Skip to main
maudeMDCC/00
Legal

Privacy notice

What personal data Maude Cloud holds, why, for how long, who else sees it, and how to get it out or get rid of it.

Last updated: 1 August 2026

Who holds your data

Bc. Michal Dovrtěl, IČO 03387666, Houbalova 2088/5, Líšeň, 628 00 Brno, Czech Republic — the controller for the personal data described here, and the processor for the design work you store (that relationship is governed by the DPA). Contact: cloud@maude.sh.

We do not have a DPO; the service is small enough that the contact address reaches a person who can act.

What we hold, and why

WhatWhyKept for
Your email addressIt is your identity here, and how we reach you about your projectsWhile your account exists
Password hash (only if you did not use Google)Signing you inWhile your account exists
Google account id, name, email (only if you used Google)Signing you in without a passwordWhile your account exists
Project name, plan, state, datesRunning and billing the projectWhile the project exists
Billing details — company, address, VAT idIssuing correct invoices, charging the right VAT10 years (Czech accounting law)
Stripe customer and subscription idsLinking your project to its paymentsWhile the project exists
Audit log — who did what to a project, and whenSo you can see what happened, including if we ever lookedWhile the project exists
Your designs and their historyThe service itself. Processed on your instruction — see the DPAUntil you delete the project

We hold no analytics, no tracking pixels, and no advertising identifiers. The documentation site sets no analytics cookies. The application sets exactly one cookie: your session.

What we never do

  • We never open, run, or render your designs on our computers. There is no browser in the workspace image, and a CI gate fails the build if one reappears.
  • We never sell or share personal data for marketing.
  • We never read the rest of your computer. Only the project folder syncs.

Why we are allowed to

  • Performance of a contract — your account, your projects, your invoices.
  • Legal obligation — accounting and tax records.
  • Legitimate interests — keeping the service secure and abuse-free, and keeping the audit log that lets you check us.

We do not rely on consent for any of the above, so there is no consent to withdraw. Marketing email, if it ever exists, will be opt-in and separate.

Who else sees it

The subprocessor list is in the DPA and is part of it: Cloudflare (hosting, storage, DNS), Stripe (payments), Resend (transactional email), Vercel (this documentation site only — no customer project data).

Where a subprocessor transfers data outside the EEA, that transfer runs on the European Commission's Standard Contractual Clauses under that provider's own terms.

Your rights

Access, correction, erasure, restriction, objection, and portability — the usual GDPR set. Two of them are self-service and do not require asking us:

  • Portability: Download everything, on your project, at any time, including while it is paused.
  • Erasure: Delete project, which stops billing, detaches the address and erases the stored data.

For the rest, write to cloud@maude.sh. We answer within 30 days. If we get it wrong, you may complain to the Czech data protection authority (Úřad pro ochranu osobních údajů, uoou.gov.cz) or to the authority where you live.

If something goes wrong

We notify you of a personal data breach within 72 hours of becoming aware of it, at the contact address on the account. Security issues: security@maude.sh.

Children

The service is not for under-18s and we do not knowingly hold their data.

Changes

Material changes are announced before they take effect. The date at the top of this page is the last change.

On this page