Cloudata

Cloudata Text Expander

Privacy Policy

Effective date: July 20, 2026

Cloudata Text Expander is a browser extension provided by Cloudata. Its sole purpose is to resolve user-configured text shortcuts in supported editable web fields and Chrome's user-activated address-bar keyword mode.

Information handled by the extension

The extension stores shortcut and replacement mappings, replacement formatting, folders, tags, and favorites in Chrome Storage Local. Mappings remain on the current browser profile and are not synchronized by Google. Preferences such as expansion mode, completion sound, and paused website hostnames use Chrome Storage Sync and may follow the user's signed-in Chrome installations when synchronization is enabled.

While a user types in a supported editable field, the extension temporarily reads the current token immediately before the cursor to determine whether it matches a saved shortcut. Password fields are excluded. This transient text is not saved by the extension and is not transmitted to Cloudata or any external server.

Dynamic fill-in and choice variables display a local form before insertion. Values entered in that form are used only for the current expansion and are not saved, synchronized, or transmitted. Date and time variables are resolved locally using the browser's locale.

If the user explicitly selects the Clipboard variable, the extension requests the optional clipboardRead permission. Clipboard text is read locally only when that variable is expanded and is not retained, synchronized, or transmitted. Denying or revoking this permission does not affect regular shortcuts.

JSON and CSV backup files are generated locally after an export command. Imported files are read locally, validated, and merged into the user's mappings; their contents are not transmitted to Cloudata.

When the user explicitly activates the cte keyword in Chrome's address bar, Chrome sends the text entered during that keyword session to the extension. It is compared locally with saved shortcuts. An accepted URL is opened by Chrome; other accepted text is sent to the user's configured search provider through Chrome's Search API. The extension does not retain this input or transmit it to Cloudata.

For the optional Business subscription, the extension retrieves public plan configuration from Cloudata, including the seven-day trial, monthly and annual prices, checkout links, and customer portal link. When Business is activated, the purchase email, license key, a randomly generated installation identifier, and a short browser-platform label are transmitted over HTTPS to Cloudata. The purchase email is compared with the email returned by the license provider and is not stored separately by Cloudata. The license key is encrypted at rest. One-way HMAC values protect installation, activation-token, rate-limit, and audit lookups. The extension stores only a revocable activation token and entitlement status in Chrome Storage Local; these values are not synchronized between browsers.

How information is used

Saved mappings and preferences are used only for shortcut suggestions, formatted and dynamic expansion, organization, backup and restore, website-level pause controls, address-bar shortcut resolution, and optional local sound. Business licensing data is used only to start or manage a trial or subscription, verify the purchaser, activate, validate, or deactivate paid features, process lifecycle events such as expiry and refund, and prevent abuse. Cloudata does not use extension data for advertising, profiling, analytics, credit decisions, or any unrelated purpose.

Sharing and sale of information

Cloudata does not receive, sell, rent, or share users' mappings, typed website content, fill-in values, clipboard content, imported files, address-bar keyword input, search queries, or browsing history. Chrome Sync applies only to preferences. Chrome Sync and the configured search provider are provided and governed by Google under the user's Chrome and Google account settings.

Business trial and subscription checkout is hosted and processed directly by Lemon Squeezy, the merchant of record. The extension and Cloudata license API do not receive or store full payment-card details. Lemon Squeezy receives the purchase and billing information entered at checkout and issues the license key. Cloudata sends the license key and activation instance to Lemon Squeezy's License API to verify monthly or annual subscription status. Lemon Squeezy processes purchase and licensing information under its own privacy terms. Cloudata does not sell licensing information or use it for advertising.

Data retention and deletion

Mappings remain in Chrome Storage Local until the user edits or deletes them in the extension, or removes the extension. Users can remove individual mappings from the popup and create local JSON or CSV backups. Preferences remain in Chrome Storage Sync until changed or removed through Chrome account settings.

The local activation token remains until Business is deactivated or the extension is removed. Server-side encrypted entitlement, activation, webhook-deduplication, and security audit records are retained while needed to operate the trial or subscription, handle refunds or disputes, prevent fraud, and meet legal obligations. Deactivation revokes the browser token and releases its provider activation. Billing records held by Lemon Squeezy follow Lemon Squeezy's retention obligations as merchant of record.

Security

License operations use HTTPS. Provider webhook signatures are verified, requests are rate-limited, license keys are encrypted at rest, lookup identifiers are HMAC-protected, and provider secrets remain only on the server. Product, store, plan variant, and purchase email are verified before activation. Local storage access is restricted to trusted extension contexts, and mappings are never sent to the licensing service.

Chrome Web Store Limited Use

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Website live chat

The Cloudata website provides an optional first-party support chat. When a visitor starts a conversation, Cloudata receives the name, email address, message content, language, and a one-way network identifier used to prevent abuse. Names, email addresses, message content, and private agent access tokens are encrypted at rest in Cloudata's database. Authentication tokens are also protected with one-way HMAC values.

A random conversation token is stored in the visitor's browser so the conversation can be resumed. Cloudata sends immediate email notifications to the support team and sends the visitor an email when an agent replies; the configured email service provider processes those notifications only for message delivery. Chat records expire after 180 days. A visitor may request earlier deletion through help@cloudata.pe.

Changes to this policy

Material changes will be reflected by updating this policy and its effective date before an extension version relying on those changes is published.

Contact

Cloudata

Business address: Av. El Sol Este 428, Urb. San Ignacio, Barranco, Metropolitan Lima, Peru
Contact form: help@cloudata.pe
Support website: https://help.cloudata.pe