ALOROS AI · Alorosai Inc
Privacy policy
This policy explains how ALOROS AI / Alorosai Inc handles information for Kloudy.ai and Kloudy’s public MCP discovery connection, including calls made from ChatGPT, Codex and other MCP clients. Effective October 5, 2026. Public discovery requires no Kloudy key or account. This policy does not announce general registration or private account access.
Contact ALOROS AI
For Kloudy privacy requests and plugin support, email gio@tensorverse.ai or use our existing contact form. Put Privacy or MCP/plugin in the subject so the team can route your request. Do not send passwords, API keys or sensitive records.
Public discovery: information we receive
When a client calls https://kloudy.ai/mcp, Kloudy receives the MCP method, request identifier, tool arguments such as a search goal and result limit, and technical request information such as IP address, user agent and timestamps. We process this information to return matching public catalog metadata, operate the service and prevent abuse. The public discovery handler does not intentionally save a separate search-history record, invoke an AI model, execute private tools or provision an account.
What public discovery does not collect
Installing the plugin does not give Kloudy access to your entire ChatGPT or Codex conversation, local files, contacts, private repositories, passwords or payment details. Kloudy receives the information the host actually sends in tool requests. Do not include API keys, account secrets, patient records or other sensitive information in a public search. Catalog results describe third-party resources; they are not proof of a connection or permission to use it.
Technical records and retention
Infrastructure processes network and request metadata to deliver responses and investigate errors or abuse. The public MCP rate limiter uses short-lived hashed network identifiers and counters with expiry set about two minutes ahead; database expiry deletion can occur later. The public reader service log retention is configured for seven days. We do not promise that upstream hosting or client platforms retain no records. Security, legal preservation requirements and separately requested support records may require longer retention.
Support messages
If you use our contact form, we collect the name or organization, reply email, topic, subject and message you provide, your storage consent, and a receipt reference. We use this information to respond, filter abuse and track the inquiry. Contact records are configured to expire after 90 days; database deletion is asynchronous. Accepted messages may be forwarded to our team’s mailbox, whose retention may differ. Contact delivery logs are configured for 14 days. Sending a support request does not subscribe you to marketing.
Cookies, device storage and analytics
Public discovery through MCP does not require a login cookie. Optional website sign-in flows use secure session and anti-forgery cookies; browser features may store preferences or drafts locally. These public policy and support pages do not set analytics cookies or load third-party advertising or analytics scripts. This statement does not cover cookies set by OpenAI, your MCP client, a sign-in provider or websites you choose to open. You can clear site data in your browser; this can end a session or remove local preferences.
Who processes information
AWS provides hosting, request processing, security controls, database storage and delivery infrastructure for this service. Our team and its email service receive support messages when delivered. OpenAI or another MCP host processes your interaction under its own policies before sending a tool request to Kloudy. Third-party resources linked in discovery results have their own policies; public discovery does not itself establish a private account connection to them. We do not sell public discovery requests or support messages or use them for advertising profiles. We may disclose information when legally required or necessary to protect the service and its users.
Your choices and privacy requests
Use public discovery without a Kloudy account, avoid submitting sensitive information, disconnect Kloudy in your host’s plugin settings, and clear browser site data when desired. For access, correction or deletion requests about information held by ALOROS AI / Alorosai Inc, use the contact form and identify the request as Privacy. Include a support receipt if available, but never include credentials. We may ask for proportionate verification before releasing or changing records. We cannot delete records held independently by your MCP host or another resource provider.
Changes and availability
We will update this page when our data practices materially change and show the new effective date. Private OAuth, engine keys and account capabilities are still rolling out; this policy is not a promise of self-service registration, permanent grants or private tools. Any future capability that changes data handling must be disclosed before you use it.