PRIVACY
What we collect, and what we do not.
Last updated 24 September 2026
This policy explains how CoreByte Studio (“CloudWink”, “we”) handles personal data in the CloudWink apps for iPhone and Android, this website and the CloudWink backend. It is written to describe the product that exists today, not a product we plan to build.
The short version.
Your library is private to your account. We do not sell personal data, we do not share it for advertising, and no third-party advertising or analytics SDK runs in the app today. What we do hold, we hold to run the service you asked for.
- You keep your files. We store them so the app can show them back to you and so the people you share an album with can open it.
- CloudWink is not end-to-end encrypted. Files are encrypted in transit and at rest with keys we manage, which means our systems can technically read them.
- No advertising SDK, no ad identifier (IDFA or Android advertising ID), no cross-app or cross-site tracking.
- You can delete individual files, an album or your whole account from inside the app at any time.
Account information you give us.
To create an account we need an email address, and the address has to be verified before the app will work. You can add a display name, and you can turn on an authenticator app for a second sign-in factor. Sign-in is handled by Amazon Cognito using a password-proof exchange, so your password is never sent to or stored by CloudWink.
- Email address, verification status, and an account identifier that is used as the owner key for everything you store.
- Optional display name. Optional time zone, taken from the device, so scheduled notifications respect quiet hours.
- If you sign in with Google or Apple, the provider tells us the email address and, once only, the name you approve. Apple’s Hide My Email relay address works the same way as any other address.
Your files and the information around them.
Photos, videos, audio and PDFs you upload are stored byte for byte, without compression or re-encoding. Alongside the file we store the details the library needs to work.
- File name, declared content type, size, upload and modification times, and a SHA-256 checksum used to detect exact duplicates.
- Album titles, album descriptions and album membership; a flag marking a file as being in the Locked folder.
- Small server-generated previews: a 512-pixel WebP thumbnail and, for video, a poster frame. They are produced on our servers, which means our systems process the file content to make them.
- Photos you choose in the picker are read from your device only when you select them. CloudWink does not scan your camera roll in the background, and the Free Up Space feature only removes local copies after the stored copy has been confirmed.
Information collected automatically.
Running a service produces operational records. We keep the smallest set that still lets us fix faults and bill infrastructure correctly, and we redact what would otherwise leak secrets.
- Request logs: method, route, redacted path, status code, request identifier, duration, error code and app version. Share tokens, passwords, signed URLs, request bodies and file contents are excluded by rule and covered by an automated test.
- Network-level records held by our infrastructure provider, including IP address, in API access logs kept for 14 days.
- Storage and usage counters for your account, which the app shows you as quota and upload activity, plus aggregate statistics grouped by plan and account age. The aggregate rollups describe cohorts, not individuals.
- Device registration when you enable notifications: an install identifier, push token, platform and app version.
- There is no third-party analytics SDK, crash-reporting network, attribution SDK or advertising SDK in the app.
Sharing an album.
A share link is created only when you make one. We store the settings of the share and a hash of its secret, never the secret itself, so a copy of our database does not hand anyone your links.
- Share settings: expiry, the number of download grants allowed, whether a password is required, and for a restricted share the CloudWink user identifiers you invited.
- A record of sharing activity on your own albums, kept for 30 days, so the app can tell you a link was opened.
- Anyone you give a link to can see the files in that album and download them. Revoking a link stops new downloads, but download URLs already issued can keep working for up to a minute, and bytes already downloaded cannot be recalled.
- Notification text never contains file names, links or tokens. Album titles appear only if you turn that option on.
Subscriptions and payments.
Paid plans are sold as auto-renewing subscriptions through the Apple App Store and Google Play. We never see your card number, and we do not process payments ourselves.
- Purchases are handled by Apple or Google. They charge you, hold the payment details, and tell us whether an entitlement is active.
- We use RevenueCat as a processor to reconcile purchases. RevenueCat receives your CloudWink account identifier (never your email address or name), the product purchased, and purchase, renewal, cancellation and expiry events, along with device and country information it collects to deliver that service.
- Our servers store the resulting plan, quota and renewal state so the app can enforce what you paid for. Only an authenticated store webhook may change a plan.
Features you switch on.
Some data is collected only if you use the feature it belongs to, and turning the feature off stops the collection.
- Google Drive import: you grant a one-time, read-only access token which is used for that import and never stored as a long-lived credential. There is no background or recurring Drive sync, and we cannot reach your Drive again after the token expires.
- Locked folder: unlocking uses Face ID, Touch ID, fingerprint or your device passcode. That check happens on the device and its result never leaves it. The Locked folder is a visibility gate, not encryption: the files are stored like any other file and still count against your quota.
- Push notifications: tokens are relayed through Expo’s push service to Apple and Google. An account keeps at most ten devices, and a device that has not been seen for 90 days is dropped.
- Referrals: we store your referral code and the credits earned on each side. The summary shown in the app does not identify who earned a credit.
- Account emails: welcome and storage notices are sent by Amazon SES and carry an unsubscribe link. Service messages required to run your account, such as email verification, are not marketing and cannot be unsubscribed from.
Why we are allowed to use it.
Where the GDPR or UK GDPR applies, we rely on these legal bases: performing the contract with you, for account, storage, sharing and subscription data; our legitimate interests in keeping the service secure, preventing abuse and understanding aggregate usage; your consent, for photo library access, notifications and Drive import, each revocable in your device settings; and legal obligations, where we must keep or produce records.
Who else processes it.
We use a small set of processors, each for a stated purpose and under contract. We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not give it to data brokers.
- Amazon Web Services: storage, database, authentication, delivery, email and logs. AWS is the substrate the whole product runs on.
- RevenueCat: subscription reconciliation. Apple and Google: payment, sign-in and app distribution.
- Expo: relaying push notifications to Apple and Google notification services.
- Law enforcement or regulators, when a valid legal request compels disclosure, and a successor in a merger or acquisition, in which case this policy governs until the successor publishes its own.
Where your data lives.
Your account, metadata, subscription state and logs are held in the United States (AWS us-east-1). File bytes are stored in the storage region assigned to your account: the United States by default, or the United Arab Emirates (AWS me-central-1) when the app measures a materially faster path there. The assignment is automatic, based on connection latency, and can change at most once every 30 days; files already written stay where they were written. Transfers out of the EEA or the UK rely on the European Commission’s Standard Contractual Clauses.
How long we keep it.
Retention is bounded by design, and the boundaries are these.
- Files: until you delete them. Deleting a file moves it to Trash for 30 days, then removes every stored version.
- Account deletion: app access ends at once, and the erase of files, metadata, shares and the sign-in record begins about 20 minutes later, once download links already issued have expired.
- Database backups: point-in-time recovery holds a 35-day window, so deleted records can persist in backups for up to 35 days before ageing out.
- Request and access logs: 14 days. Sharing activity: 30 days. Device registrations: 90 days after the device is last seen.
- Usage counters that feed aggregate statistics: up to 400 days, tied to your account identifier, and removed with the account.
Your rights and how to use them.
Most of what a privacy request asks for is available directly in the app: download or delete any file, delete an album, revoke a share, change notification settings, unsubscribe from account emails, or delete the entire account from account settings.
- If the GDPR or UK GDPR applies to you: access, rectification, erasure, restriction, portability, objection, and the right to complain to your supervisory authority.
- If you are a California resident: the right to know, delete and correct, and to be free of discrimination for exercising them. We do not sell or share personal information as those terms are defined by the CCPA, and we do not process sensitive personal information for inferring characteristics.
- Email support@cloudwink.pro to make a request. We answer within the time your law allows, normally one month, and we may need to confirm control of the account before acting.
How your data is protected.
Security measures we actually run, stated plainly.
- TLS in transit, AWS-managed encryption at rest, private buckets with no public access, and signed short-lived URLs for originals.
- Every request is authorised against a verified token, and the server derives your storage keys from your account identifier, so one account cannot name another’s files.
- On the device, tokens live in the iOS Keychain or Android Keystore; cached media sits in the app sandbox, is excluded from iCloud and Android auto-backup, and is wiped when you sign out.
- What we do not claim: CloudWink is not end-to-end encrypted, revocation is not instantaneous, and uploads are not scanned for malware. No transmission or storage system is perfectly secure.
Children.
CloudWink is not directed to children. You must be at least 13 to hold an account, or 16 where local law sets that as the minimum age for consent to online services, and under those ages a parent or guardian must hold the account. We do not knowingly collect data from children below the applicable age; if we learn that we have, we delete the account and its contents.
Advertising.
CloudWink shows no third-party advertising today, sets no advertising identifier and performs no tracking as Apple’s App Tracking Transparency defines it. The Free plan may show CloudWink’s own messages about CloudWink features. If third-party advertising is ever introduced, this policy and the store privacy disclosures will be updated before it ships, and any tracking will require your consent.
Changes to this policy.
This policy was last updated on 24 September 2026. If a change materially affects how we handle your data, we will tell you in the app or by email before it takes effect, and the date above will change.
Contact us.
Email support@cloudwink.pro with any privacy question, request or complaint. If you are in the EEA or the UK you may also complain to your national data protection authority.
Contact CloudWink