Privacy notice

Last updated August 2026

This document describes the platform’s real data practices and is pending review by legal counsel.

This notice explains what personal data CyberHacker.AI(“we”, “us”, CyberHacker.ai) collects when you use our platform, why we collect it, who we share it with, and the choices you have. It covers our marketing site, the customer application, and the security testing services we deliver.

Who we are

The data controller is CyberHacker.AI, Dallas, Texas, United States. For any privacy question or to exercise your rights, contact us at [email protected].

Data we collect

  • Account & identity — name, work email, job title, phone number, company name and website, and the country you operate from, provided when you create an account.
  • Authentication — a securely hashed password (we never store it in the clear), and, if you sign in with Google, LinkedIn or Microsoft, the basic profile and email released by that provider.
  • Engagement data — the targets, scope answers, assets and supporting files you submit for testing, plus the findings, reports and certificates we produce.
  • Support & communications — messages you send us, sales-chat and concierge conversations, and support tickets.
  • Payments — billing records and the last four digits / card brand returned by our payment processor. We do not receive or store full card numbers.
  • Technical — IP address and request metadata used to keep sessions secure and to rate-limit abuse.

How we use it

  • To provide, secure and operate the platform and deliver the services you request.
  • To authenticate you, including two-step verification by email or SMS.
  • To take payment and issue invoices and receipts.
  • To respond to your enquiries and provide support.
  • To detect, prevent and investigate abuse, fraud and security incidents.
  • To meet our legal and regulatory obligations.

Our lawful bases are performance of our contract with you, our legitimate interests in running and securing the service, your consent (where asked), and compliance with law.

Sharing & sub-processors

We do not sell your personal data. We share it only with the service providers that make the platform work — payment, communications and AI providers among them. The current list, and what each one processes, is on our sub-processors page.

International transfers

Some sub-processors operate outside your country. Where personal data is transferred internationally, we rely on appropriate safeguards such as standard contractual clauses.

Retention

We keep account and engagement data for as long as your account is active and as needed to provide the services, then for the period required to meet legal, accounting and security obligations, after which it is deleted or anonymised.

Your rights

Subject to your local law, you may request access to, correction or deletion of your personal data, object to or restrict certain processing, and request portability. Contact [email protected] and we will respond within the timeframe the law requires. You may also complain to your local data protection authority.

Security

Passwords are hashed, sessions are signed and short-lived, transport is encrypted with TLS, and access to engagement data is scoped to your own company. No system is perfectly secure, but we work to protect your data in line with industry practice.

Changes

We will update this notice as the platform evolves and revise the “last updated” date above. Material changes will be communicated through the platform.