How Cloud iNIT collects, uses, and protects information when you use the site, the test sandbox, the API, and the downloadable client.
Cloud iNIT ("we", "us", "our") builds tools that boot cloud infrastructure in a predictable, auditable order across AWS, Azure, and Google Cloud. This policy explains what data we collect when you visit our site, request a sandbox, download the client, call the API, or read the training materials bundled under /profile/, and what choices you have about that data.
We built Cloud iNIT to be auditable by design — the same principle applies to how we handle your data. We collect only what's needed to run the service, keep it secure, and improve it, and we say so plainly here rather than burying it in dense legal text.
Each sandbox generates a short-lived, isolated credential set at the identity boot stage. These credentials are scoped to the sandbox only, are never linked to a personal identity beyond the email used to request access, and are automatically rotated and destroyed on teardown.
We do not sell personal information, and we do not use sandbox credentials or infrastructure data for advertising purposes.
Where the UK/EU GDPR applies, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Providing sandboxes, API keys, and downloads | Performance of a contract with you |
| Security logging and abuse prevention | Legitimate interests |
| Analytics and advertising cookies | Consent, collected via the cookie banner |
| Responding to support emails | Legitimate interests / consent |
We use a small number of essential cookies to keep the site working, plus performance and advertising cookies where you've consented. Full details — including a table of every cookie set, its purpose, and its lifetime — live in the dedicated Cookie Policy.
| Service | Purpose |
|---|---|
| Google AdSense | Displays ads on the site; may set cookies to personalize ads based on your settings at adssettings.google.com |
| Cloudflare | Content delivery, DDoS protection, and edge analytics (Cloudflare Insights beacon) |
| GitHub | Hosts our open API repositories; interactions there are governed by GitHub's own privacy policy |
| AWS · Azure · Google Cloud | Underlying infrastructure providers for sandbox provisioning |
These providers may process data on our behalf under their own privacy and security terms. We choose providers that meet or exceed the protections described in this policy.
We share information only in the following cases:
| Data type | Retention period |
|---|---|
| Sandbox credentials | Deleted immediately on sandbox teardown |
| Server & security logs | 90 days, then aggregated or deleted |
| Support email threads | Up to 24 months, or until you ask us to delete them |
| Advertising & analytics cookies | Per the durations listed in the Cookie Policy |
All traffic to cloudinit.online and test.cloudinit.online is encrypted in transit (TLS). Sandbox credentials are generated fresh per session, scoped tightly, and rotated on teardown — the same "nothing starts silently" principle we apply to infrastructure applies to how we protect your data. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security, but we design for least privilege and short-lived secrets by default.
Depending on where you live, you may have some or all of the following rights over your personal data:
California residents have equivalent rights under the CCPA/CPRA, including the right to know what personal information is collected and to opt out of its sale — we do not sell personal information. To exercise any of these rights, email cloudgcp08@gmail.com.
Because Cloud iNIT provisions sandboxes across AWS, Azure, and Google Cloud regions (including us-east-1, eastus2, and us-central1), your data may be processed in countries other than your own. Where required, we rely on standard contractual clauses or equivalent safeguards offered by our infrastructure providers.
Cloud iNIT and the bundled training materials are not directed at children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us and we will delete it.
We may update this policy as the product evolves. Material changes will be reflected by updating the "Last updated" date at the top of this page. Continued use of the site or sandbox after a change means you accept the revised policy.
Questions about this policy, a data request, or anything privacy-related — we read every email.
cloudgcp08@gmail.com