Privacy
Privacy policy
Version 1 · Last updated 14 May 2026
1. Introduction
This Privacy Policy explains how CloudLase ("we", "us", "our") collects, uses, stores, and discloses personal information when you use the CloudLase desktop application, the CloudLase Editor at app.cloudlase.studio, our marketing website, and any related services (collectively, the "Services").
CloudLase is operated from Australia. We comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where you are located in another jurisdiction, additional rights may apply (see section 9).
By using the Services, you consent to the collection and use of information described in this policy.
2. What We Collect
2.1 Account information
When you create a CloudLase account we collect:
- Your email address (used as your login identity and for product communications)
- A password (stored only as a one-way hash by our authentication provider, we never see your plaintext password)
- If you sign in with Google: your Google account email and basic profile information (name, profile picture URL) returned by Google's OAuth flow
2.2 Subscription and billing
If you subscribe to a paid plan, our payment processor (Stripe) collects and stores your payment details. We receive only:
- A Stripe customer ID
- Subscription status, plan, renewal date, and last four digits of the payment method (for receipts)
We never see or store your full card number, CVC, or banking details.
2.3 Workspace content
When you use the CloudLase Editor (cloud) we store the laser shows, audio files, timeline data, and related content you create. These are stored encrypted at rest in Cloudflare R2 (object storage) and Supabase Postgres (metadata) within the regions described in section 6. You retain ownership of all content you create, see section 10 of our Terms of Use.
The desktop CloudLase application stores your workspaces locally on your device. We do not collect or transmit desktop workspaces unless you explicitly enable Cloud Sync.
2.4 Licence validation
CloudLase desktop licences are Ed25519-signed key files verified locally on launch. The desktop application does not transmit your licence key or any activation telemetry to us in normal operation, and remains fully functional offline.
If you choose to pair your desktop licence with a CloudLase Editor (cloud) account, an optional flow used to share your subscription entitlement across the desktop and cloud editor, we record the following in our cloud database:
- A one-way hash of your licence key (we do not store the raw key)
- The email address printed on the licence
- Pairing timestamp and result (success / failure)
Pairing is opt-in and can be removed at any time from Settings → License in the cloud editor.
2.5 Diagnostic and usage data
If you opt in, we collect anonymous crash reports and error diagnostics via Sentry to help us identify and fix bugs. These reports contain stack traces, application version, and operating system information. They do not include your workspace contents, personal files, or identifying information beyond a randomly generated device ID.
You can disable diagnostic reporting at any time in the application settings.
2.6 Communications
If you contact us via email, the support form, or any other channel, we retain those messages and your contact details for the purpose of responding and improving the Services.
2.7 Server logs
Our servers log standard request metadata (IP address, user agent, request path, timestamp, response status) for security monitoring, abuse prevention, and operational diagnostics. Logs are retained for up to 30 days and then automatically purged.
3. How We Use Your Information
We use the personal information we collect to:
- Provide, operate, and maintain the Services
- Authenticate you and protect your account
- Process payments and deliver licences
- Send transactional emails (account confirmations, password resets, billing receipts, security notifications)
- Respond to support requests and feedback
- Diagnose, fix, and improve the Software
- Detect, prevent, and investigate fraud, abuse, or security incidents
- Comply with legal obligations
We do not sell your personal information. We do not use your information for advertising or marketing analytics on the desktop application.
4. Marketing Emails
Where permitted by law, we may send occasional product update emails to registered users (new releases, important announcements). You can unsubscribe at any time using the link at the bottom of any marketing email. Transactional emails (billing, security, password reset) are required for the Services to function and cannot be unsubscribed from while you hold an account.
5. Third-Party Service Providers
We use the following processors to operate the Services. Each is bound by its own privacy commitments and processes data only on our behalf:
- Supabase, authentication and database hosting (data stored in the United States)
- Cloudflare, DNS, CDN, R2 object storage, and Pages hosting (global edge network)
- Stripe, payment processing and subscription billing (Australia / United States)
- Brevo, transactional email delivery (European Union)
- Sentry, error and crash reporting (European Union)
- Fly.io, application server hosting (United States, Sydney region for some workloads)
- Google, sign-in with Google identity provider (when you choose this sign-in method)
We periodically review these providers' security and privacy practices. We do not authorise any of them to use your information for their own marketing or analytics.
6. Data Storage and International Transfers
Because some of our service providers operate outside Australia, your personal information may be transferred to, stored, and processed in countries including the United States and the European Union. We take reasonable steps to ensure those providers handle your information in accordance with the Australian Privacy Principles, including by relying on their contractual commitments and recognised cross-border transfer frameworks (such as the EU Standard Contractual Clauses).
7. Data Retention
- Account data is retained for as long as your account is active.
- If you delete your account, we delete or de-identify your account data and workspace content within 30 days, except where retention is required for legal, tax, fraud-prevention, or accounting reasons (typically up to 7 years for financial records).
- Server logs and diagnostic data are retained for up to 30 days then purged.
- Backups containing your data may persist for up to 30 days after deletion before being overwritten.
8. Security
We use industry-standard measures to protect your information, including:
- TLS encryption in transit for all network traffic
- Encryption at rest for stored content (database and object storage)
- Hashed passwords (we never store plaintext)
- Restricted internal access on a need-to-know basis
- Regular security review of dependencies and infrastructure
No system is completely secure. While we work hard to protect your information, we cannot guarantee its absolute security. If we become aware of a data breach affecting your personal information, we will notify you in accordance with Australian Notifiable Data Breaches scheme requirements.
9. Your Rights
You have the right to:
- Access the personal information we hold about you
- Correct inaccurate or out-of-date information
- Delete your account and associated personal information (subject to legal retention obligations)
- Export your workspace content (.clws bundles via the desktop, ILDA exports via desktop and web, MP4 video via desktop and web)
- Withdraw consent for optional data collection (e.g. opt out of crash reports)
- Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au if you are not satisfied with how we have handled your personal information
If you are located in the European Economic Area, the United Kingdom, or California, you may have additional rights under the GDPR or CCPA, including portability and the right to restrict processing. To exercise any of these rights, contact us at cloudlase.studio/contact.
10. Cookies and Local Storage
The CloudLase Editor (web) uses local storage and cookies to:
- Maintain your authenticated session (essential, required for sign-in)
- Remember UI preferences such as theme and panel layouts (essential, required for the editor to function)
The marketing website may load Cloudflare Web Analytics, which uses no cookies and does not collect any personally identifying information. We do not use third-party advertising cookies or cross-site tracking.
11. Children's Privacy
The Services are not directed to children under 13 (or under 16 in jurisdictions where that is the local age of digital consent). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Services, or legal requirements. The "Last updated" date at the top of this page indicates when it was last revised. Material changes will be communicated to registered users via email. Continued use of the Services after changes constitutes acceptance of the updated policy.
13. Contact
For privacy questions, requests, or complaints, please contact us at cloudlase.studio/contact. We aim to respond within 30 days as required by the Australian Privacy Principles.