Mockarty Cloud Privacy Policy
Version v1 · Effective from 4 September 2026
This Privacy Policy explains what personal data Artem Orlovich (the "Operator", "we") processes when you use Mockarty Cloud at https://mockarty.ru and the services managed through it (the "Service"), why, for how long, and what rights you have. It is part of the Terms of Service at https://mockarty.ru/legal/terms.
This Policy covers data about you and your team members as users of the Service. Data that you place inside the Service yourself — mocks, recordings, test data, files, prompts ("Customer Content") — is processed on your instructions, and you are responsible for it as its controller (Section 5 of the Terms).
1. Who is responsible
The controller of your personal data as a user of the Service is Artem Orlovich. Contact for privacy matters: i@aorlovich.ru.
2. What we process and why
The Privacy center in your account lists every processing purpose, its legal basis, the retention period, the region where the data is kept, and whether it needs your consent. The purposes currently in use are:
| Purpose | Data | Legal basis | Consent |
|---|---|---|---|
| Account and service delivery | name, email, password hash, second-factor secrets, language and theme, Space membership and roles, sessions | performance of the contract (the Terms) | not required |
| Security and audit | sign-in events, IP address, browser identification, actions taken in the Service, Terms acceptance records | legal obligation and our legitimate interest in protecting the Service | not required |
| Billing and accounting | billing details you enter, invoices, payments, refunds, wallet transactions, seller and tax data | legal obligation (accounting and tax law) and the contract | not required |
| Support | the content of your support requests and their attachments, your account identifiers, correspondence | performance of the contract | not required |
| Product analytics | anonymised usage events: which features are used and how often, performance measurements | your consent, given and withdrawn in the Privacy center | required |
| Crash diagnostics | error reports and technical context when the Service or a desktop application fails | your consent, given and withdrawn in the Privacy center | required |
We do not process special categories of personal data and do not perform decisions based solely on automated processing that have legal effects on you.
3. Where the data comes from
We collect data that you enter (registration, profile, billing, support requests), data produced by your use of the Service (sessions, actions, technical logs), data received from identity providers you choose to sign in with (name and email), and data from payment providers about the outcome of a payment. We do not buy personal data from third parties.
4. Cookies and local storage
The Service uses a session cookie to keep you signed in, a short-lived cookie to protect sign-in through identity providers, and a cookie that remembers your interface language. Your theme choice is kept in the browser's local storage. These are strictly necessary for the Service and need no consent. We do not use advertising or cross-site tracking cookies.
5. Who receives the data
We share personal data only with parties needed to run the Service, and only what they need:
- payment providers, to take payments and process refunds; they receive your payment data directly and are independent controllers of it;
- email delivery providers, to send verification, security and billing messages;
- identity providers you choose for sign-in;
- providers of large language models, when you use AI features: they receive the prompt and the context you submit;
- hosting and infrastructure providers that store and run the Service;
- our personnel and contractors bound by confidentiality, to the extent needed for support and operation;
- public authorities, when the law obliges us to.
The list of processors and the region for each purpose is shown in the Privacy center. Where data leaves the home region, we rely on the safeguards required by applicable law.
6. How long we keep the data
Each purpose has its own retention period and deletion mode, shown in the Privacy center. At the time of this version: account data is anonymised ten years after the account is closed; security and audit records are kept for six years and billing records for five years because the law requires it; support cases are anonymised after three years; product analytics events are anonymised after one year; crash reports are erased after ninety days. Backups are deleted on their own rotation, after which residual copies no longer exist.
7. Your rights
Through the Privacy center you can, without contacting support:
- see every purpose and its details;
- give or withdraw consent for optional purposes at any time, with effect for the future;
- request an export of your data; the export is encrypted and delivered only to your signed-in session;
- request a correction of your profile data;
- request the deletion of your account and data;
- track the status of every request.
You also have the right to object to processing based on our legitimate interest, to restrict processing, and to lodge a complaint with the supervisory authority for personal data in your country. To exercise a right that is not available in the Privacy center, write to i@aorlovich.ru; we may need to verify your identity first. We answer within the period the law sets and no later than 30 days.
Deleting your account removes your access immediately. Data that we must keep by law (billing, audit) stays for its retention period and is then deleted or anonymised; it is not used for any other purpose meanwhile.
8. Security
We protect personal data with technical and organisational measures appropriate to the risk: isolation between Spaces, encryption in transit, encryption of sensitive fields at rest where configured, access control by role, second-factor authentication, and audit logging of administrative actions. If a breach affects your data, we will inform you and, where required, the supervisory authority without undue delay.
9. Children
The Service is intended for professional use by adults. We do not knowingly process data of persons under 18. If you believe a minor has created an account, tell us at i@aorlovich.ru and we will remove it.
10. Changes to this Policy
We may update this Policy. A new version is published at https://mockarty.ru/legal/privacy with a new version number and effective date, and material changes are announced in the Service or by email before they take effect. Optional purposes that are added later require a fresh consent in the Privacy center.
11. Contact
Artem Orlovich · i@aorlovich.ru · https://mockarty.ru
This Policy is published in English and in Russian. In case of a conflict between the versions, the Russian version prevails.