Privacy Policy
Last Updated: June 3, 2026
At CyberForget, we are committed to protecting your privacy and safeguarding your personal information. This Privacy Policy outlines how we collect, process, use, and protect your data when you interact with our AI-powered privacy protection platform, automated data removals, secure VPN, and zero-knowledge password manager services.
1. Definitions
- "Policy": This Privacy Policy.
- "We", "Our", "Us": Refers to CyberForget.
- "You", "Your": Refers to the user of our website, tools, or services.
- "Services": Refers to the AI-powered privacy management dashboard, automated data removals, VPN, password manager, and email threat alerts.
- "Personal Information": Any data that can identify you as an individual or relate to an identifiable person.
2. Data We Collect
We collect data that you directly provide and technical details collected automatically to keep our services running securely:
- Account & Profile Details: Full name, email address, password hash, and billing information (processed securely through Stripe; we do not store raw credit card numbers).
- Identity Data (for Data Removals): Any personal details you submit for search and removal purposes, including aliases, birth date, current and previous residential addresses, and phone numbers.
- Usage Data: Technical logs such as your browser type, device information, operating system, and anonymous site interaction metrics via essential cookies.
3. Legal Bases for Processing
In accordance with GDPR, CCPA, and other global data protection frameworks, we process your personal data under the following legal bases:
- Performance of a Contract: Processing is required to perform the services you subscribed to (e.g., verifying payment, activating your VPN tunnel).
- Your Consent: You give explicit permission for us to act on your behalf (e.g., submitting opt-out requests using your personal profile).
- Legitimate Interests: Necessary for maintaining our platform security, debugging code, and optimizing AI features, provided these do not override your privacy rights.
- Legal Compliance: To comply with financial auditing, law enforcement subpoenas, or corporate regulation.
4. How We Use Your Data
We use your information solely to deliver secure and effective services:
- Setting up and securing your account.
- Executing threat scans and presenting exposure reports.
- Automating data broker opt-outs and legal removal requests.
- Processing subscriptions and preventing billing fraud.
- Providing customer support and debugging technical errors.
5. Data Removals Specifics
To successfully request your deletion from data broker databases and people search directories, our AI system handles data in the following manner:
- Targeted Submission: We compile the identifiers you submit (e.g., name, past addresses, email) and feed them to automated opt-out systems that fill out removal requests on broker websites.
- Alias & Verification Emails: We may generate temporary email aliases or verification mailboxes on your behalf to receive, parse, and confirm deletion responses from data brokers without exposing your primary inbox.
- Zero Sale: We strictly do not sell, license, or monetize the personal search data you provide. It is used exclusively to facilitate your opt-out requests.
6. VPN Specific Privacy (No Logs)
We design our VPN service around a strict zero-logs policy to protect your identity and internet activity from surveillance:
- Zero Activity Logging: We do not log, store, track, or monitor your online activity while connected to the VPN. This includes your browsing history, destination IPs, DNS queries, search queries, or downloaded content.
- Zero Connection Logging: We do not log your original source IP address, the VPN IP address you are assigned, connection timestamps, or session durations.
- Aggregated Network Statistics: We track anonymous, aggregated bandwidth consumption and general network load indicators to maintain service performance. This aggregate data is completely detached from individual accounts or sessions.
7. Password Manager (Zero Knowledge)
The Password Manager functions as a zero-knowledge, end-to-end encrypted storage environment:
- Client-Side Encryption: All passwords, notes, and usernames are encrypted directly on your device before they are transmitted to our cloud sync servers. Encryption is performed using AES-256 standard encryption keys derived from your Master Password.
- No Server Keys: Your Master Password is never sent to our servers. We do not hold decryption keys. We have absolutely no way to inspect or read the contents of your credentials vault.
- Data Retention on Deletion: If you choose to delete your account or vault, all associated encrypted data blobs are permanently and immediately purged from our servers.
9. Data Retention & Security
- Data Retention: We store your personal information only for as long as your account remains active or as required by law for auditing and tax compliance.
- AES-256 Encryption: We encrypt sensitive data in transit using TLS/HTTPS protocols and at rest using AES-256 standards.
- Security Audits: We undergo periodic external security audits and maintain compliance with industry standards to prevent data breaches.
10. Your Rights & Choices
Regardless of your geographic location, we respect your rights to control your personal data. You can exercise these options via your account settings or by contacting us:
- Right of Access & Correction: Review and update your personal info at any time inside your dashboard.
- Right of Erasure ("Right to be Forgotten"): Request that we delete all your stored accounts and data from our records.
- Right to Restrict or Object: Object to processing your data for marketing campaigns or analytical research.
- Right to Portability: Export a structured file of your account data.
12. International Transfers
As a global platform, your personal information may be transferred to and processed in countries outside your residence where privacy laws might differ. We use Standard Contractual Clauses (SCCs) to ensure that your data receives an equivalent standard of protection regardless of location.
13. Children’s Privacy
Our Services are not designed for or marketed to individuals under the age of 16. If we discover that we have inadvertently collected personal data from a child under 16 without parental verification, we will delete that data immediately.
14. Policy Modifications
We may update this Privacy Policy as our features evolve or when regulatory standards shift. When updates occur, we will post the new version on this page and revise the "Last Updated" date. We encourage you to review this policy periodically.
15. Contact Privacy Hub
For privacy concerns, complaints, data deletion requests, or to contact our Data Protection Officer (DPO), please email:
- Privacy Hub: privacy@cyberforget.com
- General Inquiries: support@cyberforget.com