Cradler

Privacy Policy

Last updated 3 August 2026

Cradler is a backend service: you create a project, and your application reads and writes data and files through it. This policy explains what we hold, why we hold it, and how to get it back or get rid of it.

There are two different kinds of data here, and the distinction matters throughout. Account data is about you, our customer. Project data is whatever your application stores — rows and files that we hold on your behalf and never inspect, use or sell.

Who is responsible

The service is operated by [OPERATOR_NAME] ([OPERATOR_ADDRESS]), the data controller for account data. For project data we act as a processor: you decide what goes in and what happens to it, and we only act on your instructions.

Privacy questions and requests: privacy@cradler.ai.

What we collect

Account data. When you sign in with Google or GitHub we receive and store your email address, display name and avatar URL. We do not receive your password. If you subscribe to a paid plan, Stripe processes the payment and we store only the customer reference it returns — we never see your card number.

Project data. The rows your application writes and the files it uploads. We store them so we can serve them back to you. We do not read them, mine them, or use them to train anything.

Usage measurements. Per project and per day: number of API calls, database size in bytes, and stored bytes. These are counts, not contents — they exist to apply plan limits and to bill.

Server logs. Requests to the API are logged with a timestamp, the HTTP method and path, the response status and the calling IP address. Logs are for debugging and abuse investigation.

Cookies. One session cookie so the dashboard knows you are signed in. There are no advertising or third-party tracking cookies.

Why we are allowed to hold it

Under the GDPR, the legal bases we rely on are:

  • Performance of a contract — account data, project data and usage measurements. Without them there is no service to provide.
  • Legitimate interests — server logs, for keeping the service running, secure and unabused.
  • Legal obligation — records we are required to keep, such as those relating to payments.

We do not sell personal data, and we do not use it for advertising.

Where it is stored

Databases run on a server in Los Angeles, United States. Files and backups are stored in Cloudflare R2. The dashboard is hosted by Vercel.

If you are in the European Economic Area or the United Kingdom, this means your data is transferred outside it. We rely on the European Commission’s Standard Contractual Clauses with our providers for those transfers.

Sub-processors — the third parties that may hold data on our behalf:

ProviderWhat it handles
Zenixcloud (US)The server the databases run on
CloudflareFile storage (R2), CDN, network routing
VercelDashboard hosting
StripePayments, for paid plans
Google, GitHubSign-in, if you use them

How long we keep it

DataKept for
Account dataAs long as your account exists. Deleted within 30 days of you closing it.
Project data (live)Until you delete the project. The database is then destroyed after a 7-day grace period, which exists so an accidental deletion can be undone.
Project data (backups)Daily backups are kept 7 days on the free plan and 30 days on paid plans, then deleted. So deleted project data is gone from backups within 30 days at the outside.
Usage measurements24 months, for billing history
Server logsUp to 30 days

Security, stated plainly

Each project gets its own separate database — projects cannot read each other. API keys are stored hashed. Traffic to the API is encrypted in transit with TLS. The database servers are not reachable from the public internet; only the API gateway can talk to them.

Backups are currently stored unencrypted in Cloudflare R2, protected by access controls on that storage rather than by encryption of the backup files themselves. We are working on encrypting them, and this page will be updated when that is done. We would rather tell you the true state than claim a protection we have not yet turned on.

No service can promise it will never be breached. If a breach affects your personal data we will notify you and, where required, the relevant supervisory authority, without undue delay.

Your rights

If the GDPR or a similar law applies to you, you can ask us to:

  • tell you what personal data we hold about you, and give you a copy;
  • correct it if it is wrong;
  • delete it;
  • export it in a machine-readable form;
  • restrict or object to how we use it.

Much of this you can do yourself: the dashboard lets you read and export project data at any time, and deleting a project starts the deletion described above. For anything else, write to privacy@cradler.ai and we will respond within 30 days.

If your application stores other people’s personal data in Cradler, those people should direct their requests to you — you are the controller of that data, and we will assist you in answering them.

If you are in the EEA or UK and are unhappy with how we have handled a request, you may complain to your local data protection authority.

Children

Cradler is a developer tool and is not directed at children. Do not create an account if you are under 16. If we learn that we hold the account data of a child under 16, we will delete it.

Changes to this policy

If we change this policy in a way that materially affects you, we will email the address on your account before the change takes effect. The date at the top always reflects the current version.

This document is written in English. If it is translated, the English text governs.