Legal · Privacy Policy
CyberCLI Privacy Policy
Effective Date: 2026-06-10 · v1.0 · 2026-05-25
This Privacy Policy describes how CyberCLI LLC, a Nevada limited liability company ("CyberCLI", "we", "us") processes limited personal data through our marketing site, account system, checkout, and transactional email. It does not describe the CyberCLI engine running on your hardware — by design, we cannot, because the engine doesn't send us anything.
1. Introduction
CyberCLI is built for data sovereignty: we do not collect security telemetry from your CyberCLI installation. This Privacy Policy explains what limited data we do collect through our marketing site, account system, checkout, and transactional email.
2. Data We Collect
Marketing site visitors
When you visit https://cybercli.com, we may process standard request data needed to operate and secure the site, such as IP address, user agent, request metadata, and security event logs through Cloudflare.
If you submit a contact form, we collect:
- Name.
- Email address.
- Company, if provided.
- Topic.
- Message.
- Daily-salted IP hash.
- User agent.
Contact forms are protected by Cloudflare Turnstile, which may process request and device signals to detect bots and abuse.
We do not use Google Analytics, third-party tracking pixels, or behavioral advertising pixels.
Account holders
If you create a CyberCLI account, we collect:
- Email address.
- Stripe Customer ID.
- License JWS.
- License metadata, including tier, expiration, and key identifier.
- Magic-link authentication tokens.
- Login timestamps and account access records.
Paying customers
For paid subscriptions, Stripe Checkout collects payment and billing information, including:
- Name.
- Email address.
- Billing address.
- Payment method information.
Payment method details are processed by Stripe under Stripe's PCI scope and do not touch our servers in plaintext.
We may store invoice records, subscription status, payment status, Stripe identifiers, and tax or accounting records.
CyberCLI engine users
We collect nothing from the CyberCLI engine.
CyberCLI installations do not send us:
- Security telemetry.
- Alerts.
- Logs.
- Packet data.
- Endpoint events.
- Usage metrics.
- Crash reports.
- Error logs.
- Model prompts or outputs.
- Endpoint counts.
- License verification events.
The CyberCLI license verifier is fully offline. It verifies an EdDSA-signed JWS license against a public key bundled in the binary and does not phone home.
3. How We Use Your Data
We use the limited data we collect to:
- Provide account access through magic-link authentication.
- Deliver license keys and transactional account emails.
- Send renewal notices, invoices, and security advisories.
- Respond to contact form submissions and support requests.
- Process payments, subscriptions, refunds, taxes, and fraud checks.
- Protect the site and account system using Cloudflare Turnstile, Cloudflare WAF, and Stripe Radar.
- Maintain legal, accounting, security, and audit records.
We do not use account or contact data for marketing automation, drip campaigns, or newsletters unless you explicitly opt in.
4. How We Share Your Data
We do not sell your personal data.
We use the following sub-processors for limited business operations:
- Stripe: checkout, payment processing, invoices, subscriptions, fraud prevention, and billing records. Privacy policy: stripe.com/privacy
- Resend: transactional email delivery, including license emails, renewal notices, account emails, and security advisories. Privacy policy: resend.com/legal/privacy-policy
- Cloudflare: site hosting, DNS, Workers, D1 database, WAF, bot protection, Turnstile, and related security operations. Privacy policy: cloudflare.com/policies/privacy
We may disclose data if required by law, subpoena, court order, or valid legal process, or to protect rights, safety, security, and service integrity.
5. Data Retention
We retain data only as long as reasonably necessary for the purposes described in this Policy, unless a longer period is required by law.
Current retention defaults:
- Contact form submissions in Cloudflare D1: retained indefinitely by default unless deletion is requested or an internal retention rule is adopted.
- Account records: retained while active, then up to 7 years after closure for tax, audit, accounting, fraud prevention, and legal purposes.
- License records and invoice records: retained as needed for subscription, accounting, audit, and legal purposes.
- Magic-link tokens: expire within 30 days or sooner, and are intended to be single-use.
- IP hashes: salted daily so they cannot be correlated across days by CyberCLI.
6. Your Rights
Depending on where you live, including under GDPR, UK GDPR, and CCPA/CPRA, you may have rights to:
- Access personal data we hold about you.
- Correct inaccurate personal data.
- Delete personal data.
- Export or receive a portable copy of personal data.
- Object to or restrict certain processing.
- Opt out of certain sharing or sale of personal data, where applicable.
CyberCLI does not sell personal data and does not use cross-context behavioral advertising.
To exercise your rights, contact privacy@cybercli.com. We may need to verify your identity before completing a request.
7. International Data Transfers
CyberCLI is US-based. Our service providers, including Cloudflare, Resend, and Stripe, operate global infrastructure.
If you are located outside the United States, your personal data may be processed in the United States or other countries. Where required, international transfers rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms.
8. Cookies and Tracking
We use a session cookie for magic-link account authentication.
We do not use third-party tracking pixels, Google Analytics, behavioral advertising cookies, or marketing automation cookies.
If we later add privacy-preserving analytics, we will update this Policy and describe what is collected, why, and how to opt out where applicable.
9. Security
We use reasonable technical and organizational measures to protect account, checkout, and marketing-site data, including:
- TLS for data in transit.
- Cloudflare WAF and bot protection.
- Cloudflare D1 encryption at rest.
- Secrets stored in Workers secret storage.
- Single-use, short-lived magic-link tokens.
- Access controls for production systems.
- Optional 2FA via TOTP where available.
CyberCLI v1 may not include 2FA at launch. If not available at launch, we plan to add it after release.
No internet service can be guaranteed completely secure. You are responsible for securing your email account, devices, local CyberCLI installation, and deployment environment.
10. Children's Privacy
CyberCLI is for businesses and professional security operations. We do not knowingly collect personal data from anyone under 18.
If we learn that we collected personal data from someone under 18, we will delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time.
We will post the updated version with a new version date. For material changes, we will provide notice by email where practical.
12. Contact
Privacy requests: privacy@cybercli.com
Security-specific concerns: security@cybercli.com
Mailing address: CyberCLI LLC, State of Nevada, USA. (Postal address available on request via privacy@cybercli.com.)
v1.0 · 2026-05-25 · Reviewed by counsel: pending pre-launch