Last updated: August 12, 2026
1. Information we collect
CloudyMax is operated by AritaWeb AI Solution Inc., which is responsible for the personal information described in this Privacy Policy.
We collect account information such as username, email address, password hash, language preference, account status, email-verification status, and basic account timestamps.
We may store payment-related records such as plan, amount, currency, traffic allowance, payment status, checkout session identifiers, provider customer identifiers, refund status, and activation status.
We may process support messages, screenshots or logs you choose to send, refresh requests, usage counters, signup IP address, user agent, audit logs, and security events needed to protect accounts and investigate abuse.
When you use automated support, we process the conversation, selected chat language, support category, rating, and limited account-state facts needed to answer the request. We ask for the current account email and send a short-lived one-time code before private account context or approved account actions become available. The code is entered only in the separate verification form and is not included in the support conversation. Do not include passwords, full card numbers, verification codes, private keys, seed phrases, wallet credentials, raw configurations, or other unnecessary secrets.
Network and VPN service data
To assign and maintain account-specific access, CloudyMax may process route assignments, connection and operational timestamps, aggregate traffic counters, profile-refresh events, node health information, and diagnostic or security metadata. We use this information for routing, reliability, fair-use review, fraud prevention, abuse response, and customer support, not to build advertising profiles from customer network activity.
Managed access components may create operational access and warning logs containing a connection time, source network address, account or profile identifier, requested destination address or domain and port, and diagnostic outcome. These records do not contain page contents, message contents, passwords, or payment credentials. We restrict production access and retain operational records only as reasonably needed for service reliability, security, disputes, and legal obligations.
2. Information we do not sell
CloudyMax does not sell customer personal information to advertisers or data brokers. We do not use customer account data for behavioral advertising.
We do not store full card numbers, CVV codes, or full payment credentials on CloudyMax servers. Payment details are handled by the payment provider.
3. How we use information
We use information to create accounts, verify email, process payments, activate plans, provide the dashboard, monitor fair use, send service emails, answer support requests, prevent fraud and abuse, improve reliability, and comply with legal obligations.
The intelligent support system uses conversation context to draft an answer, classify the topic, suggest a safe next step, and decide whether to create a human-support ticket. Sensitive account, security, refund, and low-confidence matters are routed for human review.
4. Payments
Payments are processed by supported payment providers such as Stripe. Those providers process payment details under their own terms and privacy notices. Stripe privacy information is available at https://stripe.com/privacy.
5. Cookies and local storage
Our website uses essential cookies and local browser storage for login sessions, CSRF protection, language selection, checkout flow, dashboard features, and cookie preference storage.
If you choose Accept all, CloudyMax enables optional first-party journey analytics and the TikTok Pixel. The TikTok Pixel may set advertising and attribution cookies and send page URLs, referrers, browser or device details, campaign attribution, and interaction or conversion information to TikTok for advertising measurement and optimization. TikTok may also process network information such as an IP address when these requests are made. Essential only prevents the TikTok Pixel base code from loading and keeps optional browser analytics disabled.
6. Sharing with service providers
We share limited information with service providers only as needed for hosting, email delivery, payment processing, security, compliance, support, and service operations.
CloudyMax uses the OpenAI API as a service provider for automated support. After the support session is verified, we may send support-message text and limited account-state context. The account context we supply automatically is designed not to include the customer's name, email address, payment credentials, raw network configuration, server identity, or subscription link or one-time verification code; information a customer chooses to type remains part of the support message. API requests use a one-way hashed user identifier and request that generated responses not be stored for later API retrieval. OpenAI processes information under its applicable terms, data controls, and privacy policy at https://openai.com/policies/privacy-policy/.
With your consent, limited website interaction and conversion-measurement data is shared with TikTok for campaign attribution and optimization. TikTok processes that information under its own privacy terms at https://www.tiktok.com/legal/privacy-policy.
After you choose Accept all, CloudyMax may temporarily retain the pseudonymous _ttp and ttclid attribution identifiers and a one-way hashed CloudyMax account identifier in an access-controlled delivery queue for up to 7 days so matching browser and server conversion events can be delivered and retried. We clear those identifiers after successful delivery or when the attribution window ends. Our server-side TikTok Events API payloads do not include email addresses, phone numbers, raw account IDs, raw IP addresses, or raw user-agent strings.
We may disclose information if required by valid legal process, sanctions rules, payment-provider requirements, or to protect CloudyMax, users, or third parties.
7. Retention
We keep information only as long as reasonably needed for account access, billing, tax and accounting records, support, security, dispute resolution, fraud prevention, legal compliance, and enforcement of our Terms.
When information is no longer needed, we delete, anonymize, or aggregate it where reasonably possible.
Support conversations, AI usage records, tickets, staff replies, and satisfaction ratings are retained only as reasonably needed to resolve requests, protect accounts, measure support quality, handle disputes, and meet legal obligations.
Optional first-party journey events are retained for up to 90 days. Account-linked conversion milestones are retained for up to 400 days for annual trend analysis, then deleted or aggregated. These analytics records do not store IP addresses, raw user-agent strings, network configurations, or payment credentials. TikTok controls the retention of information processed through its Pixel and Events API under its own privacy and retention policies.
8. Security
We use technical and organizational safeguards such as encryption in transit, password hashing, access controls, audit records, limited production access, and security review. No online service can guarantee absolute security.
9. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, export, or restrict certain personal information. To request help, contact [email protected].
10. Children
CloudyMax is not intended for children under 18 or the age of majority in their location. We do not knowingly collect personal information from children.
11. International processing
CloudyMax may process information in countries other than where you live. Where required, we use appropriate safeguards for cross-border processing.
12. Changes and contact
We may update this Privacy Policy as our service, providers, or legal requirements change.
Privacy questions may be sent to [email protected] or [email protected].