Privacy Policy
Effective Date: August 30, 2026
At DeCloudUs, we believe privacy is a fundamental right. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our DNS resolver platform and related services (collectively, the “Service”). Please read this policy carefully. By using the Service, you consent to the data practices described in this policy.
1. Information We Collect
1.1 Information You Provide
We collect information you voluntarily provide when:
- Creating an account (any name, email address)
- Setting up authentication (passwords, passkeys, two-factor authentication codes)
- Configuring DNS profiles, custom rules, schedules, and preferences
- Making payments via payment providers (billing name, address, payment method details processed by our payment providers)
- Contacting our support team
- Using promotional codes or participating in surveys
1.2 Information Collected Automatically
When you use the Service, we automatically collect certain technical information:
- DNS queries: When you use our resolver, your device sends DNS queries to our servers. We process these queries in real-time to provide DNS resolution. DNS query data handling is detailed in Section 3 below.
- Device and usage data: For security purposes, we may collect browser type, operating system, device identifiers, IP address (used only for connection routing and security), pages visited, features used, and interaction timestamps.
- Log data: Web server logs containing timestamps, request URLs, HTTP status codes, and referrer information for troubleshooting and security purposes.
- Cookies and similar technologies: Session cookies for authentication, CSRF protection cookies for security, and preference cookies for theme and settings persistence.
1.3 Information from Third Parties
We may receive information from third-party payment processors (Stripe, PayPal) to process your subscription payments. These processors handle your financial data in accordance with their own privacy policies and applicable financial regulations. We receive only the minimum information necessary to confirm your payment and subscription status.
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the DNS resolution Service
- Process DNS queries and apply your configured filtering rules
- Create and manage your account and authentication credentials
- Process subscription payments and manage billing
- Communicate with you about your account, Service updates, and support inquiries
- Detect, prevent, and address fraud, abuse, and security issues
- Monitor and analyze Service performance, reliability, and usage patterns
- Comply with legal obligations and enforce our Terms of Service
3. DNS Query Data — Our Privacy Commitment
As a privacy-first DNS resolver, the handling of your DNS queries is central to our privacy commitment. This section explains in detail how we process DNS data.
3.1 Real-Time Query Processing
When your device sends a DNS query to our resolver, we process it in real-time to:
- Resolve the domain name to its corresponding IP address
- Apply your configured filtering rules (blocklists, allowlists, custom rules)
- Apply scheduled rule changes based on your configured time zones and schedules
- Route the query through your selected regional resolver node
- Return the DNS response to your device
This processing occurs in memory and is ephemeral. Queries are not stored to persistent storage unless you have explicitly enabled DNS logging.
3.2 DNS Logging (Opt-In)
DNS query logging is disabled by default. When you enable logging for a profile:
- You choose the retention period (from 1 hour up to the platform maximum)
- Logs are stored in an isolated, encrypted database
- Only you can access your DNS logs through your authenticated dashboard
- Logs are automatically purged after your configured retention period
- You may delete your logs at any time
- You may disable logging at any time, after which no new queries are recorded
3.3 Client IP Address Logging (Opt-In)
Client IP address logging is disabled by default and must be explicitly enabled per profile. When enabled:
- Your IP address is stored alongside each DNS log entry
- This data is subject to the same retention period and deletion controls as DNS logs
- IP addresses are never shared with third parties
- When Client IP address logging is disabled, our DNS platform never records your IP anywhere in our systems
- We recommend enabling this feature only when needed for troubleshooting
3.4 Aggregated and Anonymized Statistics
We may collect and use aggregated DNS query volume for the following purposes:
- Monitoring the health and performance of our resolver network
- Detecting and mitigating abuse, attacks, or anomalous traffic patterns
- Improving our filtering rules and blocklist quality
- Capacity planning and infrastructure optimization
This data is only aggregated counter data at the platform level and in now way records details about your DNS queries.
3.5 What We Never Do With DNS Data
- We never sell your DNS query data to any third party
- We never share individual DNS query logs with advertisers, data brokers, or analytics companies
- We never use DNS queries to build user profiles for advertising purposes
- We never use DNS queries to track your browsing behavior across websites
- We never inject ads, redirects, or modified DNS responses based on query content
- We never log DNS queries by default — logging is always an explicit, user-controlled choice
4. AI Assistant Conversations
The Service includes an optional AI assistant — named “Dex” in the dashboard — that you can ask to explain or change your DNS settings in ordinary language. This section describes exactly what happens to what you type into it. Using the assistant is entirely optional, and the rest of the Service works without it.
4.1 What is sent for processing
To answer you, we send your message and the context needed to act on it to a hosted large language model provider. That context is limited to what the request requires — typically your DNS profiles and their filtering settings, and any results the assistant retrieved while working on your request.
- We do not send your password, payment details, API tokens, or authentication credentials
- DNS query logs are sent only when you ask a question that requires them, and only the entries needed to answer it
- You control what the assistant can reach at all — it can be restricted to chosen DNS profiles, or prevented from making any changes, from your account settings
4.2 Our requirements of inference providers
We use hosted large language model providers to run the assistant. We contract only with providers that commit, in their terms, to the following:
- Zero data retention — your messages and the responses to them are processed to produce an answer and are not stored by the provider afterwards
- No training — your conversations are never used to train, fine-tune, or otherwise improve any model
- No human review — conversations are not read by provider staff for quality, moderation, or any other purpose
- No onward sharing — providers act on our instructions only and may not use your data for their own purposes
We do not sell, rent, or share assistant conversations with anyone, and they are never used for advertising or profiling. The identity of our current inference providers is available on request; we may change providers, and any replacement must meet the same commitments before it processes anything.
4.3 What we store, and for how long
We keep your conversations so that you can return to them. They are stored on our own infrastructure, in the same database as the rest of your account data and under the same protections.
- You can delete any conversation at any time, individually or all at once, from your account settings. Deletion is immediate and permanent
- Conversations are deleted automatically after a limited retention period — currently 30 days from the last message. This happens whether or not you ask for it
- Everything is removed when your account is closed. Deleting your account permanently deletes your conversations, your assistant settings, and your token balance and its history, along with the rest of your data
Records of what an assistant request cost are kept with your billing records rather than with the conversation, so deleting a conversation does not erase the charge associated with it. Those records contain usage amounts only — never the content of what you asked.
4.4 Connecting your own AI assistant
Separately from the built-in assistant, you may connect an AI client you already use to your account. In that case the client runs under your own arrangement with whoever provides it, and what it does with your data is governed by their terms rather than ours. We pass data to it only in response to requests it makes with the access you granted, and you can revoke that access at any time.
5. Third Party Disclosure
5.1 Service Providers
We use minimal third-party service providers to operate our platform:
- Payment processors (Stripe, PayPal) — to process subscription payments securely. These processors handle your financial data in compliance with PCI-DSS standards and their own privacy policies. Data is directly provided by you to the payment providers.
- Data centers — to host our servers, databases, and resolver nodes.
- Email service providers — to deliver transactional emails (verification, password reset, notifications).
- Hosted AI providers — to run the optional AI assistant, under the zero-retention and no-training commitments described in Section 4. Used only when you use the assistant.
5.2 Legal Requirements
We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court or government agency). We will notify you of such requests unless we are legally prohibited from doing so. However, it is important to keep in mind that you are in complete control of what DNS data get logged and for how long.
5.3 Protection of Rights
We may disclose your information when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.
5.4 Business Transfers
In the event of a merger, acquisition, reorganization, or sale of all or a portion of our assets, your personal data may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our website before your data becomes subject to a different privacy policy.
5.5 No Sale of Data
We do not sell, rent, or trade your personal information or DNS query data to any third party for marketing or advertising purposes.
6. Data Security
We implement industry-standard security measures to protect your information:
While we strive to protect your data, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security but are committed to promptly addressing any vulnerabilities that may be discovered.
7. Data Retention
- Account data: Retained for the duration of your account plus a reasonable period after deletion to comply with legal obligations
- DNS query logs: Retained only for the user-configured retention period (1 hour to platform maximum). Automatically purged after the retention period expires
- AI assistant conversations: Deleted automatically after a limited retention period (currently 30 days from the last message), and deletable by you at any time before that
- Billing records: Retained as required by financial regulations and tax obligations (typically up to 7 years)
- Authentication logs: Retained for a limited period for security monitoring and fraud detection
- Support communications: Retained for the duration of the support case plus a reasonable period for quality assurance
When data is no longer needed, it is securely deleted in accordance with our data retention policy.
8. Your Rights and Choices
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: You can view and export your account data through your dashboard at any time
- Rectification: You can update your account information through your dashboard settings
- Deletion: You can request deletion of your account and associated data. DNS logs can be deleted at any time through the dashboard
- Data portability: You can export your DNS logs and account data in machine-readable format via dashboard and APIs
- Restriction: You can restrict processing by disabling DNS logging, client IP logging, deleting query logs, or by closing your account
- Objection: You may object to certain types of processing via your account dns profile settings or by closing your account
- Withdrawal of consent: Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal
To exercise any of these rights, please use your dashboard or our APIs for self-service or contact us through your account dashboard. We will respond to your request within 30 days, or sooner if required by applicable law.
9. Children’s Privacy
Our Service is not directed to children under the age of 13 (or 16 in certain jurisdictions). We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child established an account with us, please delete the account and all data is then removed from our systems.
Our DNS filtering service may be used by households to protect children from inappropriate content. In this context, the service processes DNS queries without collecting personal data from children — DNS logging is off by default, and when enabled, logs are accessible only to the account holder.
10. International Data Transfers
Our Service operates globally, and your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place:
- Our regional resolver nodes allow you to choose a preferred region for DNS resolution, minimizing unnecessary data transfers
- We apply the same privacy standards regardless of where your data is processed
- We comply with applicable data protection laws, including the GDPR for European users and the CCPA for California residents
11. California Privacy Rights (CCPA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):
- Right to know: You have the right to request information about the categories and specific pieces of personal information we collect, the purposes for which it is used, and the categories of third parties with whom it is shared
- Right to delete: You have the right to request deletion of your personal information, subject to certain exceptions
- Right to opt out: You have the right to opt out of the sale of your personal information. We do not sell your personal information
- Right to non-discrimination: We will not discriminate against you for exercising your CCPA rights
To exercise these rights, simply use your dashboard as it already shows you the information we have about you and gives you easy way to completely delete everything. Alternatively, you can contact us via our support channels.
12. European Data Protection (GDPR)
If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR):
- Legal basis for processing: We process your personal data under the following legal bases: (a) performance of the contract to provide the Service, (b) legitimate interests for security and fraud prevention, (c) consent where explicitly obtained (e.g., optional DNS logging), and (d) legal obligations
- Right to be informed: This Privacy Policy serves as our transparency notice
- Right to erasure: You can request deletion of your data, subject to legal retention requirements
- Right to restrict processing: You can request that we limit how we use your data
- Right to data portability: You can request your data in a structured, commonly used, machine-readable format
- Right to object: You can object to processing based on legitimate interests
- Right to lodge a complaint: You have the right to lodge a complaint with a supervisory authority in your jurisdiction
For the purposes of the GDPR, we act as a data controller for account data and as both a data controller and data processor for DNS query data, depending on the context.
13. Cookies and Tracking Technologies
We use a minimal number of cookies and similar technologies:
- Essential cookies: Required for authentication (session cookies), security (CSRF tokens), and remembering your preferences (theme, sidebar state). These cookies are necessary for the Service to function and cannot be disabled.
- Analytics: We may use privacy-respecting analytics to understand how our Service is used. Any analytics we use are configured to not collect personally identifiable information.
We do not use advertising cookies, tracking pixels, or third-party tracking scripts. We do not use cross-site tracking technologies or browser fingerprinting.
14. Third-Party Links
Our Service may contain links to third-party websites, services, or resources that are not owned or controlled by us. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services you access through our platform.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will:
- Post the updated Privacy Policy on our website with a revised “Effective Date”
- Notify you by email or through a prominent notice on our website for significant changes
Your continued use of the Service after the effective date of any changes constitutes your acceptance of the revised Privacy Policy.
16. Data Controller Information
The entity responsible for your personal data (the “data controller”) is the operator of DeCloudUs, as identified in our Terms of Service. For any privacy-related inquiries, including requests to exercise your data protection rights, please contact us through:
- Your account dashboard’s support section
- The contact form on our website
We aim to respond to all privacy-related requests within 30 days. In some cases, we may need additional time (up to an additional 60 days) to fulfill your request, in which case we will inform you of the reason for the delay.
17. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us through your account dashboard or the contact information provided on our website.
For data protection inquiries, including requests to exercise your rights under GDPR, CCPA, or other applicable privacy laws, please reach out through the same channels and include “Privacy Request” in the subject line.