CyberNet AI logoCyberNet AI Return to CyberNet
Legal Center · Version 2026-08-04

Privacy Policy

How CyberNet handles account information, submitted evidence, AI processing, GhostScan data, browser storage, billing records, and privacy rights.

Effective: 4 August 2026Contact: [email protected]Service: cybernetai.app
On this page1. Scope and controller 2. Information we collect 3. How specific CyberNet features store data 4. Why we use information 5. Legal bases 6. Service providers and disclosures 7. International processing 8. Retention 9. Cookies and browser storage 10. Security 11. Your privacy rights 12. Children 13. Automated analysis 14. Security incidents 15. Changes and contact

1. Scope and controller

This Privacy Policy explains how the operator of CyberNet AI collects, uses, stores, discloses, and protects personal data when you visit cybernetai.app, create an account, submit content, purchase Pro, use GhostScan, contact support, or otherwise use CyberNet.

For privacy questions or requests, contact [email protected]. Before commercial launch, the operator should add its full legal name, registered address, licence details, and any required local data-protection contact.

2. Information we collect

Account and profile data

Name, email address, authentication identifiers, account status, plan, subscription status, billing interval, and settings.

Usage and technical data

Feature use, analysis counts, timestamps, browser and device information, IP address, diagnostic logs, security events, error data, and interaction records.

Submitted Content

Text, links, screenshots, images, QR codes, email headers, investigation notes, and other evidence you choose to analyse.

Analysis and report data

Risk scores, findings, classifications, extracted indicators, AI responses, reports, history, and feedback about results.

Billing and support data

Stripe customer or subscription identifiers, payment status, invoices, refund or dispute information, support emails, and survey submissions. CyberNet does not directly store complete payment-card numbers.

3. How specific CyberNet features store data

  • Free AI accounts: CyberNet is designed not to provide saved account history as a Free feature, although limited server, security, and diagnostic logs may still be retained.
  • Pro AI history: Successful Pro analyses and related report information may be stored in Supabase and displayed only to the signed-in account, subject to access controls.
  • Protect saved investigations: Saved cases may be stored in the browser’s localStorage on that device. Clearing browser data, changing browsers, or losing the device can remove them.
  • Images and screenshots: Image data may be processed in the browser and sent to secure Netlify functions and configured AI or browser-isolation providers. Screenshot bytes are intended to be removed before browser-saved case history is written, but submitted images may still be processed temporarily by providers.
  • BYOK API keys: A visitor-supplied OpenAI API key is stored in sessionStorage for the current browser tab, transmitted over HTTPS to a Netlify function for validation and analysis, and removed when the tab closes or the user selects “Forget Key”. It is not intended to be stored in Supabase by the BYOK feature.
  • GhostScan: Submitted URLs and images may be transmitted to Netlify, an isolated-browser provider, reputation services, and AI services to inspect redirects, behaviour, screenshots, forms, and related signals.
Do not upload information that is unnecessary for the analysis. Redact passwords, one-time codes, full card numbers, private keys, government identifiers, medical information, and unrelated personal data.

4. Why we use information

  • Provide accounts, authentication, analysis, GhostScan, reports, history, billing, support, and requested features.
  • Enforce daily limits, subscription access, fraud controls, security safeguards, and the Acceptable Use Policy.
  • Improve reliability, user experience, threat detection, model prompts, documentation, and product performance.
  • Respond to support requests, refunds, disputes, legal notices, and incident reports.
  • Comply with law, court orders, tax obligations, payment rules, and legitimate security requirements.
  • Protect CyberNet, users, providers, and the public from abuse, attacks, fraud, and unlawful activity.

5. Legal bases

Depending on your location and the activity, CyberNet processes personal data because it is necessary to perform the contract with you, to take steps at your request, to comply with legal obligations, to pursue legitimate interests in providing and securing the Services, or because you have given consent. Where consent is required, you may withdraw it, but withdrawal does not affect earlier lawful processing.

6. Service providers and disclosures

CyberNet may share personal data with providers that help operate the Services, including:

  • Supabase for authentication, profiles, usage, and Pro history.
  • Netlify for hosting, serverless functions, logs, forms, and security.
  • Stripe for checkout, recurring payments, invoices, billing portal, refunds, fraud prevention, and disputes.
  • OpenAI or configured AI providers for AI-assisted analysis. Where configured, requests are designed to use settings such as store:false, but provider terms and technical processing still apply.
  • Browser-isolation and reputation providers for GhostScan, redirects, screenshots, network behaviour, and known-threat checks.
  • Professional advisers and authorities when reasonably necessary to enforce rights, protect safety, investigate abuse, or comply with law.

CyberNet does not sell personal data. CyberNet does not allow payment providers or infrastructure providers to use personal data outside their contracts and independent legal obligations.

7. International processing

CyberNet and its providers may process data in countries other than where you live. Privacy and government-access laws may differ. Where required, CyberNet will use appropriate contractual, organisational, or legal safeguards for international transfers.

8. Retention

CyberNet keeps personal data only as long as reasonably necessary for the purposes described, including providing accounts and subscriptions, preserving reports requested by users, preventing abuse, resolving disputes, maintaining security, and complying with legal, tax, payment, and accounting obligations.

  • Browser localStorage remains until you delete it, the browser removes it, or CyberNet code clears it.
  • SessionStorage, including BYOK keys, normally ends when the browser tab closes.
  • Pro history may remain while the account is active and for a limited period after cancellation or deletion, subject to operational and legal requirements.
  • Payment, fraud, and transaction records may be retained by Stripe and CyberNet as required by law and payment rules.

9. Cookies and browser storage

CyberNet may use essential cookies, localStorage, and sessionStorage for authentication, security, preferences, usage controls, saved browser reports, legal-consent state, and feature operation. Essential storage may be required for the site to work. If analytics or advertising technologies are added later, CyberNet should update this Policy and obtain consent where required.

10. Security

CyberNet uses technical and organisational measures intended to protect personal data, including HTTPS, access controls, authenticated sessions, server-side secrets, database row-level security where configured, provider security controls, and limits on sensitive browser storage. No system is completely secure, and CyberNet cannot guarantee that unauthorised access, loss, alteration, or disclosure will never occur.

11. Your privacy rights

Depending on applicable law, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal data, withdraw consent, and complain to a regulator. Some requests may be limited by security, fraud prevention, legal obligations, other people’s rights, or technical feasibility.

Send requests to [email protected] from the account email. CyberNet may need to verify identity before responding. Cancelling a subscription and deleting an account are separate actions.

12. Children

CyberNet is not directed to children under 13 and does not knowingly permit them to create accounts. Users below the legal age of majority should use CyberNet only with a parent or guardian. If you believe a child’s data was collected without proper permission, contact support for review and deletion.

13. Automated analysis

CyberNet uses automated rules and AI to classify submitted content and generate cybersecurity information. These outputs may significantly influence a user’s decision, but CyberNet does not intend them to make legally binding decisions about eligibility, credit, employment, insurance, or legal rights. Users must apply independent judgment and may request support when a result appears incorrect.

14. Security incidents

If CyberNet becomes aware of a personal-data incident, it will investigate, take reasonable containment measures, and make notifications required by applicable law. Users should immediately change affected passwords, enable multi-factor authentication, and contact relevant providers if their own account or Submitted Content may have been exposed.

15. Changes and contact

CyberNet may update this Policy as features, providers, laws, and business operations change. The effective date and version will be updated, and material changes may be communicated through the site, account, or email.

Privacy questions and requests: [email protected].

© 2026 CyberNet AI. These documents are general website terms and should be reviewed by a qualified lawyer for your legal entity, licensing location, and target markets before commercial launch.