Cloudy CMS

Privacy Policy

Effective date: 22 September 2026

Operator: Cloud By Day Group Pte. Ltd., 7030 Ang Mo Kio Avenue 5, #05-042, Northstar @ AMK, Singapore 569880.

This notice covers the whole Cloudy service: the web dashboard that businesses log into, the APIs behind it, and the player application that runs on their screens. A shorter, app-specific summary is at the player privacy notice.

1. Who this applies to

Cloudy is a business tool. Two groups of people are involved, and we treat them differently:

  • Operators: the staff of a business who hold a Cloudy account and manage screens. We hold personal data about them as the controller.
  • Members of the public near a screen: people walking past a display. We do not identify them. Section 5 explains exactly what the optional audience-measurement feature does and does not record.

2. Data we collect about operators

  • Account details: name, email address, role, and the organisation the account belongs to.
  • Authentication records: sign-in, sign-out and failed sign-in events, including the IP address they came from.
  • Activity records: what was published, which screen was linked or unlinked, role and billing changes, with the acting account, the IP address, and a timestamp.
  • Content you upload: images, video and documents. If you choose to put personal data into your own signage content, you remain the controller of it.
  • Billing details: billing name and email. Card details are entered directly with our payment processor and never reach our systems.
  • Support correspondence and anything you type into the in-product assistant.

3. Data we collect from screens

  • Device identifiers: a device ID we generate at linking, an authentication token, and an organisation ID. These identify the screen, not a person.
  • Push token, used solely to deliver control commands such as sync, volume, or reboot.
  • Technical telemetry: platform, screen dimensions, storage used, installed content version, sync results, and playback status.
  • Linking address and location: when a screen is linked we record the IP address of the network it was linked on, and look up an approximate city from it so an operator can tell their own screens apart. We store both the IP address and the resulting city, region and country, a rough area, not a precise position. The lookup is performed by a third party (section 7).

4. How we use it

To deliver the service (linking screens, delivering the right playlists, applying remote settings), to keep it secure and available (monitoring, alerting, fraud and abuse prevention), to bill for it, to support you, and to improve the product. We do not sell personal data, and we do not use it for advertising.

5. Audience measurement: what it does not do

Cloudy offers an optional audience-measurement feature that estimates whether anyone was in front of a screen and for how long. It is off by default and has to be switched on by the operator, per organisation and per screen.

In every case:

  • Camera frames are analysed on the device and discarded immediately. No image or video is transmitted or stored.
  • No facial template or biometric identifier is created. We do not attempt to identify anyone, and we cannot recognise the same person on a later visit.
  • Emotion and ethnicity are never measured. Age and gender are not measured unless the organisation operating the screen has turned on audience demographics and confirmed that a notice is displayed at the screen. Where it has, the screen estimates a gender and an age band (20-39, 40-59 or 60 and over) on the device, people under 20 are never broken down, and only per-play counts leave the device. No per-person record of age or gender is created, stored or sent.
  • What leaves the device is a set of numbers per piece of content played: how many viewers were counted, the peak number at once, how long attention and presence lasted in milliseconds, and quality indicators describing how reliable the measurement was.
  • The camera runs while content is playing, and for a short grace period after playback stops.

No image and no per-face geometry leaves the screen, at any time and by any route. There is no on-screen indicator: the business operating the screen is responsible for signage telling people that audience measurement is in use on its premises.

6. Legal basis and your rights

We handle personal data under the Singapore Personal Data Protection Act (PDPA). You may ask us for a copy of the personal data we hold about you, ask us to correct it, or withdraw consent. Write to our Data Protection Officer at dpo@cloudycms.app. We respond to access and correction requests as soon as reasonably possible and in any case within the timeframes the PDPA sets.

7. Who we share data with

We use the service providers below. Each one receives only what it needs for its stated purpose, and none of them is permitted to use it for their own purposes. Some of them process data outside Singapore; where they do, we rely on their contractual commitments to provide a standard of protection comparable to the PDPA.

ProviderPurposeWhat they receive
Vercel Inc.Application hosting, content delivery, scheduled jobs, and sandboxed presentation conversionAccount identifiers, IP addresses in request logs, and files processed during a presentation import
Supabase Inc.Managed database, authentication, and realtime messagingAccount name, email address, and all customer content and operational records
Cloudflare, Inc.Object storage and delivery of media filesCustomer-uploaded media. No camera images: audience measurement runs entirely on the screen and transmits only aggregate counts
Google LLC — Firebase Cloud MessagingDelivering control commands to signage devicesThe device push token. No account personal data
Stripe, Inc.Subscription billing and payment processingBilling name and email. Card details are collected by Stripe directly and never reach our systems
Functional Software, Inc. — SentryApplication error monitoringError reports, which can include the acting account identifier and request metadata
PostHog Inc.Product usage analytics for the dashboardA pseudonymous account identifier, the account's role, and the organisation identifier — no name or email address — plus page views, performance metrics, IP address and browser details collected by their script
ipapi.coResolving an approximate city from the network a screen was linked from, so operators can recognise their own devicesThe IP address seen at the moment a screen is linked
Anthropic PBCPowering the in-product assistant, when an operator uses itThe conversation content the user types into the assistant
Telegram FZ-LLCDelivering operational alerts, where an operator opts into that channelAlert text, which can name an organisation or a screen
Healthchecks.ioConfirming our scheduled jobs are still runningNone. Liveness pings carry no personal data
Google LLC — DriveImporting a presentation the operator chooses to importOnly the file the operator selects, at the moment they select it
Google LLC — Places and MapsAddress autocomplete and the location map on an organisation's profileThe address text an operator types, and the resulting place identifier and coordinates
Google LLC — YouTubePlaying YouTube content an operator adds to a playlist, and showing its thumbnailThe IP address and player telemetry of the screen playing it, and of the dashboard browser previewing it
Expo (650 Industries, Inc.)Delivering over-the-air updates to the player applicationDevice IP address, platform, and application runtime version, sent whenever a screen checks for an update
MicrolinkGenerating a preview thumbnail for a web page an operator puts on a screenThe page address being previewed, plus the operator browser's IP address and user agent, because the preview image loads directly in their browser
Email relay providerSending transactional email — invitations, password resets, trial reminders and alertsRecipient email address and the content of the message

We may also disclose data where the law requires it, or to establish or defend a legal claim.

8. How long we keep it

  • Account data: for as long as the account exists.
  • Activity and sync records: on the plan retention window, currently 7 days on a trial and 90 days on a paid plan. If a paid plan lapses, the window returns to 7 days.
  • Security records (sign-in, sign-out, failed sign-in, role changes), retained for 365 days regardless of plan, so a security question can still be answered later.
  • Audience-measurement records: these contain no personal data, and they have no time limit. Removing a screen from your dashboard archives it and keeps its history. They are erased only when the screen is permanently deleted, or when the organisation is deleted.
  • Screen records: a screen you unlink is archived rather than erased, so its history stays readable. Its stored details, including the address of the network it was linked on, are retained until the screen is permanently deleted or the organisation is deleted.
  • Billing records: kept as long as tax and accounting law requires.

9. Deleting your data

Unlinking a screen archives it: it stops receiving content, but its record and history are kept so past reporting still makes sense. Permanently deleting an archived screen erases it and its history.

Deleting an organisation removes its content, stored media, schedules, screens and audience records, deletes the accounts that belong to it, and cancels its subscription. Accounts that manage several organisations are detached rather than deleted, because they outlive any one organisation. See data deletion for how to request it and what is retained afterwards.

10. Security

Data is encrypted in transit. Each organisation’s data is isolated at the database level as well as in the application. Passwords are handled by our identity provider and are never stored by us. Device credentials are held as a cryptographic hash once a screen has collected them, and in protected system storage on the device. Access to production data is limited to staff who need it.

If a data breach occurs that is likely to result in significant harm or is of significant scale, we will notify the Personal Data Protection Commission and affected individuals as required under the PDPA.

11. Children

Cloudy is a business tool. It is not directed at children and we do not knowingly collect their personal data.

12. Changes

We may update this notice. The effective date above reflects the latest revision, and material changes will be notified to account holders.

13. Contact

Cloud By Day Group Pte. Ltd.
7030 Ang Mo Kio Avenue 5, #05-042, Northstar @ AMK, Singapore 569880
Data Protection Officer: dpo@cloudycms.app
Telephone: +65 8967 7188
General enquiries: support@cloudycms.app

Privacy Policy | Cloudy CMS