I think immich.app is the production domain, not cloud?

.cloud is used to host the map embedded in their webapp.

In fairness, in my local testing sofar, it appears to be an entirely unauthenticated/credential-less service so there's no risk to sessions right now for this particular use-case. That leaves the only risk-factors being phishing & deploy environment credentials.