Privacy Policy
In short
Cybercorp gives you an AI copilot, workflows and agents. To do that, we store your account details and the content you create, we process your requests with vetted AI model providers acting on our behalf, and we keep a short security log of sign-ins. We never sell your personal data, we show no advertising and we use no trackers. You can export your data or delete your account yourself, from Settings, at any time.
Who we are and what this policy covers
Cybercorp operates cybercorp.ai and the products available through it: Cyber Copilot, a conversational assistant you can type or speak to; Workflows, drag-and-drop routines that can run on a schedule or in the background; and Agents, a team of AI specialists that act together on your behalf. In this policy we call these products, together with our website, "the Service".
"We" and "us" mean Cybercorp, the controller of the personal data described in this policy. "You" means the person using the Service.
This policy applies to the Service wherever you use it — in your browser, in our desktop apps, and in our mobile apps as they become available. It does not cover third-party services you choose to connect to your account; those are governed by their own terms and privacy policies (see section 7).
Data we collect
We collect only what we need to run the Service. This is the full list.
- Account data — your name or username, your email address, and an avatar if you add one. You can sign up with an email address and password, or with a supported third-party sign-in such as Google.
- Content you create — your conversations and messages with Cyber Copilot, the workflows you build, the files you upload, and the memories you choose to save.
- Connected-app credentials — if you connect one of your own apps or accounts, the credentials needed to act in it. These are stored encrypted at rest.
- Security sign-in log — when you sign in, we record your IP address, an approximate location derived from that IP, your browser and device type, and a timestamp. We keep this to protect your account and to prevent fraud.
- Usage counts — counts of the operations you run, the data you transfer and the storage you use, applied only against the fair-usage quotas of your plan.
- Billing metadata — if you subscribe to a paid plan, our payment processor Stripe handles the payment itself. We receive billing metadata such as your plan, invoices and payment status. We never store your full card number.
- Voice audio — if you use voice input or read-aloud, we process the audio to transcribe your request or to generate the spoken reply.
- Support correspondence — the messages you send to our support and contact addresses.
We do not collect data for advertising, and we do not buy data about you from anyone.
How we use your data
We use the data above for these purposes, and no others.
- To provide and operate the Service — answering your requests, running your workflows and agents, and keeping your content available to you.
- To personalize the Service within your account — for example, applying your saved memories and your theme and language preferences.
- To keep your account secure — detecting suspicious sign-ins and preventing fraud and abuse, using the security sign-in log.
- To enforce fair usage — counting operations against the quota of your plan.
- To bill you — managing subscriptions, renewals, cancellations and refunds through Stripe.
- To support you — answering the messages you send us.
- To comply with the law — keeping records we are legally required to keep, and responding to valid legal requests.
We do not use your data to show you advertising, and we do not sell personal data to anyone.
Legal bases under the GDPR
Where the GDPR applies, we rely on the following legal bases, mapped to the uses above.
- Performance of a contract — providing the Service you signed up for: your account, your content, billing and support.
- Legitimate interests — keeping the Service secure and reliable: the security sign-in log, fraud prevention, and fair-usage enforcement. We balance these interests against your rights, and you can object (see section 11).
- Consent — optional features you switch on yourself, such as connecting one of your apps or using voice input. You can withdraw consent at any time by turning the feature off or disconnecting the app.
- Legal obligation — retaining billing records and responding to requests where the law requires it.
AI processing and model providers
When you send a request to Cyber Copilot, a workflow or an agent, that request — and the content needed to answer it — may be processed by vetted third-party AI model providers acting on our behalf.
These providers act strictly to provide the Service: they process your request in order to produce a response, under contracts that restrict what they may do with the data. We do not sell your personal data to model providers or to anyone else, and we do not let them use it for advertising.
Apps you connect
You can connect your own accounts and apps to the Service so that Cyber Copilot, your workflows and your agents can act in them — always on your instructions.
- We store the credentials needed for the connection encrypted at rest.
- The Service accesses a connected app only to carry out what you asked it to do.
- Your use of a connected app remains governed by that app’s own terms and privacy policy.
- You can disconnect an app at any time; disconnecting removes its stored credentials.
International transfers
We may process data in countries other than the one you live in. Where the GDPR applies and your data leaves the European Economic Area, we rely on recognised safeguards — an adequacy decision of the European Commission where one exists, or the European Commission’s Standard Contractual Clauses — so that your data keeps an equivalent level of protection wherever it is processed.
How long we keep data
- Account data and content — kept for as long as your account is active.
- Account deletion — when you delete your account from Settings, we delete your account data, conversations, workflows, files, memories and connected-app credentials. Copies may persist in backups for a limited period before they are purged. File data in storage becomes permanently inaccessible as soon as its records are deleted.
- Security sign-in log — kept for a limited period, long enough to investigate account-security incidents, then deleted.
- Billing records — kept for as long as tax and accounting law requires.
- Support correspondence — kept for as long as needed to resolve your request, and for a limited period afterwards.
How we protect data
- Data is encrypted in transit between your device and the Service.
- Connected-app credentials are encrypted at rest.
- Access to personal data inside Cybercorp is restricted to the people who need it to operate the Service.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you believe your account has been compromised, change your password from Settings straight away and contact support@cybercorp.ai.
Your rights and controls
The fastest controls are built into the product. From Settings, you can:
- Export your data.
- Change your password.
- Delete your account, which removes your data as described in section 9.
Where the GDPR applies, you also have the right to:
- Access — obtain a copy of the personal data we hold about you.
- Rectification — have inaccurate data corrected.
- Erasure — have your data deleted.
- Restriction — limit how we process your data in certain cases.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests.
- Withdrawal of consent — withdraw consent at any time, without affecting processing that already happened.
To exercise any of these rights, use Settings or write to support@cybercorp.ai. We may ask you to verify that you control the account before we act. You also have the right to lodge a complaint with a supervisory authority — in France, the CNIL — or with the authority where you live.
Children
The Service is not directed at children. You must be at least 16 years old to use it. We do not knowingly collect personal data from anyone under 16. If you believe a child under 16 has created an account, contact support@cybercorp.ai and we will delete it.
Changes to this policy
We may update this policy as the Service evolves — for example, when new apps or features arrive. When we do, we will change the "Last updated" date at the top of this page, and if the changes are significant we will tell you more prominently, such as by email or by a notice in the Service. Your continued use of the Service after an update means the updated policy applies to you.
Contact
For questions about privacy, this policy or your data, write to us. We answer in English or French.
- support@cybercorp.ai — privacy questions, data requests and support.
- hello@cybercorp.ai — anything else.
- sales@cybercorp.ai — enterprise enquiries.
This policy is governed by French law, and disputes relating to it fall to the courts of Paris — without depriving you, as a consumer, of the mandatory protections and competent courts of your country of residence.