Docs Cloud Privacy Center

Cloud privacy center

The Cloud cabinet’s Profile → Privacy center explains every published processing purpose. Required account, security, commerce, and support processing is shown with its legal basis, region, retention window, and deletion mode. It is not presented as a switch. Optional product analytics and crash diagnostics remain off until you explicitly allow them.

Changing an optional choice takes one click: a consent is withdrawn as easily as it was given, with no password prompt. Each accepted, denied, or withdrawn decision advances a revision and appends evidence; changing the current view does not overwrite the earlier decision.

The request history on the same page shows the current state of access/export, correction, and deletion requests. It exposes bounded reason codes for blocked or failed requests, but never displays encrypted request payloads, worker leases, or provider credentials.

The privacy center requires the durable Cloud PostgreSQL configuration. The local in-memory demonstration mode shows the surface as unavailable instead of pretending that a privacy decision was persisted.

Download your data

Choose Create export in the privacy center. Mockarty asks for step-up verification and downloads a JSON document for the signed-in account. The document contains profile data (including your profile picture, if you set one) and bounded metadata for Spaces, linked sign-in providers, sessions, API tokens, terms acceptance, and privacy choices. Passwords, session credentials, API-token hashes, request bodies, and payment-provider payloads are excluded.

The server stores a completed export only in its configured PII encryption envelope and expires it after seven days. If encryption is unavailable, export creation fails closed. Security-audit and accounting categories are identified as legally retained categories rather than being silently omitted.

Correct your profile data

Use Request correction to change the account’s full name. The request requires step-up verification, is encrypted before it is stored, and is applied by the privileged privacy worker. Email changes continue to use the separate verified email-change flow; the worker cannot bypass verification.

Request deletion

Choose Request account deletion and complete the forced step-up check. Cloud creates a tracked deletion request; it does not immediately run an unbounded delete inside the browser request. If you own a team Space with other members, the request is blocked until ownership is transferred.

The privileged privacy worker revokes active sign-in sessions, API tokens, device credentials, and linked sign-in identities, releases memberships and active seats, detaches Desktop installations, and anonymizes the account. It completes the request only through a lease- and generation-fenced database operation.

Deletion is blocked while a legal hold is active, while ownership of a team Space must be transferred, or while the account still controls an active, trial, or past-due subscription. Security, audit, accounting, dispute, and other legally retained evidence remains subject to the published retention policy; a completed request does not claim that legally required evidence was destroyed.

Terms of Service and Privacy Policy

The documents you accept are published in English and Russian on the cabinet’s own address at /legal/terms and /legal/privacy, and on the product site at https://mockarty.ru/legal/terms and https://mockarty.ru/legal/privacy. The sign-up form, the acceptance dialog, the profile page and the footer of the sign-in screen link to them. Each page shows its version and effective date; the page follows the interface language you chose and can be switched with the link in its header.

API surface

The cabinet uses these authenticated endpoints:

  • GET /api/v1/cloud/privacy/purposes
  • GET /api/v1/cloud/privacy/requests
  • GET /api/v1/cloud/privacy/requests/{request_id}
  • PUT /api/v1/cloud/privacy/consents/{purpose}
  • POST /api/v1/cloud/privacy/exports
  • POST /api/v1/cloud/privacy/correction-requests
  • POST /api/v1/cloud/privacy/deletion-requests

Export, correction and deletion require an action-bound step-up proof; a consent change does not. Export, correction, and deletion creation also require a stable Idempotency-Key. Data-subject routes remain available even when a new Terms of Service version is waiting for acceptance.

Use the Cloud cabinet or these authenticated Cloud API endpoints for privacy requests. The customer SDKs, CLI and MCP server do not offer these actions. Sign in with a Cloud account that is allowed to act for the data subject; a Mockarty installation administrator account is not a substitute.