Privacy notice
What personal data Maude Cloud holds, why, for how long, who else sees it, and how to get it out or get rid of it.
Last updated: 1 August 2026
Who holds your data
Bc. Michal Dovrtěl, IČO 03387666, Houbalova 2088/5, Líšeň, 628 00 Brno, Czech Republic — the controller for the personal data described here, and the processor for the design work you store (that relationship is governed by the DPA). Contact: cloud@maude.sh.
We do not have a DPO; the service is small enough that the contact address reaches a person who can act.
What we hold, and why
| What | Why | Kept for |
|---|---|---|
| Your email address | It is your identity here, and how we reach you about your projects | While your account exists |
| Password hash (only if you did not use Google) | Signing you in | While your account exists |
| Google account id, name, email (only if you used Google) | Signing you in without a password | While your account exists |
| Project name, plan, state, dates | Running and billing the project | While the project exists |
| Billing details — company, address, VAT id | Issuing correct invoices, charging the right VAT | 10 years (Czech accounting law) |
| Stripe customer and subscription ids | Linking your project to its payments | While the project exists |
| Audit log — who did what to a project, and when | So you can see what happened, including if we ever looked | While the project exists |
| Your designs and their history | The service itself. Processed on your instruction — see the DPA | Until you delete the project |
| Usage events — your account id, the project id, the name of the action, and when it happened | Operating the service and knowing which parts of it are used | 90 days |
| Project size figures — how many designs, artboards and design systems a project holds, and how much media storage it uses | Knowing what it costs us to run your project | 90 days |
We hold no tracking pixels, no advertising identifiers, and no third-party analytics. The documentation site sets no analytics cookies, and the application sets one cookie for you: your session. (Signing in with Google adds a second one for ten minutes, to carry that sign-in back.)
About those usage events. They are first-party and emitted by our own servers — the application ships no JavaScript at all, so there is nothing in the page that could report on you even if we wanted it to. An event is the name of something that happened ("signed in", "project created"), your account id, the id of the project it concerned, and a timestamp. It never contains your email address, and it never contains anything from inside your designs. They are stored on Cloudflare, already our hosting subprocessor, and they are not shared with anyone. We rely on legitimate interests for this, and you may object — write to cloud@maude.sh.
One thing worth naming plainly: a project id is the short name you chose when you created the project, and it becomes part of that project's web address. If you name a project after yourself or a client, that name is in these records. Nothing else about the project travels — not its contents, not its file names.
About the size figures. Your project counts its own designs and reports the totals to us once an hour, so we can see what running it actually costs. Counts and sizes only: never a design's name, never a file path, never anything you wrote.
What we never do
- We never open, run, or render your designs on our computers. There is no browser in the workspace image, and a CI gate fails the build if one reappears.
- We never sell or share personal data for marketing.
- We never read the rest of your computer. Only the project folder syncs.
Why we are allowed to
- Performance of a contract — your account, your projects, your invoices.
- Legal obligation — accounting and tax records.
- Legitimate interests — keeping the service secure and abuse-free, keeping the audit log that lets you check us, and the usage events above.
We do not rely on consent for any of the above, so there is no consent to withdraw. Marketing email, if it ever exists, will be opt-in and separate.
Who else sees it
The subprocessor list is in the DPA and is part of it: Cloudflare (hosting, storage, DNS, usage events), Stripe (payments), Resend (transactional email), Vercel (this documentation site only — no customer project data).
Where a subprocessor transfers data outside the EEA, that transfer runs on the European Commission's Standard Contractual Clauses under that provider's own terms.
Your rights
Access, correction, erasure, restriction, objection, and portability — the usual GDPR set. Two of them are self-service and do not require asking us:
- Portability: Download everything, on your project, at any time, including while it is paused.
- Erasure: Delete project, which stops billing, detaches the address and erases the stored data.
For the rest, write to cloud@maude.sh. We answer within 30 days. If we get it wrong, you may complain to the Czech data protection authority (Úřad pro ochranu osobních údajů, uoou.gov.cz) or to the authority where you live.
If something goes wrong
We notify you of a personal data breach within 72 hours of becoming aware of it, at the contact address on the account. Security issues: security@maude.sh.
Children
The service is not for under-18s and we do not knowingly hold their data.
Changes
Material changes are announced before they take effect. The date at the top of this page is the last change.
Terms of Service
The agreement between you and the provider of Maude Cloud — what you get, what you pay, what happens when you stop paying, and what happens to your work when you leave.
Data Processing Addendum
The GDPR Article 28 processor terms for Maude Cloud — scope, instructions, subprocessors, security measures, deletion, and audit.