Legal
Privacy Policy
Last updated: September 8, 2026
This policy describes what information CyberBlink AI collects, how we use it, and the choices available to you. For a detailed, tool-by-tool description of how each security tool specifically handles the data you submit, see our Security & Trust page.
Information we collect
CyberBlink AI collects information in three ways: information you give us directly, information generated by your use of the service, and limited information collected automatically when you visit our public pages.
Account information
When you create an account, we collect your full name, email address, and password. Authentication and password storage are handled by Supabase Auth, a managed authentication provider — CyberBlink does not store your password directly.
Security-tool input
Our analysis tools (CVE Lookup, Domain + URL Lookup, Phishing Analyzer, Password Toolkit) process the values you submit to them — a CVE identifier, a domain or URL, message content, or a password to check or generate — in order to return a result. How each tool specifically handles that input (what is logged, hashed, cached, or never transmitted at all) is described tool-by-tool on our Security & Trust page, linked below, so it is not duplicated here.
Usage and log information
Our servers record standard operational and security-audit information for requests to the service, including request identifiers, timestamps, event category and outcome, and — for authenticated requests — an internal account identifier. Security-audit metadata is sanitized before it is recorded.
Public-page analytics
On our public Knowledge Center pages only (the Knowledge Center landing page and individual articles), we use Google Analytics (GA4) to understand aggregate readership — for example, which articles are read and how far a reader scrolls. GA4 events on these pages do not carry your name, email address, account identifier, or any content you submitted to a security tool.
How we use information
To provide the service
Account information is used to create and secure your account, authenticate your sessions, and enforce access to account-only tools and pages. Security-tool input is used to generate the result you requested and nothing else.
To secure the service
Audit-log and request information is used to detect and investigate suspicious activity, enforce rate limits, and maintain the reliability of the platform.
To improve the public Knowledge Center
Aggregate GA4 analytics from our public articles are used to understand which educational content is useful, so we can prioritize future coverage.
Cookies, analytics & advertising
Authentication cookies
Signing in sets a Supabase Auth session cookie so the service can recognize your authenticated session on later requests. This cookie is required for the account and tool features to function and is not used for advertising.
Analytics cookies (Knowledge Center only) & your consent choice
On our public Knowledge Center pages, a small banner asks whether you'd like to allow Google Analytics (GA4). GA4 does not load, and no analytics cookie is set, until you choose "Accept" — choosing "Decline" (or simply not choosing) keeps it off. Your choice is remembered in your browser (not sent to our servers) so you aren't asked again on that device. GA4 is never loaded anywhere else in the application — not on the homepage, sign-in/sign-up pages, dashboard, or any security tool — and declining has no effect on your ability to read any Knowledge Center article in full.
Advertising (Google AdSense)
CyberBlink has registered with Google AdSense and displays an AdSense site-ownership verification tag and a published ads.txt file, both required for our site to be reviewed as an AdSense publisher. As of this policy's last-updated date, this application does not load an AdSense ad-serving script or set an ad-personalization cookie. If and when we begin serving ads, this section will be updated first, and any ad shown on a public page will be provided by Google AdSense, which sets its own cookies and may use them for interest-based advertising subject to Google's own privacy policy.
Security-tool data handling
Each CyberBlink tool handles the data you give it differently, based on what it needs to do its job — for example, the Password Toolkit never leaves your browser, while CVE Lookup queries public vulnerability databases on your behalf. Rather than duplicate that description here (and risk it drifting out of date), see the full breakdown on our Security & Trust page.
Data retention
We retain account information for as long as your account remains open, so that we can provide the service to you.
Security-audit log entries are retained for as long as needed to investigate abuse, security incidents, and platform reliability issues, and are not indefinitely retained by design — see our Security & Trust page for tool-specific detail (for example, some lookup results are held only briefly in memory rather than stored in a database).
We do not currently commit to a fixed, universal retention period across every system, because retention behavior differs by tool, as described on our Security & Trust page. We will update this section if that changes.
Third parties & processors
Supabase
Supabase provides our authentication and database infrastructure, including Postgres row-level security enforcement described on our Security & Trust page.
Google Analytics (GA4)
Google provides analytics for our public Knowledge Center pages, as described above.
Google AdSense
Google AdSense provides the advertising program we have registered our site with, as described above.
Vulnerability-data sources
CVE Lookup retrieves data from the National Vulnerability Database (NIST) and the CISA Known Exploited Vulnerabilities catalog. These are public data sources we query on your behalf; we do not send them information that identifies you.
Hosting infrastructure
The application is hosted on cloud infrastructure providers that operate our servers and network. These providers process data only to deliver hosting and network services and do not use it for their own purposes.
Your choices & rights
Access and correction
You can review and update your full name from your account settings at any time. To request a copy of the account information we hold about you, contact us using the details below.
Account deletion
To request deletion of your account and associated account information, contact us at the email address below. We will act on verified deletion requests, subject to any information we are required to retain for security, audit, or legal reasons.
Browser controls
You can block or delete cookies through your browser's settings. Blocking the Supabase Auth session cookie will prevent you from staying signed in; blocking analytics cookies will not affect your ability to read Knowledge Center articles, which are fully accessible without an account.
Security
We apply the technical protections described in detail on our Security & Trust page, including Supabase-managed authentication, server-side (not merely client-side) access control, PostgreSQL row-level security, standard HTTP security headers including a Content Security Policy, validated post-login redirects, and rate limiting on authentication and analysis endpoints.
No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. We have not yet completed an independent third-party security audit or penetration test of CyberBlink, and do not currently hold SOC 2, ISO 27001, or other third-party security certifications — the same disclosure made on our Security & Trust page.
Children's privacy
CyberBlink is intended for a general professional and consumer security-education audience and is not directed to children. We do not knowingly collect account information from children under 13. If you believe a child has provided us with account information, contact us and we will take appropriate action.
Changes to this policy
This policy was last updated on September 8, 2026. If we make a material change — such as beginning to serve AdSense ads or changing how a security tool handles your data — we will update this page and revise the date above.
Contact
For privacy questions or to exercise the choices described above, email support@cyberblinksecurity.com. To report a security vulnerability, see our Vulnerability Disclosure Policy or email security@cyberblinksecurity.com.