CyberNet AI logoCyberNet AI Return to CyberNet
Legal Center · Version 2026-09-17

Privacy Policy

How CyberNet handles account data, submitted evidence, AI processing, connected API keys, browser storage, billing records, legal acceptance, retention, export, and deletion rights.

Effective: 4 September 2026 · Updated 17 September 2026Contact: [email protected]Service: cybernetai.app
On this page1. Scope, controller, and legal operator 2. Information CyberNet may collect 3. How specific features handle information 4. Why CyberNet uses information 5. Legal bases 6. Service providers and recipients 7. International processing 8. Retention schedule 9. Cookies and browser storage 10. Security measures 11. Privacy rights and account controls 12. Account deletion and residual records 13. Automated analysis and human review 14. Children 15. Security incidents 16. Sensitive information users should not submit 17. Changes to this Policy 18. Contact and complaints

1. Scope, controller, and legal operator

This Privacy Policy explains how CyberNet processes personal information when you visit the website, create or use an account, submit content for analysis, connect an API key, purchase or manage a subscription, save reports, use support, or interact with current and planned features.

The data controller is Marks Events FZ LLE, registration number 20116/2025, which operates CyberNet AI. Privacy requests, access requests and complaints may be sent to [email protected].

2. Information CyberNet may collect

Account and identity information

  • first name, last name, full name, email address, user ID, account status, authentication timestamps, and profile metadata;
  • email-verification, password-reset, sign-in, session, and security-event information handled through Supabase;
  • plan, subscription status, billing interval, daily usage, feature access, and account preferences.

Submitted Content and analysis information

  • messages, text, URLs, screenshots, images, QR codes, email headers, filenames, and other evidence you choose to submit;
  • local analysis signals, AI prompts derived from the submission, risk scores, verdicts, evidence, limitations, recommended actions, reports, history, and feedback about results.

Technical and usage information

  • IP address, approximate network location, browser and device type, operating system, page URL, timestamps, language, request identifiers, function logs, error records, security events, and rate-limit information;
  • feature interactions, selected plan, analyses used, report actions, legal-document views, support category, and website-performance data.

Billing and support information

  • Stripe customer, checkout, subscription, invoice, payment status, refund, cancellation, and dispute identifiers; CyberNet does not intentionally store complete card numbers;
  • support form details, contact email, message, category, page URL, submission time, and browser information.

Legal-acceptance records

  • user ID, acceptance type, document versions, server timestamp, page URL, billing cycle when relevant, and limited user-agent information.

3. How specific features handle information

Quick Scan and Analysis AI

Submitted evidence is processed in the browser and may be sent over HTTPS to Netlify Functions. When AI is enabled, relevant content may be sent to OpenAI to generate the requested analysis. CyberNet does not promise that all processing stays on the device.

Recovery Mode

Incident descriptions, quick-answer signals, and optional screenshots you submit to Recovery Mode are processed to generate a recovery case, plan, and task checklist stored in Supabase under your account. CyberNet attempts to detect and redact common secrets (such as passwords, OTPs, and card numbers) before they are stored or sent for AI processing, but automatic redaction is not guaranteed — never submit passwords, one-time codes, recovery codes, full card numbers, seed phrases, or private keys.

Saved reports and history

Some Quick Scan reports may be stored in browser local storage. Pro AI history, Recovery Mode cases, and account information may be stored in Supabase. Screenshot bytes may be excluded from browser-saved history or kept only for the active session, depending on the feature. Browser data can be removed by the user or browser and is not guaranteed to be recoverable.

User-provided OpenAI API keys

A validated key is stored only in the current browser tab’s session storage. It is temporarily transmitted over HTTPS to a Netlify Function for validation and to send the requested analysis to OpenAI. CyberNet does not intentionally store the key in Supabase, the user profile, logs, or saved reports. Closing the tab or selecting “Forget Key” removes the browser copy. OpenAI may process or temporarily retain API data under its own terms and controls.

Business team accounts — your activity is visible to your team owner

If you join a CyberNet AI Business team, the team owner can see what you do on that team. This is the single most important privacy consequence of accepting a team invitation, so it is stated plainly here rather than buried elsewhere.

Specifically, the owner of the team you belong to can view, for every Quick Scan, Analysis AI, and Recovery Mode use you make while you are a member: your name and the email address on your account, the date and time, which feature you used, what you submitted, and the full stored result — including the verdict, risk score, threat type, the full explanation, the warning signs found, the recommended actions and the limits of the check, and for Recovery Mode the case title, incident type, risk level, urgency, status, the recovery plan, your checklist progress, and the plan’s update history.

What is kept from your submissions (updated 17 September 2026). While you are a member of a team, CyberNet stores the text, links, and decoded QR-code contents you submit to Quick Scan and Analysis AI, and the description you write when you open a Recovery Mode case, so that the team owner can read them in the team activity log. Quick Scan normally runs only in your browser; for team members its result and the submitted text or link are also sent to CyberNet for this log. Before anything is stored, payment-card numbers, private keys, and secret-key-style tokens are removed, and Recovery Mode descriptions additionally have one-time codes and recovery phrases removed. Pictures and screenshots you upload are not stored — only what was read from them, such as a QR code’s contents. Treat anything you run on a team account as visible to the team owner.

This applies only to members of a Business team. The team owner’s own activity is not shown to anyone and its submitted content is not stored, and submissions from personal Free and Pro accounts are not added to saved history.

Activity from before you joined a team, and activity after you are removed from it, is not shown to that owner. If you do not want an owner to see your activity, do not accept the invitation and use a separate personal account instead. You are shown this consequence on the invitation screen before you join.

Payments

Stripe processes payment details and returns customer, subscription, invoice, and status information needed to unlock, renew, cancel, refund, or troubleshoot Pro or Business access. For a Business team, billing information belongs to the team owner's account; members do not have access to it.

4. Why CyberNet uses information

CyberNet may process information to:

  • create, authenticate, secure, and support accounts;
  • provide text, link, image, QR, and report functions;
  • enforce Free and Pro limits, save eligible history, and provide downloads;
  • validate and route optional BYOK requests;
  • process subscriptions, invoices, renewals, cancellations, refunds, and payment failures;
  • record legal acceptance and demonstrate payment authorisation or compliance;
  • detect abuse, fraud, attacks, unauthorised access, and service misuse;
  • debug errors, maintain availability, measure performance, and improve safety and usability;
  • respond to support, privacy, security, and legal requests; and
  • comply with law, enforce agreements, and protect users, CyberNet, providers, and third parties.

CyberNet does not sell personal information. CyberNet does not use OpenAI API submissions to train CyberNet’s own public model. Third-party processing is governed by provider terms.

5. Legal bases

Depending on location and context, CyberNet relies on:

  • contract: to provide accounts, analyses, reports, subscriptions, billing, and requested support;
  • legitimate interests: to secure, prevent abuse, troubleshoot, improve, and operate the Services while considering user rights;
  • consent: where law requires it for a particular optional activity or communication;
  • legal obligation: for accounting, tax, sanctions, fraud prevention, consumer, security, and lawful-request duties; and
  • vital or public interests: only where applicable and legally permitted.

Accepting the Privacy Policy acknowledges this notice; it is not blanket consent for unrelated marketing or advertising.

6. Service providers and recipients

CyberNet may disclose limited information to providers that process it for the purposes described above, including:

  • Supabase: authentication, profiles, usage, saved history, legal-acceptance records, and database services;
  • Netlify: website hosting, serverless functions, security, logs, deployment, and support forms;
  • Stripe: checkout, recurring billing, invoices, payment methods, refunds, disputes, fraud prevention, and billing portal services;
  • OpenAI: AI analysis requested by CyberNet or by a user through BYOK;
  • professional advisers and authorities: where reasonably necessary for legal, security, fraud, accounting, insurance, or compliance purposes; and
  • business successors: in a merger, financing, acquisition, restructuring, or sale, subject to appropriate safeguards.

CyberNet does not permit providers to use information for unrelated purposes except as allowed by their direct relationship with the user, their terms, or applicable law.

7. International processing

CyberNet and its providers may process information in the United Arab Emirates, the European Economic Area, the United States, and other countries where providers operate. Those countries may have different data-protection laws.

Where required, CyberNet will use contractual, legal, organisational, or provider safeguards for cross-border transfers and will provide additional information upon a valid request.

8. Retention schedule

CyberNet keeps information only for the periods reasonably necessary for the stated purposes, security, disputes, and legal obligations. Current target periods are:

CategoryTypical retention
Active account and profileFor the life of the account, then deletion from active systems generally within 30 days after a valid deletion request, subject to exceptions below.
Unsaved analysis input and outputCyberNet does not intentionally add it to saved history; temporary function, security, or provider processing may continue for up to 30 days, unless a shorter provider setting applies or an incident requires longer preservation.
Business team activity (submitted text, links, QR contents, Recovery descriptions, and full results of team members)While the member’s account remains active or until the member deletes their data or account; deletion from active systems generally within 30 days and residual backups for up to 90 days. Removal from a team stops new activity being shown to that owner; past activity stays in that team’s log.
Pro saved history and reportsWhile the account remains active or until the user deletes it; deletion from active systems generally within 30 days and residual backups for up to 90 days.
Browser local or session storageUntil the user clears it, the browser removes it, the tab closes for session data, or the feature’s “Forget/Clear” control is used.
BYOK API keyCurrent browser tab only; removed when the tab closes or “Forget Key” is used. It is not intentionally retained in the CyberNet account or database.
Security, access, and rate-limit logsNormally up to 90 days; up to 12 months where needed to investigate abuse, fraud, attacks, or service incidents.
Support and feedback recordsNormally up to 24 months after the matter is closed, unless a dispute or legal duty requires longer.
Billing, tax, invoice, refund, and dispute recordsNormally up to 7 years after the relevant transaction or account closure, or longer where law requires.
Legal-acceptance recordsNormally up to 7 years after account closure or the last relevant transaction, or longer where needed for a legal claim or mandatory obligation.
BackupsRolling backups may retain deleted data for up to 90 days before overwrite, unless isolated for security or legal reasons.

CyberNet may shorten these periods as systems improve. Information may be retained longer when necessary for fraud prevention, security investigations, payment disputes, legal claims, sanctions, tax, accounting, lawful requests, or protection of rights.

9. Cookies and browser storage

CyberNet may use essential cookies, local storage, and session storage for authentication, navigation, preferences, plan state, legal acceptance, temporary API-key handling, saved browser reports, and security. Essential storage is required for core functionality.

If optional analytics, advertising, or non-essential cookies are introduced, CyberNet will update this Policy and provide choices where required.

10. Security measures

CyberNet uses measures intended to reduce risk, including HTTPS, server-side secret storage, authenticated Netlify Functions, Supabase Row Level Security, access controls, request limits, input and file-size validation, security headers, restricted browser permissions, provider authentication, and separation of public and private keys.

No method of transmission or storage is completely secure. Users must protect their devices, passwords, email accounts, API keys, recovery methods, and downloaded reports.

11. Privacy rights and account controls

Depending on applicable law, you may have rights to access, receive a copy of, correct, delete, restrict, object to, or transfer personal information; withdraw consent; request information about recipients and international transfers; ask for review of automated output; and complain to a regulator.

CyberNet’s Account area may provide controls to export available account data, clear saved reports, and request account deletion. Browser-saved information must also be removed through CyberNet’s clear controls or browser settings. Subscription cancellation is separate from account deletion.

CyberNet may verify identity before completing a request. It may refuse or limit a request where law permits, including when necessary to protect another person, preserve security, collect a debt, prevent fraud, or retain legally required records.

12. Account deletion and residual records

Before deleting an account, cancel any active subscription through Manage Billing. A valid deletion request removes the CyberNet authentication user and active account data according to the retention schedule. Saved local browser information is cleared on the requesting browser where technically possible.

Deletion does not require Stripe or other providers to erase records they must retain for payment, fraud, accounting, or legal purposes. CyberNet may retain de-identified information and records necessary for legal acceptance, billing, disputes, security, or compliance.

13. Automated analysis and human review

CyberNet uses automated rules and AI to classify submitted content and generate cybersecurity information. These results may influence a user’s decision but are not intended to make legally binding decisions about credit, employment, insurance, eligibility, or legal rights.

Users should apply independent judgment and may contact support to report an incorrect or concerning result. CyberNet may use submitted feedback to investigate and improve the service.

14. Children

CyberNet is not directed to children under 13 and does not knowingly permit them to create accounts. Users below the legal age of majority should use CyberNet only with a parent or guardian. Contact support if you believe a child’s information was collected without appropriate permission.

15. Security incidents

If CyberNet becomes aware of a personal-data incident, it will investigate, take reasonable containment measures, preserve relevant evidence, and provide notifications required by applicable law. Users should promptly change affected passwords, revoke exposed API keys, enable multi-factor authentication, and contact relevant providers if their own account or submission may have been exposed.

16. Sensitive information users should not submit

Never submit passwords, one-time passcodes, complete card details, private keys, recovery phrases, identity documents, medical records, intimate material, or trade secrets unless there is a lawful, necessary, and protected reason. Redact unrelated personal information before using analysis or support features.

17. Changes to this Policy

CyberNet may update this Policy as features, providers, retention practices, laws, and business operations change. The effective date and version will be updated. Material changes may be communicated through the website, account, or email, and renewed acceptance will be requested where required.

18. Contact and complaints

Privacy questions, access requests, export requests, deletion requests, and complaints may be sent to [email protected]. Include the account email and request type, but never send passwords, one-time codes, API keys, private keys, or complete payment-card information.

© 2026 CyberNet AI — operated by Marks Events FZ LLE, registration number 20116/2025. Contact: [email protected].