CloudCMD is in early access — use for testing only. Your vault is zero-knowledge by design: we can't see or decrypt it. Feedback:

Legal

Privacy Policy

Effective February 1, 2026

CloudCMD (“CloudCMD,” “we,” “our,” or “us”) is committed to processing your information in ways that respect your privacy and keep it safe. This Privacy Policy explains what information we collect, how we use and share it, your rights, and how to contact us.

Privacy Policy Summary

This summary highlights key points. The full policy follows below.

  • What we cover: how we collect, use, share, and protect Personal Information when you use our website (cloudcmd.com) and desktop application (collectively, the “Services”).
  • Secure Data: sensitive items you store in CloudCMD (SSH keys, cloud credentials, encrypted notes, and similar vault content) are encrypted with keys derived from your master password. We cannot read your Secure Data in plaintext.
  • Service Data: account, billing, support, and diagnostic information we need to operate the Services.
  • No sale of Personal Information: we do not sell your Personal Information. Our use of Google user data complies with Google’s Limited Use requirements — we use it only to provide and improve user-facing features and never for advertising, AI training, or any other prohibited purpose.
  • Your choices: access, correct, export, delete, disconnect cloud accounts, and revoke OAuth access as described below.

Introduction

This Privacy Policy applies when CloudCMD acts as the controller of your personal data. It supplements our Terms of Service. By using the Services, you agree to this Privacy Policy.

CloudCMD is a desktop multi-cloud terminal and infrastructure management application. It helps you connect to and manage servers and resources across cloud providers (including AWS, Google Cloud Platform, and Tailscale) from a single encrypted workspace synced to your account.

Secure Data and Service Data

We distinguish two categories of information:

Secure Data is the sensitive information you choose to store in CloudCMD — for example SSH private keys, cloud provider credentials and OAuth refresh tokens, encrypted notes, and environment configuration. Secure Data is your property. We claim no rights to it beyond what is necessary to provide the Services to you.

Secure Data is encrypted before it is stored in your synced account. Encryption uses keys derived from your master password (Argon2id key derivation and AES-GCM/JWE encryption in the desktop app). We do not possess your master password or decryption keys and cannot read your Secure Data in plaintext. You may add, modify, and delete Secure Data at your discretion inside the app.

Service Data is information CloudCMD collects or generates to provide, secure, bill, and support the Services, excluding Secure Data. Service Data includes account registration details, device metadata, billing records, support communications, and limited diagnostic information described below.

Information We Collect

Information you provide. When you create an account, subscribe, or contact us, we may collect your name, email address, authentication credentials, billing information (processed by our PCI-compliant payment provider), and the content of support requests.

Secure Data you store. As described above, when you save SSH keys, connect cloud accounts, or store encrypted content, that data is encrypted by the app before sync. We store the encrypted form only.

Information collected automatically. We may collect limited diagnostic and usage information, such as app version, operating system, device hostname (stored for device management), crash reports, and error logs. Crash and error reports are processed with secret scrubbing configured to redact credentials, tokens, and key material from reports.

Website information. When you visit cloudcmd.com, we may use cookies or similar technologies for essential site functionality and analytics, as described in our cookie practices on the site.

Google User Data (Google Cloud OAuth)

When you connect a Google Cloud account using OAuth in CloudCMD, you authorize our application to access certain Google APIs on your behalf. This section describes how we handle Google user data.

CloudCMD’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

What we access. Depending on the features you use, CloudCMD may access:

  • Your Google account email address (to identify which account authorized the connection).
  • An OAuth refresh token (to obtain short-lived access tokens for API calls you initiate).
  • GCP resource metadata retrieved through Google APIs — for example Compute Engine instances, Cloud Monitoring metrics, Kubernetes cluster listings, and project information — to display and manage resources in the app.

How we use Google user data. We use Google user data only to provide and improve user-facing CloudCMD features visible in the application, such as server discovery, metrics charts, SSH/IAP terminals, Kubernetes browsing, and user-approved command execution as your Google identity. We do not use Google user data for:

  • Serving, targeting, personalizing, retargeting, or enabling interest-based advertising.
  • Selling data to third parties.
  • Selling to or sharing with data brokers or information resellers.
  • Determining credit-worthiness or for lending purposes.
  • Building or populating databases unrelated to the Services.
  • Training artificial-intelligence or machine-learning models (including generative AI).

How we store Google user data. OAuth refresh tokens and related session configuration are treated as Secure Data: encrypted in your synced account (Firebase Cloud Firestore, hosted on Google Cloud) before storage. Access tokens are minted in the desktop application as needed and are not stored at rest.

Human access. Our employees and contractors do not read the content of your GCP API responses or OAuth tokens except where necessary for security investigations, legal compliance, or with your explicit permission.

Sharing. We do not transfer Google user data to third parties except as necessary to provide the Services (for example, storing your encrypted data in Firebase/Google Cloud infrastructure you contract with by using CloudCMD) or as required by law. We do not transfer Google user data to any third party for advertising, data-broker, information-reseller, credit, lending, database-building, or AI/ML-training purposes.

Revoking access. You can disconnect a GCP OAuth session in CloudCMD (Environments → your GCP session → delete or disconnect) and revoke CloudCMD’s access at any time at Google Account permissions. Deleting your CloudCMD account removes your encrypted Secure Data from our systems as described in Retention and Deletion.

Other Cloud Provider Credentials

CloudCMD also supports connecting AWS (including IAM Identity Center SSO), GCP (service account keys and other auth methods), and Tailscale. Credentials and tokens for these providers are treated as Secure Data and encrypted before sync, similar to GCP OAuth refresh tokens. We use these credentials only to perform actions you initiate in the app (discovery, terminals, metrics, and related features). We do not share cloud credentials with third parties except as necessary to operate the encrypted sync infrastructure.

How We Use Information

We use Personal Information to:

  • Provide, maintain, and improve the Services, including encrypted sync, cloud discovery, terminals, and billing.
  • Authenticate you and protect your account.
  • Process subscriptions and send transactional emails (receipts, security notices, product updates).
  • Provide customer support and respond to your requests.
  • Detect, investigate, and prevent fraud, abuse, and security incidents.
  • Comply with legal obligations.

How We Share Information

We do not sell your Personal Information. We may share information only in these circumstances:

  • Service providers. Trusted vendors who help us operate the Services (for example cloud hosting, payment processing, email delivery, and error monitoring), under contractual obligations to protect your data and use it only to provide services to us.
  • Legal requirements. When required by law, regulation, legal process, or to protect the rights, safety, and security of CloudCMD, our users, or others.
  • Business transfers. In connection with a merger, acquisition, or sale of assets, subject to the acquirer honoring this Privacy Policy.

Because Secure Data is encrypted with keys we do not hold, if we are required to disclose account data, Secure Data would be provided in encrypted form that we cannot decrypt.

Keeping Your Information Safe

We use administrative, technical, and organizational measures designed to protect Personal Information, including encryption of Secure Data, access controls, Firestore security rules that restrict data access to the authenticated account owner, and automated secret scrubbing in error reports. No method of transmission or storage is completely secure; if you believe your account has been compromised, contact us immediately at security@cloudcmd.com.

Retention and Deletion

We retain Service Data for as long as your account is active and as needed to provide the Services, comply with law, resolve disputes, and enforce our agreements. Secure Data remains in your account until you delete it or delete your account.

You may delete your CloudCMD account from the app or by contacting us. When you delete your account, we remove your encrypted Secure Data and associated Service Data from active systems within a reasonable period, subject to backup retention cycles and legal retention requirements. Copies in backups may persist for a limited time before being overwritten.

International Data Transfers

CloudCMD is operated from the United States. Your information may be processed and stored in the United States and other countries where we or our service providers operate. We take steps designed to ensure that transfers comply with applicable data protection laws, including contractual safeguards where required.

Your Rights and Choices

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to certain processing of your Personal Information, and to data portability. You may also withdraw consent where processing is consent-based.

  • Access and correction: much of your account information is available in the app; contact us for additional requests.
  • Deletion: delete Secure Data in the app, disconnect cloud sessions, or delete your entire account.
  • Export: contact us if you need help exporting account-related Service Data. Export of decrypted Secure Data requires your master password in the app.
  • Marketing: opt out of promotional emails using the unsubscribe link in any marketing message.
  • Complaints: you may lodge a complaint with your local data protection authority.

To exercise your rights, email help@cloudcmd.com or security@cloudcmd.com. We may verify your identity before fulfilling requests.

Children

The Services are not directed to children under 16, and we do not knowingly collect Personal Information from children under 16.

Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the effective date. For material changes, we may notify you by email or in the app.

Contact Us

Questions about this Privacy Policy or our data practices:

CloudCMD
Email: security@cloudcmd.com (security and privacy)
Email: help@cloudcmd.com (general support)