New Release v2.4 ⚡ Anycast POP Nodes Active • AVIF & WebP 2.0 Engine Live Try Real-Time Sandbox →
Security & Compliance

Privacy Policy

Last updated: July 30, 2026 • Effective Date: January 1, 2026

1. Information We Collect

Modnet Radoslaw Zawartko ("ZawCloud", "we", "us") operates the ZawCloud Images CDN Edge platform. We collect information necessary to operate, optimize, and secure our edge image transformation service:

  • Account Registration Data: Work email, user full name, company name, and encrypted authentication tokens.
  • CDN Edge Telemetry: HTTP request metadata including client IP addresses, Accept headers, requested image dimensions, user-agent headers, and POP cache hit ratios.
  • Payment Information: Processed securely via PCI-DSS compliant payment gateways (Stripe/Braintree). ZawCloud does not store credit card numbers on its servers.

2. Image Asset Processing & Edge Caching

When your web applications request image transformations via ZawCloud CDN URLs, our edge workers retrieve source images from your designated origin buckets (S3, GCS, or HTTP origins).

Transformed variants (AVIF, WebP, JPEG, PNG) are stored in volatile edge memory cache across our global Anycast POPs. We do not inspect, retain, or monetize private image asset content.

3. Data Security & Encryption

All data in transit across our edge network is encrypted using TLS 1.3 with 256-bit AES encryption. Access tokens and HMAC signing keys are stored at rest using Windows DPAPI and FIPS 140-2 validated key vaults.

4. Deleting your account

You can delete your account yourself, from Dashboard → Security. It removes the account and everything belonging to it: API keys, custom domains and their certificates, presets, webhooks, delivery records, usage history, and any team memberships. There is no grace period and nothing to restore afterwards.

Two things do not disappear at that moment, and it is worth being exact about them. Edge nodes cache what they have been told: keys and signed URLs stop being accepted within about a minute, and TLS on a custom hostname can keep working for up to an hour, until each node re-checks. And billing records are kept — the ledger of what was charged names a payment, not a person, and we do not destroy it because the payer left.

Cached image bytes are evicted on their own schedule, or immediately through the purge API before you close the account.

There is no self-service export yet. Ask us before you delete, because afterwards there is nothing left to export.

5. Contact Our Privacy Officer

If you have questions regarding this Privacy Policy or data handling practices, contact our Data Protection Office:

Email: privacy@zawcloud.com
Address: Modnet Radoslaw Zawartko, ul. Wilejki 2, 71-215 Szczecin, Poland