Cloudbricks
PlatformBlocks
Basic
$20/ developer / month
Pro
$50/ developer / month
CompanyRequest a demo

Privacy Policy

Effective Sep 28, 2026

Who we are

Cloudbricks is operated by Onentry, Inc., a corporation incorporated in Washington, United States ("Cloudbricks," "we," "us"). This policy explains how we handle personal information when you visit our website, create an account, sign in, or use the current early-access service.

Contact us about this policy or your personal information at hello@cloud-bricks.com.

Information we collect

Account and sign-in information. We collect your email address, display name, account identifier, account status, and account creation and authentication times. We also process verification codes and temporary authentication records to verify your email and maintain a signed-in session.

Google sign-in. If you choose Google, we request basic identity access using the openid, email, and profile permissions. Google and our authentication provider process the sign-in and supply identity information. We use and retain your Google account identifier, verified email information, and name to create or identify your Cloudbricks account, sign you in, and secure access. We do not request access to your Gmail messages, Google Drive files, or contacts. You do not give Cloudbricks your Google password.

Workspace information. We collect the personal or team use option you choose, your organization name where applicable, onboarding progress, memberships, roles, and access permissions.

Support and demo requests. If you contact us or schedule a demonstration, we receive the information you provide, such as your name, email, message, and meeting details. The website links to Cal.com for scheduling; information you submit there is also handled under Cal.com's own privacy policy.

Technical information. Our hosting and authentication providers receive information needed to deliver and protect the service, such as network addresses and request details. Cloudbricks also records limited operational events and error categories for troubleshooting and security. Our application diagnostics are designed to exclude authentication tokens, verification codes, and raw error messages containing personal information.

How we use information

We use information to create and manage accounts, authenticate users, maintain sessions, save onboarding progress, manage organization access, respond to requests, deliver the service, investigate errors or abuse, and meet applicable legal obligations.

Google identity information is used for account identification, sign-in, and related security purposes. This sign-in connection does not give Cloudbricks access to the contents of your other Google services.

Cookies and device storage

We use essential first-party cookies for your signed-in session and for email and Google authentication attempts. The session cookie has a maximum lifetime of 12 hours; authentication-attempt cookies have a maximum lifetime of 10 minutes. They use secure, HTTP-only browser settings.

These are Cloudbricks application cookies. Google, the hosted authentication service, and any optional third-party services may use their own cookies with different lifetimes under their respective policies.

These lifetimes describe access validity, not guaranteed physical deletion times for associated server records or backups. Some successful authentication records remain associated with the resulting session until it expires.

We also use browser local storage to remember whether the workspace sidebar is open. Clearing browser storage removes that preference. Blocking essential cookies can prevent sign-in from working. The current application does not include advertising cookies or a third-party analytics SDK.

Chat, files, and voice input

The current early-access workspace does not send chat drafts or selected files to an AI provider or an application-building backend. These features have not yet been connected to those services.

If you choose microphone dictation, your browser's speech-recognition service processes audio to produce text. Depending on the browser, that processing can involve its service provider and may occur remotely. Your browser controls microphone permissions; you can revoke those permissions in its settings.

We will update the relevant disclosures before introducing features that materially change these practices.

Service providers and other disclosures

Amazon Web Services provides application hosting, authentication, email delivery, data storage, security, and operational services. Cloudflare provides hosting for the public website and domain-related services. Google processes its own sign-in flow under its own policies. Providers process information needed to perform their respective services.

We may also disclose information when required by applicable law, to respond to valid legal process, or where necessary to protect the service and the rights or safety of users and others. Any such disclosure must be limited to the relevant purpose and applicable law.

Storage and security

Our primary application services and account database run in the United States. Website delivery and service providers can involve infrastructure in other locations.

We use HTTPS, access controls, protected authentication cookies, and managed infrastructure security features. No system can guarantee absolute security. If you suspect unauthorized account access, contact us using the address above.

Retention

Account, identity, organization, and onboarding records do not currently have an automatic expiration date. We retain them to provide and administer the account and evaluate deletion requests as described below.

Temporary authentication and rate-limit records are assigned expiration times and are removed through background cleanup. The application log groups are configured to retain diagnostics for 14 days. Backup copies and provider operational records may remain for their applicable retention periods. Signing out ends your session; it does not delete your account or account history.

When handling a deletion request, we may need to retain limited information for security, resolving disputes, or compliance with applicable legal requirements. We will explain any relevant limitation when responding to your request.

Your choices and requests

Contact hello@cloud-bricks.com to request access, correction, a copy, or deletion of your personal information, or to ask about our handling of it. There is currently no self-service account deletion or export control. We may need to verify your identity before fulfilling a request and will handle requests as required by the laws that apply to you.

You can review or revoke Google's authorization in your Google Account settings. Revoking authorization does not itself delete the information already held in Cloudbricks or necessarily end an existing Cloudbricks session. You can sign out separately and contact us to request deletion.

Different sign-in methods can create separate Cloudbricks accounts even when they use the same email address. We do not automatically merge accounts based only on a matching email. When making a request, tell us which sign-in methods you have used; do not send verification codes or passwords.

Depending on your location and the applicable law, you may have additional rights, including rights to object to or restrict processing and to complain to a data-protection authority. Nothing in this policy limits those rights.

Changes

We will publish updates to this policy with a revised effective date. If a change materially affects how we handle personal information, we will provide any notice and obtain any consent required by applicable law and the relevant authentication provider's policies.

Contact

Onentry, Inc., Washington, United States

hello@cloud-bricks.com

Cloudbricks
PlatformBlocksPricingCompanyRequest a demoPrivacy PolicyTerms of Service
© 2026 Cloudbricks