional advisers, such as our accountant, or where the law requires it.

If you sign in with Google or Microsoft

This is entirely your choice — a display name and a passcode work just as well. If you do, your browser goes to Google or Microsoft so you can prove who you are there. That part happens under their privacy policy, not ours: they'll see your IP address, your browser details, and the fact that you're signing in to CloudCaive, and they may record that connection against your Google or Microsoft account.

They send us back your email address and the account reference they use for you. We keep those so we recognise you next time. Nothing about your learning goes to either company. If you disconnect the account later we delete that link; the email address stays on your profile as your recovery address — ask us and we'll remove it.

Cookies

Honestly minimal — no analytics cookies, no advertising trackers, nothing that follows you around the web. We set one cookie of our own: if you sign in with Google or Microsoft, or connect one of them to your account, a short-lived security cookie checks it's still you when you come back, then disappears within ten minutes. What else exists:

  • Local storage (data kept in your browser): your learning progress, your Labs sign-in token, how you first found the site, and your poll answer. Without a Labs profile none of it leaves your machine; with one, your progress syncs to our database automatically while you're signed in — that's what makes cross-device pickup work.
  • Session storage (cleared with the tab): a random analytics session ID. It is not a cross-site cookie.
  • Kit's signup form is embedded on some pages. It sets no cookies, but it does keep a subscriber identifier in your browser's local storage so it recognises you if you subscribe.
  • Stripe checkout happens on Stripe's own pages, which set their cookies for fraud prevention.
  • Cloudflare may set a security cookie to tell humans from bots.

How long we keep things

  • Newsletter data — until you unsubscribe; Kit then removes you from our list.
  • Beta purchase records — plan, entitlement, checkout-confirmation and payment references are retained with the purchase record where required for security, disputes, tax or accounting. Records from the beta's earlier, now-retired invitation flow are retained the same way where they attach to a purchase.
  • Contact messages — normally up to 12 months after the question is resolved, unless they become part of a purchase, legal or security record that must be retained longer.
  • Labs profile and synced progress — while your account is active, and for up to five years after you last sign in. Your progress is protected for that whole period — a lapsed subscription doesn't delete anything. After five years of inactivity we'll email you (if we hold an address for you) a month before deletion, with a summary of what you achieved; sign in again and the clock resets. Or ask us and we'll delete it sooner.
  • AI tutor usage records — the per-profile token counts and question references described above are kept for six months.
  • Payment records — kept as long as UK tax law requires (six years), by Stripe and in our accounts.
  • Our sign-in and public-form abuse records — the daily sweep deletes records older than 24 hours (so scheduled deletion occurs within 48 hours), and new attempts opportunistically remove old records sooner; Cloudflare's separate technical-log retention is governed by its service settings.
  • Website funnel events — no more than 90 days, with a rolling ingestion ceiling and hard database row cap as additional safeguards. The non-identifying capacity counters expire after their short window.
  • Progress in your browser — yours to clear whenever you like (it's in your browser's site data).

Your rights

Under UK GDPR you can, free of charge:

  • Access — ask for a copy of what we hold about you.
  • Rectification — have anything wrong corrected.
  • Erasure — have your data deleted.
  • Restriction — ask us to pause what we do with your data while something is sorted out.
  • Portability — get the data you gave us in a form you can take elsewhere.
  • Objection — object to processing based on legitimate interests.
  • Withdraw consent — for anything consent-based (like the newsletter), at any time, as easily as you gave it.

Use our on-site contact form and we'll respond within a month — and we'll tell you if a complex request needs longer (the law allows up to two extra months). If you're not happy with how we handle it, you have the right to complain to the Information Commissioner's Office at ico.org.uk.

International transfers

Kit, Stripe, Anthropic, Resend and Cloudflare are US-based, so some data is processed in the United States. Those transfers rely on UK-approved safeguards — the UK Extension to the EU-US Data Privacy Framework, or the UK's International Data Transfer Agreement or Addendum — which put those companies under obligations equivalent to UK law. Ask us through the contact form if you'd like the details.

Signing in with Google or Microsoft is different: you deal with those companies directly, under their own privacy policies. We don't send them your data — you sign in with them, and they confirm to us who you are.

Who this is for

CloudCaive is an 18+ service — you must be 18 or over to use it. We don't knowingly collect information from anyone younger; if you think a child has given us their details, tell us through the contact form and we'll delete them.

Changes to this policy

If we change what we collect or who processes it, we'll update this page and the date at the top. For anything significant, we'll email newsletter subscribers and account holders we hold an address for, rather than hope you notice.

Contact

Questions, requests, or something here doesn't match your experience? Use our on-site contact form.