Last updated: May 1, 2026
This Privacy Policy applies to all CloudSlash products, services, and websites operated by CloudSlash Contributors ("we", "us", "our"). This includes:
Each product handles data differently. We describe each below in detail.
CloudSlash CLI collects zero data.
When you install and run CloudSlash locally, no telemetry, analytics, crash reports, usage metrics, or infrastructure data is sent to any external server. All operations — including scans, graph construction, policy evaluation, and remediation — execute entirely on your machine or within your network.
cloudslash upgrade)Your cloud provider credentials, infrastructure metadata, scan results, policy configurations, and AI prompts remain entirely under your control. We have no mechanism to access, view, or retrieve any data from self-hosted installations.
When using the DEVI AI engine locally with Ollama, all inference runs on your hardware. If you configure an external AI provider (OpenAI, Anthropic), data is sent directly from your machine to that provider under their privacy terms. CloudSlash does not proxy, log, or retain any AI-related data.
CloudSlash Cloud is the optional managed service. When you use it, we process the following data:
Infrastructure data is processed solely to provide the service. We do not sell, share, license, or use your infrastructure data for any purpose other than operating CloudSlash Cloud for your account.
Each tenant's data is logically isolated. Credentials are encrypted per-tenant with unique keys. Database queries are scoped to the authenticated organization. We do not aggregate data across tenants.
The CloudSlash website does not use cookies, tracking pixels, analytics services, or advertising scripts. We do not collect any personal data through the website.
The website makes a single API call to api.github.com to display live repository statistics. This request is made from your browser directly to GitHub and is subject to GitHub's privacy policy.
When you publish or install packages from the CloudSlash Registry, we collect:
We do not track which users install which packages. Download counts are incremented anonymously.
We do not use your data to train AI models.
CloudSlash does not use any customer infrastructure data, scan results, policies, or other user-generated content to train, fine-tune, or improve machine learning models. This applies to both self-hosted and cloud deployments.
CloudSlash Cloud uses the following infrastructure providers:
We do not use any third-party data brokers, analytics platforms, or advertising networks.
Depending on your jurisdiction, you may have the right to:
To exercise any of these rights, contact us at privacy@cloudslash.dev.
We implement the following security measures for CloudSlash Cloud:
If you discover a security vulnerability, please report it to security@cloudslash.dev. We follow responsible disclosure practices.
We may update this Privacy Policy to reflect changes in our practices or applicable law. Material changes will be communicated via the CloudSlash website and, for CloudSlash Cloud users, via email notification at least 30 days before they take effect.
For questions about this Privacy Policy or our data practices: