Privacy Policy

Last updated: August 2026

1. Information We Collect

We collect information you provide directly to us, including:

  • Account information (email address, name)
  • Organization details (company name)
  • Monitored email addresses
  • Alert configuration preferences
  • Billing information (processed securely by Stripe)

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our services
  • Monitor email addresses for data breaches
  • Send breach alerts and notifications
  • Process payments and manage subscriptions
  • Send service-related communications
  • Respond to your requests and support inquiries

Authorized Cykanner personnel may use a time-limited (30-minute), read-only support session to view your organization's dashboard for support or operational purposes. Starting a support session creates an audit record of the acting account and time.

3. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • All data encrypted in transit using HTTPS
  • Passwordless, magic-link authentication
  • Organization-scoped customer access controls, with time-limited, read-only support sessions for authorized personnel
  • Automated daily database backups, retained for 7 days

4. Data Retention

We retain your data for as long as your account is active or as needed to provide services, including breach history, for compliance and audit purposes. You can delete your account and its data yourself at any time from Settings > Danger Zone — deletion from our database is immediate and permanent, with no recovery window, and cancels any active subscription. A short-lived session cache may continue recognizing an already-open session for up to 5 minutes after deletion before it expires on its own; no new session can ever be created for a deleted account. A minimal record that an account existed and was deleted is kept for our own audit trail, with your personal details removed from it. Because we retain daily database backups for 7 days (see Data Security above), a deleted account's data may persist in those backup copies until they age out on that same schedule — backups exist solely for disaster recovery and are not used to reconstruct or restore an account you've deleted. If you verified a domain through our HIBP Pro-tier integration, HIBP retains that domain's own verification state under our shared account after you delete it from Cykanner; we cannot erase that record on your behalf.

5. Data Sharing

We do not sell your personal information. We share data with the service providers below (our subprocessors), each limited to what they need to perform their specific function:

  • Third-party breach database provider — monitored email addresses are checked against a breach-notification database as part of every scan
  • DigitalOcean — application hosting, database, and cache/queue infrastructure
  • Stripe — payment processing and subscription billing
  • SMTP2GO — outbound transactional email (sign-in links, breach alerts, and contact-form submissions — if you use our contact form, your name, email, and message are forwarded through it)
  • Cloudflare Email Routing — inbound email to our @cykanner.io addresses (e.g. this page's own contact address below) is routed through Cloudflare before it reaches us
  • OpenAI — used only as a fallback when bulk-importing monitored emails, if our own extraction can't identify any addresses in the file you upload. On that fallback path, the complete raw file content (up to 100,000 characters) is sent to OpenAI, not just the addresses — if your file has other columns or text, that goes too
  • Google Fonts — every page loads a web font from Google's CDN, which receives the visitor's IP address and browser details as part of that request (not data we send Google directly, but a consequence of how the page is built)

Alert channels work the same way regardless of type — email recipients you add, a Slack workspace you connect, or a custom webhook you point us at: the breach-alert content is sent to the destination you configure. Those destinations are yours, not vendors we chose, so they aren't in the list above — but we want to be clear they're still real places your data goes.

Separately from the vendors above, we may also disclose data to law enforcement when legally required to — this is a legal obligation, not a service we've engaged a provider to perform on our behalf.

This list reflects our infrastructure as of the "last updated" date above and changes as our infrastructure does — contact us if you'd like the current list confirmed.

6. Your Rights

You have the right to access, correct, or delete your data. Deleting your account is self-service (Settings > Danger Zone) and immediate. For access or correction requests, or if you'd rather we handle deletion for you, contact us (see below).

7. Cookies

We use essential cookies for authentication and session management. These are necessary for the service to function and cannot be disabled.

8. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "last updated" date.

9. Contact Us

If you have questions about this privacy policy, please contact us at:

Email: [email protected]
Address: 5830 E 2nd St, Ste 7000 #37463, Casper, Wyoming 82609, US