CyberNet AI
Return to CyberNet
Privacy Policy
How CyberNet handles account information, submitted evidence, AI processing, GhostScan data, browser storage, billing records, and privacy rights.
1. Scope and controller
This Privacy Policy explains how the operator of CyberNet AI collects, uses, stores, discloses, and protects personal data when you visit cybernetai.app, create an account, submit content, purchase Pro, use GhostScan, contact support, or otherwise use CyberNet.
For privacy questions or requests, contact [email protected]. Before commercial launch, the operator should add its full legal name, registered address, licence details, and any required local data-protection contact.
2. Information we collect
Account and profile data
Name, email address, authentication identifiers, account status, plan, subscription status, billing interval, and settings.
Usage and technical data
Feature use, analysis counts, timestamps, browser and device information, IP address, diagnostic logs, security events, error data, and interaction records.
Submitted Content
Text, links, screenshots, images, QR codes, email headers, investigation notes, and other evidence you choose to analyse.
Analysis and report data
Risk scores, findings, classifications, extracted indicators, AI responses, reports, history, and feedback about results.
Billing and support data
Stripe customer or subscription identifiers, payment status, invoices, refund or dispute information, support emails, and survey submissions. CyberNet does not directly store complete payment-card numbers.
3. How specific CyberNet features store data
- Free AI accounts: CyberNet is designed not to provide saved account history as a Free feature, although limited server, security, and diagnostic logs may still be retained.
- Pro AI history: Successful Pro analyses and related report information may be stored in Supabase and displayed only to the signed-in account, subject to access controls.
- Protect saved investigations: Saved cases may be stored in the browser’s localStorage on that device. Clearing browser data, changing browsers, or losing the device can remove them.
- Images and screenshots: Image data may be processed in the browser and sent to secure Netlify functions and configured AI or browser-isolation providers. Screenshot bytes are intended to be removed before browser-saved case history is written, but submitted images may still be processed temporarily by providers.
- BYOK API keys: A visitor-supplied OpenAI API key is stored in sessionStorage for the current browser tab, transmitted over HTTPS to a Netlify function for validation and analysis, and removed when the tab closes or the user selects “Forget Key”. It is not intended to be stored in Supabase by the BYOK feature.
- GhostScan: Submitted URLs and images may be transmitted to Netlify, an isolated-browser provider, reputation services, and AI services to inspect redirects, behaviour, screenshots, forms, and related signals.
4. Why we use information
- Provide accounts, authentication, analysis, GhostScan, reports, history, billing, support, and requested features.
- Enforce daily limits, subscription access, fraud controls, security safeguards, and the Acceptable Use Policy.
- Improve reliability, user experience, threat detection, model prompts, documentation, and product performance.
- Respond to support requests, refunds, disputes, legal notices, and incident reports.
- Comply with law, court orders, tax obligations, payment rules, and legitimate security requirements.
- Protect CyberNet, users, providers, and the public from abuse, attacks, fraud, and unlawful activity.
5. Legal bases
Depending on your location and the activity, CyberNet processes personal data because it is necessary to perform the contract with you, to take steps at your request, to comply with legal obligations, to pursue legitimate interests in providing and securing the Services, or because you have given consent. Where consent is required, you may withdraw it, but withdrawal does not affect earlier lawful processing.
6. Service providers and disclosures
CyberNet may share personal data with providers that help operate the Services, including:
- Supabase for authentication, profiles, usage, and Pro history.
- Netlify for hosting, serverless functions, logs, forms, and security.
- Stripe for checkout, recurring payments, invoices, billing portal, refunds, fraud prevention, and disputes.
- OpenAI or configured AI providers for AI-assisted analysis. Where configured, requests are designed to use settings such as
store:false, but provider terms and technical processing still apply. - Browser-isolation and reputation providers for GhostScan, redirects, screenshots, network behaviour, and known-threat checks.
- Professional advisers and authorities when reasonably necessary to enforce rights, protect safety, investigate abuse, or comply with law.
CyberNet does not sell personal data. CyberNet does not allow payment providers or infrastructure providers to use personal data outside their contracts and independent legal obligations.
7. International processing
CyberNet and its providers may process data in countries other than where you live. Privacy and government-access laws may differ. Where required, CyberNet will use appropriate contractual, organisational, or legal safeguards for international transfers.
8. Retention
CyberNet keeps personal data only as long as reasonably necessary for the purposes described, including providing accounts and subscriptions, preserving reports requested by users, preventing abuse, resolving disputes, maintaining security, and complying with legal, tax, payment, and accounting obligations.
- Browser localStorage remains until you delete it, the browser removes it, or CyberNet code clears it.
- SessionStorage, including BYOK keys, normally ends when the browser tab closes.
- Pro history may remain while the account is active and for a limited period after cancellation or deletion, subject to operational and legal requirements.
- Payment, fraud, and transaction records may be retained by Stripe and CyberNet as required by law and payment rules.
9. Cookies and browser storage
CyberNet may use essential cookies, localStorage, and sessionStorage for authentication, security, preferences, usage controls, saved browser reports, legal-consent state, and feature operation. Essential storage may be required for the site to work. If analytics or advertising technologies are added later, CyberNet should update this Policy and obtain consent where required.
10. Security
CyberNet uses technical and organisational measures intended to protect personal data, including HTTPS, access controls, authenticated sessions, server-side secrets, database row-level security where configured, provider security controls, and limits on sensitive browser storage. No system is completely secure, and CyberNet cannot guarantee that unauthorised access, loss, alteration, or disclosure will never occur.
11. Your privacy rights
Depending on applicable law, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal data, withdraw consent, and complain to a regulator. Some requests may be limited by security, fraud prevention, legal obligations, other people’s rights, or technical feasibility.
Send requests to [email protected] from the account email. CyberNet may need to verify identity before responding. Cancelling a subscription and deleting an account are separate actions.
12. Children
CyberNet is not directed to children under 13 and does not knowingly permit them to create accounts. Users below the legal age of majority should use CyberNet only with a parent or guardian. If you believe a child’s data was collected without proper permission, contact support for review and deletion.
13. Automated analysis
CyberNet uses automated rules and AI to classify submitted content and generate cybersecurity information. These outputs may significantly influence a user’s decision, but CyberNet does not intend them to make legally binding decisions about eligibility, credit, employment, insurance, or legal rights. Users must apply independent judgment and may request support when a result appears incorrect.
14. Security incidents
If CyberNet becomes aware of a personal-data incident, it will investigate, take reasonable containment measures, and make notifications required by applicable law. Users should immediately change affected passwords, enable multi-factor authentication, and contact relevant providers if their own account or Submitted Content may have been exposed.
15. Changes and contact
CyberNet may update this Policy as features, providers, laws, and business operations change. The effective date and version will be updated, and material changes may be communicated through the site, account, or email.
Privacy questions and requests: [email protected].