Privacy
Privacy policy
Effective 15 August 2026
This policy explains what information CloakRDP needs to run a private Windows workspace, what it does not require, and how that information is used. It is written for customers. It does not claim that CloakRDP collects nothing or that accounts cannot be connected to the service.
Our privacy approach
CloakRDP is designed as a privacy-focused service. The product aims to minimize unnecessary identity requirements and to be clear about the information that is needed to operate the service.
Privacy here means a smaller account footprint and a privacy-focused access and internet path for your workspace. It does not mean that CloakRDP keeps no records at all.
What information we need
Account information. CloakRDP uses a customer identifier and authentication-related information so you can sign in, recover access, and keep the account under your control. This exists because the service does not use email as a login or recovery channel.
Workspace information. CloakRDP keeps the information required to provide and maintain your Windows workspace — such as the plan, location, and operating system you select, and the status of that workspace. This exists so the workspace can be created, reached, billed, and supported.
Payment information. When payment is used, CloakRDP keeps payment-provider references and transaction-related information needed to confirm payment and fulfill an order. This exists so CloakRDP can tell whether an order has been paid.
The public site may also store a language preference so English and Turkish pages stay consistent, and signed-in sessions use cookies required to keep you authenticated.
Information we do not require
Email is not required to create an account. Identity verification and KYC are not required. CloakRDP asks for minimal account information: a customer identifier, a password you choose, and a recovery code shown once.
Minimal account requirements are not the same as remaining unknown to the service. Your customer identifier is still linked to your account, orders, and workspaces.
Workspace privacy
Remote access to your workspace uses a privacy-focused access path rather than a public remote-desktop service on the open internet. Workspace internet traffic is intended to leave through a privacy-focused VPN path rather than a direct datacenter internet exit.
Watching or reviewing customer workspace activity is not a product feature. Customer privacy is separated from the records needed to operate the service. VPN traffic logs are not kept. That policy does not mean that no service records exist.
Operational records
Limited records may exist so CloakRDP can keep the service reliable, protect accounts, prevent abuse, and troubleshoot problems. Examples include account status, sign-in related information used for account security, order and workspace status, and records created while providing or repairing a workspace.
These operational records are different from monitoring what you do inside your Windows workspace. They are also different from VPN traffic logs, which are not kept.
Payment privacy
Payment processing is handled through payment providers, under those providers’ own terms. CloakRDP uses only the payment-related information needed to confirm a transaction and operate the order.
CloakRDP does not treat payment records as VPN traffic logs. This policy does not claim that payments are hidden from the payment provider or from the commercial record of your order.
Security of stored information
Sensitive information is protected using secure storage practices. Account credentials and other sensitive operational information are not stored as plain text.
How that protection is implemented is not described on this page. See the Security page for customer-facing protections of your workspace.
Legal requests
CloakRDP may need to respond to valid legal requests. Any response is limited to information that exists and that is legally required.
This section does not promise that CloakRDP can refuse every request, and it does not describe a specific legal jurisdiction.
Data retention
CloakRDP keeps information while it is needed for the purpose that required it — for example to maintain an account, a workspace, a payment, or service security.
This product does not publish fixed retention periods. How long a record is kept depends on that purpose and on operational requirements.
Website analytics and optional cookies
CloakRDP may use optional analytics technologies on the public marketing website to understand general patterns of site usage and to improve the website. Optional analytics are not required to use the website or its features.
When analytics is enabled, a third-party analytics provider — managed through Google Tag Manager — may process technical information about your browser, device type, and how you interact with public pages. This may include information such as pages visited, time on site, and an approximate geographic region derived from your connection. CloakRDP cannot guarantee that no IP address processing occurs on the provider side, and does not claim that no information reaches the provider.
Optional analytics are activated only according to your consent choice when you visit the public website. You can accept or reject optional analytics using the consent banner displayed on the public site. If you reject optional analytics, the website remains fully usable and no optional analytics technologies are activated.
Essential storage — such as your language preference and your session when signed in — is distinct from optional analytics and is not affected by your analytics consent choice.
Website analytics apply only to public marketing pages. They do not extend to your Windows workspace activity, VPN traffic, or anything inside your customer account. Workspace activity and VPN traffic logs are not kept, and that policy is separate from website analytics.
Related policies
Use of the service is also described in the Terms of Service and the Acceptable Use Policy. How your workspace is protected is described on the Security page.