← Cloakiller Legal document

Privacy Policy

Last updated: August 17, 2026

1. Summary in three lines

We keep the minimum the service needs to work: your e-mail, which plan you subscribe to and what you looked up. We do not have your card, we do not sell your data and we do not use your account for advertising. The controller of this data is [LEGAL ENTITY NAME, BRAZILIAN COMPANY REGISTRY NUMBER (CNPJ), ADDRESS].

2. What we collect, and why

DataWhy it existsLegal basis (LGPD)
E-mail and password (stored as a hash, never as plain text) Create your account and authenticate access Performance of a contract
Plan, subscription status and payment reference Unlock the access you paid for and apply the plan's quota Performance of a contract
Record of queries (which target, when, which result) Count the quota, return a recent result without charging again, and investigate errors Performance of a contract and legitimate interest
Technical logs (server errors, calls to providers) Keep the service up and investigate failures Legitimate interest

We do not collect national ID numbers, address, phone number, card data or browsing history. We do not use advertising cookies or third-party tracking inside the application.

3. Payment

Payment data is handled directly by KashPay (with Stripe as the acquirer, in Brazil) and Stripe (international). Card number, CVV and expiry date never pass through our servers. All we get back is the buyer's e-mail, the payment status and a transaction identifier — enough to unlock access.

4. Data about third parties (the offers you audit)

The tool works on public information about companies and campaigns: pages on the open internet, ads published in the Meta Ad Library, domain records and aggregated traffic data. That is commercial information, not consumers' personal data.

We do not collect, sell or expose personal data of the buyers of those offers. If you believe personal data of yours appears in the service improperly, write to the contact in section 10 and we will look into it.

5. The Chrome extension

The Cloakiller extension is a separate product from the website and collects data of its own. It does not work without an active subscription: with no login, no code is injected into any page — the scripts are only registered in the browser after you sign in.

What it observes on its own

Only browsing that starts from an ad click. It recognizes this by Meta's redirector and by the click markers fbclid, igshid, gclid and ttclid — that is, ads from Meta, Instagram, Google and TikTok. In those cases it follows the redirect chain to the final page and records, in your account: the final page, the hops along the way, and what was read from that page (checkout link, payment platform, pixels, technologies and video player), together with your browser's time zone and language — which is what indicates the region that page was being shown to.

The rest of your browsing is neither read nor sent. A page you open by typing the address, from a bookmark or through an ordinary link is not included. And this automatic recording can be turned off in the Account tab of the extension's panel, at any time.

What it sends when you ask it to

What stays in your browser only

Your session token, the filters you leave checked and the ads already filtered (the "Harvested" panel) stay in the extension's local storage and are never sent. Revealing hidden elements, unblocking clicks, unlocking the player and downloading video or images all run entirely on your machine.

The shared index

Captures feed Cloakiller's offer index, which is shared among subscribers. What gets shared is the information about the third-party offer — the page, the checkout, the pixels, the ads. Your identity is not shared: no other subscriber sees who captured what.

What it never collects

The extension does not read or send your health data, financial or payment data, personal communications (e-mail, messages, conversations), passwords for other sites, cookies from other sites, browser history, saved credentials, or what you type into forms.

6. Who we share with

Only the infrastructure the service needs in order to exist:

Some of them operate outside Brazil. International transfers take place under those providers' contractual safeguards, in accordance with article 33 of the LGPD. We never sell personal data to anyone.

7. How long we keep it

8. Security

Traffic always over HTTPS. Passwords stored only as hashes. The database uses row-level isolation, so an account can only see its own data, and access to the service's content requires an active subscription — having an account is not enough. Provider keys are kept in a secrets vault, never in the code.

No system is infallible. In the event of an incident with relevant risk, we notify you and the ANPD (Brazil's National Data Protection Authority) within the legal deadline.

9. Your rights

The LGPD (Lei Geral de Proteção de Dados, Brazil's General Data Protection Law) guarantees that you can confirm whether we process your data, access what we hold, correct whatever is wrong, request deletion, request portability, find out who we share it with, and withdraw consent.

To exercise any of them, write to the contact below. We reply within 15 days. Deleting your account erases your personal data, except for what tax law requires us to retain.

10. Data protection officer and contact

Data protection officer (DPO): [OFFICER'S NAME]gabrielcoragem@gmail.com. Account and support matters: gabrielcoragem@gmail.com.

11. Changes to this policy

If anything changes materially, we let you know by e-mail before it takes effect. The date at the top of this page always indicates the version in force.