Cloud World Model on Smithery
    Back to Home

    Privacy Policy

    Effective date: September 28, 2026

    1. Overview

    Cloud World Model ("the Platform") is a product of Canvas Cloud AI. This Privacy Policy explains what information we collect when you use the Platform, how we use it, and the choices you have. By accessing or using the Platform you agree to the practices described here.

    2. Information We Collect

    • Account & API key data — when you generate an API key we store a hashed version of the key, a display prefix, the scopes you requested, and optional metadata you supply.
    • Simulation data — scenario definitions, resource configurations, traffic patterns, failure injections, metrics, and events that you create or run on the Platform.
    • Usage & log data — server-side request logs including IP address, request path, HTTP method, response status, and timestamps. These are used for security monitoring, debugging, and rate limiting.
    • Webhook configuration — callback URLs and HMAC secrets you register for asynchronous job notifications.
    • Browser data — standard browser telemetry such as page load timing, screen size, and browser type collected by our hosting provider (Replit).

    We do not collect payment card data, government identifiers, or sensitive personal health information.

    3. How We Use Your Information

    • Operate and improve the simulation engine and APIs.
    • Authenticate API requests and enforce rate limits.
    • Detect abuse, fraud, and security threats.
    • Send job-completion webhook callbacks to URLs you configure.
    • Generate AI-powered explanations of simulation results via OpenAI (see Sharing of Information).
    • Comply with legal obligations.

    4. Sharing of Information

    We do not sell your data. We share information only in the following limited circumstances:

    • Service providers — Replit (hosting & infrastructure) and other vendors necessary to operate the Platform, bound by confidentiality obligations.
    • OpenAI — simulation context (resource types, metrics, and event descriptions) is sent to OpenAI to generate explanations. Responses are treated as untrusted text. No API keys or personal identifiers are included in prompts.
    • Legal requirements — if required by law, regulation, court order, or to protect the rights and safety of Canvas Cloud AI and its users.

    5. GitHub App and PR reports

    When you install the Cloud World Model GitHub App, it reads only the infrastructure files a pull request touches, plus the support files needed to model them, at the PR's base and head commits. It does not access cloud credentials, cloud environments, Terraform state, provider APIs, application code or production traffic. Full details are on GitHub PR reports.

    The App posts a comment and a GitHub Check on the pull request. Each report is also saved and viewable through an unlisted link, which anyone with the link can open. Report links do not currently expire, and uninstalling the App does not remove existing reports. We store only a hashed reference to the API key you link during setup, never the key itself.

    6. Data Retention

    • Anonymous demo simulations are removed automatically after about 5 minutes of inactivity, and only a limited number are kept.
    • Simulations paid for with an x402 wallet expire 90 days after their last use, and their metrics and events are removed with them.
    • Simulations created with an API key are kept until you delete them and do not otherwise expire. RL clone simulations created for API-key environments are an exception: they are removed, along with their metrics and events, when the environment is canceled or after its inactivity timeout (two hours by default).
    • Account and API key records are kept while your account exists. API keys are stored only as hashes.
    • Request logs (IP address, path, method, status, timestamp) are kept by our hosting provider according to its own retention settings.
    • PR reports are covered in the GitHub App section above.

    To ask about your data, contact api@cloudworldmodel.ai.

    7. Security

    API keys are stored as bcrypt hashes; raw key values are shown only once at creation time. Webhook callbacks are signed with HMAC-SHA256. All traffic is protected by TLS. Despite these measures, no system is perfectly secure and you use the Platform at your own risk.

    8. Your Rights & Choices

    Depending on your jurisdiction you may have rights to access, correct, or delete personal data we hold about you. To exercise these rights, or to ask a question about this policy, contact us at:

    Canvas Cloud AI
    Email: api@cloudworldmodel.ai

    9. Children

    The Platform is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, please contact us and we will delete it promptly.

    10. Changes to This Policy

    We may update this policy from time to time. Material changes will be announced on the Platform. Continued use of the Platform after the effective date of any change constitutes your acceptance of the revised policy.