Last updated: April 28, 2026
Privacy Policy
This policy explains how Cloud Leader Prep handles personal data for accounts, purchases, downloads, quiz access, and the AI study assistant.
Data controller
The controller is Cloud Leader Prep. Contact: info@paoloronco.it.
Business address: Business address to be added before public launch.
Personal data we process
- Account data, including email address, authentication provider, Firebase user identifier, email verification state, and session records.
- Purchase and entitlement data, including Stripe customer, checkout, subscription, payment references, selected plan, access status, and purchase events.
- Product usage data, including protected download access, quiz access, AI credit usage, rate-limit records, and dashboard activity needed to operate the service.
- AI assistant content, including messages you submit, assistant responses, timestamps, and related user identifiers needed to provide and protect the chat feature.
- Support and transactional email data, including messages required for verification, password reset, purchase confirmation, and account support.
- Analytics data, if you consent, including page views, traffic source, browser and device information, approximate location, and aggregate interaction data collected through Google Analytics.
- Technical data, including IP-related security records, request metadata, error logs, device or browser information, and security audit information.
Why we use personal data
- To create accounts, authenticate users, verify email addresses, maintain sessions, and protect access to paid content.
- To process payments, subscriptions, refunds, invoices, plan changes, and fraud prevention through Stripe.
- To provide downloads, quiz access, daily AI credits, the AI study assistant, and related product features.
- To send transactional messages such as email verification, password reset, purchase confirmation, and credit-limit notices.
- To measure aggregate site traffic and product usage through Google Analytics only when analytics consent has been provided.
- To secure the service, enforce rate limits, detect abuse, debug errors, and maintain service reliability.
- To comply with legal, tax, accounting, consumer protection, and regulatory obligations.
Legal bases
We process data where it is necessary to perform the service contract, where we have a legitimate interest in securing and improving the service, where we must comply with legal obligations, and where consent is required for a specific optional activity.
Processors and third parties
We use service providers only where needed to operate the product. This may include Firebase and Google Cloud for authentication, database, and email workflows; Stripe for checkout, billing, and payment processing; Google Analytics for optional consent-based traffic measurement; n8n or a configured automation endpoint for the AI assistant workflow; email delivery infrastructure for transactional email; and OAuth providers such as Google or GitHub when you choose those login methods.
Payment card details are handled by Stripe and are not stored by Cloud Leader Prep.
Retention
- Account and entitlement records are kept while the account is active and as needed for support, security, and legal obligations.
- Session records are retained until they expire or are revoked, plus a limited period needed for security logs.
- Purchase, refund, invoice, and tax records are retained for the period required by applicable law.
- AI chat records and product usage records are retained as needed to provide the feature, enforce credits, debug issues, and protect the service.
- Transactional email records are retained for operational evidence and support for a limited period unless legal obligations require longer retention.
Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data. You may also withdraw consent where processing is based on consent.
To exercise these rights, contact info@paoloronco.it. You may also have the right to complain to your local data protection authority.
International transfers and security
Providers may process data in countries other than your own. Where required, we rely on appropriate transfer mechanisms and provider commitments. We use access controls, server-side session validation, httpOnly cookies, rate limiting, and provider security controls to protect the service.
Children
The service is not directed to children. If you believe a child has provided personal data, contact us so we can review and remove it where appropriate.