Skip to content
ChatWithCloud
Home Blog Tools Pricing Use Cases How it Works
Sign inGet started free
Sign in Get started
Dashboard My Account
  1. Home
  2. Privacy Policy

Privacy Policy

What personal data ChatWithCloud collects, why, who it’s shared with and the choices you have. Last updated: September 30, 2026.

Terms of Service Contact

On this page
  1. At a glance
  2. What we collect
  3. Cookies
  4. How we use it
  5. Who we share with
  6. Retention
  7. Your rights
  8. Security & changes
  9. Contact

At a glance

This policy explains what personal data ChatWithCloud collects, why, who it’s shared with and the choices you have. Spread Capital Corporation is responsible for your data (the “controller”). Contact: [email protected].

In short: we collect as little as we can, we don’t sell your data, we don’t use advertising or tracking cookies, and we don’t train AI models on what you submit.

WhatWhyHow long we keep it
Name, email, password hashYour account and sign-inUntil you delete your account
Profile photo (if you add one)Showing it on your account and in the site headerUntil you remove it or delete your account
Sign-in sessions (IP, browser)Keeping you signed in securelyUntil the session ends: 1 day, or 30 days with “Remember me”
Security log (event, time, IP)Spotting suspicious sign-ins12 months
Tool usage (tool, model, sizes, time)Your dashboard and service limitsUntil you delete your account. Never the code itself
Code you paste into a converterConverting itNot stored by us. Sent to the AI provider only to produce the result
IP address for rate limitsPreventing abuse24 hours

What we collect

When you use the web app (app.chatwithcloud.ai)

  • Account details: your name, email address and whether it’s verified. We store your password only as a salted scrypt hash, never the password itself. If you sign in with Google or GitHub, we store that account’s ID and email to link it to yours.
  • Profile photo (optional): if you add one, your browser crops and shrinks it to 256×256 pixels before sending it, so the original file never leaves your device. We keep that small copy and the time you set it. It appears on your account and dashboard and in the chatwithcloud.ai header when you’re signed in. It’s served from a web address that contains your random account ID, so anyone who has that exact address can see the photo. You can remove it at any time on the Account page.
  • Sessions: a cookie keeps you signed in. On our side we store only a hash of it, with the time, your IP address and your browser’s user-agent string.
  • Security log: sign-ins, failed attempts, password resets and similar events, with the time and IP address.
  • Account status and admin records: whether your account is active, waiting for approval, rejected or suspended, any reason our team gave, your plan and its renewal date, and a record of changes our staff make to your account (who, what and when).
  • Tool usage: for each conversion we record the tool, the AI model, whether it succeeded, the length of the input and output, and how long it took. This powers your dashboard. We never store the code you convert. For signed-out visitors these records aren’t linked to anyone.
  • Code you submit: sent to the AI model that performs the conversion and returned to you. We don’t keep a copy.
  • Password breach check: when you choose a password, we check it against Have I Been Pwned using k-anonymity. Only the first 5 characters of its SHA-1 hash leave our servers, never the password.
  • Rate limiting: your IP address, or your email for sign-in attempts, with timestamps, to stop abuse.

When you use the CLI

  • The CLI runs on your computer. Your AWS credentials never leave it.
  • Your questions, the generated code and the results of the AWS calls it makes are sent to the AI provider to produce answers. With your own key, that’s OpenAI directly. On the trial or subscription, it’s ChatWithCloud’s managed endpoint, which also receives your license key, a machine ID and your computer’s host and user name for licensing.
  • License keys are checked with Lemon Squeezy each time the CLI starts.
  • Anonymous analytics are optional. You choose during setup, and you can change it later with /settings. If enabled, usage events go to PostHog with GeoIP lookup disabled, keyed to a machine identifier, never to your name or email. They never include your question text.
  • Settings and conversations are saved on your computer in ~/.chatwithcloud/. The Security page has the full details.

When you buy a plan

Lemon Squeezy collects your payment details and billing address as merchant of record. We receive order details such as your name, email, plan and license status, but never your full card number.

Page-view analytics and server logs

The website and the web app use Cloudflare Web Analytics to count page views and see which pages are useful. It doesn’t use cookies, doesn’t build a profile of you and doesn’t follow you across other sites. It’s switched off on the password-reset page, so reset links are never recorded. There are no advertising or tracking cookies. Our hosting providers also keep standard server logs, including IP address, pages requested and browser type, for security and troubleshooting.

When you contact us

If you use the contact form, we receive your name, email address, the topic you choose and your message. The form sends them through our web app, which emails them to our support inbox (using Resend) and doesn’t store them. Your IP address is used only for rate limiting, which stops the form from being abused (kept for 24 hours). If you email us directly, we keep your message and email address. Either way, we use them only to reply and help you.

Cookies and browser storage

We only use what’s needed for the services to work, so there’s no cookie banner.

NamePurposeDuration
cwc_sessionKeeps you signed in to the web app. Secure, HttpOnly cookie. While you’re signed in, chatwithcloud.ai uses it to ask the web app for your name and email so it can show your profile menu. Nothing extra is stored.Until you close the browser, or 30 days with “Remember me”
cwc_oauthProtects Google or GitHub sign-in against forgery.10 minutes
cwc-theme (browser storage)Remembers light or dark mode.Until you clear it
cwc-tool:… (browser storage)Keeps your last converter input and output on your device so you don’t lose work. It’s never sent to us unless you press Convert.Until you clear it

How we use your data

  • To provide the services: your account, sign-in, conversions, your dashboard and licenses. Legal basis: performing our contract with you.
  • To keep the services secure and prevent abuse: rate limits, security logs and breach checks. Legal basis: our legitimate interest in protecting you and the services.
  • To send account emails: verification, password resets and security notices. We don’t send marketing email without your consent.
  • For CLI analytics, only if you turn them on. Legal basis: your consent, which you can withdraw in /settings.
  • To meet legal obligations, such as tax records kept by our payment provider.

We don’t sell or rent your personal data, we don’t use it for advertising, and we don’t use your code, questions or results to train AI models.

Who we share it with

We use these service providers to run ChatWithCloud. Each one gets only what it needs for its job.

ProviderWhat for
CloudflareHosting the web app and its database, which is stored in Cloudflare’s Asia-Pacific region. Also cookieless page-view analytics for the website and web app.
HostingerHosting this website
NVIDIA (AI inference API)Running the AI models behind the web converters. Receives the code you submit.
OpenAIThe CLI’s AI model when you use your own API key
ResendSending account emails and delivering contact-form messages to our support inbox
Lemon SqueezyPayments, subscriptions and license keys
PostHogCLI analytics, only if you opt in
Google, GitHubSigning in, only if you choose to use them
Have I Been PwnedPassword breach check (a partial hash only)

These providers may process data outside your country, including in the United States. Where the law requires it, transfers are covered by appropriate safeguards such as Standard Contractual Clauses. We may also share data if the law requires it, or to protect the rights and safety of our users or the services.

How long we keep it

  • Account and tool-usage data: until you delete your account. Deleting it removes your profile, sign-in methods, sessions and security log right away, and your usage records are kept only as anonymous totals.
  • Sessions: deleted when they end or expire. Expired email links are deleted within a week.
  • Security logs: 12 months, or until you delete your account.
  • Records of staff changes to your account: 2 years.
  • Rate-limit records: 24 hours.
  • Code you convert: not stored by us.
  • Payment records: kept by Lemon Squeezy as tax law requires.

Old records are removed automatically every day.

Your rights and choices

Depending on where you live, including under the GDPR and UK GDPR and in California, you have the right to access, correct, delete or export your personal data, and to object to or restrict how we use it.

  • To delete your account, go to Account in the web app and choose Delete account. It takes effect immediately. For any other request, email [email protected] from the address on your account. We’ll reply within 30 days.
  • You can turn CLI analytics off at any time with /settings, and clear browser storage in your browser settings.
  • If you’re unhappy with how we’ve handled your data, you can complain to your local data-protection authority. We’d appreciate the chance to put it right first.

Security, children and changes

  • Security: passwords are hashed with scrypt, and sessions and email links are stored only as hashes. All traffic uses HTTPS with HSTS, and the web app runs under a strict Content Security Policy. No system is perfectly secure, but we’ll tell you promptly if a breach affects your data.
  • Children: the services aren’t intended for anyone under 16, and we don’t knowingly collect their data.
  • Changes: if we change this policy, we’ll update the date at the top of this page. For material changes, we’ll give notice on this page and email account holders.

Contact

Questions about your data, or a privacy request? Email [email protected] from the address on your account, or see our contact page. The rules for using the services are in the ChatWithCloud terms of service.

Spread Capital Corporation, operator of ChatWithCloud, is the controller of your personal data.

ChatWithCloud

Talk to your AWS Cloud in human language, right inside your terminal.

$ npx chatwithcloud

Product

  • How it works
  • Use cases
  • Pricing
  • Security

Tools

  • All AWS code tools
  • AWS SDK v2 to v3
  • Terraform to AWS CDK
  • IAM policy generator
  • S3 pricing calculator

Resources

  • AWS examples
  • Blog
  • FAQ
  • Dashboard

Company

  • About
  • Contact
  • Terms
  • Privacy
© 2026 ChatWithCloud. All rights reserved.Not affiliated with Amazon Web Services.