Privacy Policy
Effective Date: August 4, 2026 · Version 1.0Cloud Army Network, Inc. ("CloudArmy," "we," "us," or "our") is committed to protecting your personal information and your right to privacy. This Privacy Policy describes how we collect, use, share, and protect information when you use the Reactor™ platform applications, including the Reactor Studio desktop application and the Reactor Self Service web application (the "Services").
If you have questions or concerns about this policy or our practices, contact us at privacy@cloud.army.
1. Information We Collect
Account and registration information. To provide access to the Services we collect information that identifies you as an authorized user, such as your name, business email address, organization, and role. Where billing applies, billing details are collected and handled by our payment and invoicing processes.
Customer Data. Your organization uploads or creates research content in the Services — for example study designs, stimuli, and results ("Customer Data"). Customer Data belongs to your organization, is processed only to provide and support the Services, and is never shared between customers.
Research participant data. Research studies run on the Reactor platform are designed to avoid collecting information that could identify participants individually. Participant responses are used in aggregated form to produce insights about group preferences and reactions. Where studies use eye tracking, it captures gaze and visual-attention metrics only — no facial images or facsimiles are recorded or transmitted by the system. No participant personally identifiable information is stored in our systems.
Usage and device information. We automatically collect service-related, diagnostic, and performance information, such as IP address, browser or client characteristics, operating system, pages or features used, timestamps, and error reports. Operational errors may be logged through monitoring tools, including Sentry, to support security, debugging, and service reliability.
Cookies and similar technologies. Reactor Self Service uses cookies necessary for sign-in and session behavior. Optional analytics cookies, where offered, are disabled until you grant consent.
2. How We Use Information
We use the information we collect to:
- provide, operate, maintain, and secure the Services;
- administer accounts, authentication, and role-based access;
- respond to support requests and communicate service notifications;
- monitor for fraud, abuse, and security incidents;
- analyze usage in aggregated and anonymized form to improve the Services; and
- comply with legal and regulatory obligations.
We do not sell or rent your personal information to third parties.
3. Artificial Intelligence Features
The Reactor platform incorporates optional AI features. Important AI privacy protections include:
- Reactor Studio protects confidential information with the Sanity Agent Privacy Wall, which replaces confidential values with pseudonymous tokens before text is sent to external AI models. It is on by default in generally available releases and is a user-controllable setting.
- Customer Data is never used to train AI models without explicit consent.
- Only the data necessary for each feature is sent to AI services, and all transmissions are encrypted in transit.
- AI features connect to third-party model providers through Reactor MCP, under data processing agreements, and data sent to AI services is not retained by us beyond the processing duration.
For detailed information about AI data handling, see our AI Policy.
4. How We Share Information
We share information only:
- with service providers that help us operate the Services (such as cloud infrastructure, monitoring, and AI service providers), under contracts that restrict their use of the information;
- with your organization's administrators, as part of account administration;
- to comply with applicable law, legal process, or governmental requests;
- to investigate, prevent, or act on suspected fraud, security issues, or violations of our terms; and
- in connection with a merger, acquisition, financing, or sale of assets, in which case we will notify affected users if their information becomes subject to a different privacy policy.
5. Data Retention
We keep personal information only as long as necessary for the purposes described in this policy, unless a longer retention period is required or permitted by law. Specific retention practices include:
- AI interaction logs: retained for 90 days for security and troubleshooting.
- AI usage records (which user used which AI feature, and when): retained as audit records.
- AI-generated content: retained as part of your project data according to your organization's retention settings.
- Customer Data: retained according to your organization's agreement and retention settings.
6. Data Security
We implement technical and organizational measures designed to protect the information we process, including encryption in transit, access controls and authentication, isolation of customer data, and security practices aligned with SOC 2 Type II standards. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
7. International Data Transfers
Information may be processed on servers located in the United States, including by AI service providers. Where required, we use appropriate safeguards for cross-border transfers, including Standard Contractual Clauses (SCCs) and data processing agreements with our service providers.
8. Your Rights
Depending on your region (for example the EEA, UK, or California), you may have rights to request access to, correction of, deletion of, restriction of, or portability of your personal information, and to object to certain processing. Where we rely on consent, you may withdraw it at any time. You will not be discriminated against for exercising your rights.
To exercise any of these rights, contact privacy@cloud.army. If you are in the EEA or UK and believe we are unlawfully processing your personal information, you also have the right to complain to your local data protection supervisory authority.
In addition, you have AI-specific controls: disable AI features or protections, request deletion of AI-processed data, and request audit logs of AI interactions for your organization, as described in our AI Policy.
9. Children
The Services are business tools intended for professional use and are not directed to anyone under 18 years of age. We do not knowingly collect personal information from children. If you believe we may have information from a child, contact us at privacy@cloud.army and we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The updated version will be indicated by a revised version number and effective date, and material changes will be communicated through the Services or by email to organization administrators.
11. Contact Us
Privacy: privacy@cloud.army — Support: support@cloud.army — Data Protection Officer: dpo@cloud.army — General: info@cloud.army.
© 2026 Cloud Army Network Inc. All rights reserved.