Data controller
The data controller is the Skyclouds association, SIRET 999 213 101 00010, 11 rue Desperouse, 63200 Mozac, France. The privacy contact is [email protected].
Data processed
- Account: name, email address, optional image and verification evidence.
- Security: signed or encrypted web session tokens, hashed IDE tokens, pseudonymised network and device fingerprints, attempts and technical statuses.
- Usage: selected model, token count, credits, latency, status code and call source.
- Product improvement: technical events and, when the separate option is enabled, redacted prompts, responses and action types. A cryptographic pseudonym replaces the account identifier.
- Bug reports: summary, description, reproduction steps, environment and version voluntarily supplied from the website or application.
- Billing: Stripe identifiers, plan, subscription status and due date. ACLIDE does not store full card numbers.
- Support: subject, category and messages voluntarily sent in a ticket.
- OAuth: technical identifiers and tokens required when Google sign-in is used.
Purposes and legal bases
Performance of the contract covers account creation, service access, credit calculation, support and billing. Legitimate interests cover security, prevention of duplicate accounts and protection of the free plan. Legal obligations cover accounting records and requests from competent authorities.
The Windows application derives a pseudonymised fingerprint from the system installation. The raw system identifier and hardware serial numbers are never transmitted. The server observes the connection IP address itself; the application does not query a third-party service for the public address. Matching only limits repeated access to the free plan and can be challenged through support when a computer is shared or reassigned.
Optional technical diagnostics contain no free-form content. Optional improvement conversation sharing is controlled separately. Detectable keys, emails, IP addresses and personal paths are removed locally and on the server; content is pseudonymised, compressed and encrypted. It can remain indirectly identifying when other personal data is entered. Disabling the option also requests deletion of samples linked to the account pseudonym.
ACLIDE does not sell personal data and does not include advertising targeting.
Requests sent to AI models
The context required for a request is sent to the provider of the selected model in order to produce the response. The model and its provider are shown in the active catalogue.
Usage logs do not retain prompts or responses. When the separate improvement-sharing option is enabled, a redacted encrypted copy may be retained for 90 days to analyse failures and improve the agent. A provider may apply its own processing terms; do not send a secret or personal data that is unnecessary for the task.
Service providers
OVHcloud hosts the infrastructure and ACLIDE transactional email server. Stripe processes payments when enabled. Google is involved only for OAuth sign-in selected by the user. OpenAI and Anthropic may receive requests addressed to their models when enabled.
Administration may select another secure AI endpoint operator; in that case, the active operator receives the context required for the response and must be identified in the catalogue or service information. Each provider receives only the data required for its function. Depending on the provider and applicable contractual safeguards, some processing may involve a transfer outside the European Economic Area.
Retention
Account data is retained while the service is used and then archived only where required by a legal obligation or the defence of a right. Reset tokens expire after thirty minutes and can be used only once.
Pseudonymised product-improvement events are deleted no later than 90 days after receipt. Bug reports and processing notes are retained for as long as necessary for analysis, correction and regression monitoring, then deleted or anonymised when no longer useful.
The pseudonymised association between a device and a free quota expires twelve months after its last use. IDE sessions expire after thirty days. Other technical logs and anti-abuse protections are retained for as long as necessary for security and quota control. Billing records follow applicable statutory retention periods. A deletion request does not erase items that must legally be retained.
Your rights
You may request access, rectification, erasure, restriction or portability of your data, and object to processing based on legitimate interests. Proportionate identity verification may be requested.
Write to [email protected]. You may also lodge a complaint with the CNIL if you believe your rights have not been respected.
Age and third-party data
The paid service is intended for persons capable of entering into a contract. Users must not submit a third party’s data without a lawful basis or include it unnecessarily in an AI request.
CONTACT
A question about this information?
Write to [email protected]. State the page concerned and, if necessary, the ACLIDE account address.