Privacy Policy
Last updated: July 28, 2026
Summary: We take your privacy seriously. We only collect data necessary to provide our cybersecurity services. We never sell your data to third parties. Your email content is scanned solely for threat detection and is never stored or shared.
1. Introduction
Ciphrai Security ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our cybersecurity platform and related services (the "Service").
By using our Service, you consent to the practices described in this Privacy Policy. If you do not agree, please discontinue use of the Service.
2. Information We Collect
2.1 Account Information
When you register for Ciphrai, we collect:
- Full name
- Email address
- Company name
- Password (stored securely using bcrypt hashing — we never store plaintext passwords)
2.2 Gmail & Email Account Data (OAuth and IMAP)
When you connect a Gmail or Microsoft 365 account via Google OAuth, Ciphrai requests the following Google API scopes:
https://www.googleapis.com/auth/gmail.readonly — Used to read incoming emails in real time and scan them for phishing links, malware attachments, spoofed senders, and other threats. Emails are scanned transiently; the full email body is never stored.
https://www.googleapis.com/auth/gmail.modify — Used to apply the Ciphrai-Quarantine label to emails identified as threats, and to remove that label when a user clears or restores a quarantined email. We do not delete emails without explicit user action.
openid, email, profile — Used solely to identify which Google account is being connected and to display the user's name and email address in the Ciphrai dashboard.
We never store the full content of your emails. Email bodies and attachments are analysed in-process for threat indicators only. Only threat metadata is retained (flagged sender address, detected malicious URL, threat score, subject line). Raw email content is discarded immediately after scanning.
2.2a Google API Services — Limited Use Disclosure
Ciphrai's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Google user data (including Gmail content) is used only to provide the email threat-detection service described in this policy — not for advertising, training AI/ML models, or sale to third parties.
- Google user data is never transferred to third parties except as necessary to provide the service (e.g., encrypted storage on our database host), or as required by law.
- Humans at Ciphrai Security do not read your email content. All scanning is automated.
- You may revoke Ciphrai's access to your Gmail at any time via myaccount.google.com/permissions, or by disconnecting the account from your Ciphrai dashboard.
2.2b IMAP / App Password Connections
As an alternative to OAuth, users may connect email accounts using an App Password (a provider-issued credential that grants limited mailbox access without sharing your main password). When using this method:
- The App Password is encrypted at rest using AES-256-GCM before storage. Your real account password is never requested or stored.
- The same limited-use rules apply: email content is scanned in real time and immediately discarded. Only threat metadata is retained.
- You can disconnect an IMAP-connected account at any time from your dashboard, which permanently deletes the stored App Password.
2.3 Network Security Data
When you enable network protection, we collect:
- Incoming request metadata (IP addresses, user agents, request URLs)
- Detected threats and attack patterns
- Website/domain identifiers
2.4 Payment Information
Payment processing is handled by Paystack, a PCI-DSS compliant payment processor. We do not store credit card numbers, bank account details, or other sensitive payment information on our servers. We only retain:
- Subscription plan and status
- Payment references and dates
- Paystack customer identifiers
2.5 Usage Data
We automatically collect certain information when you use the Service, including:
- Browser type and version
- Pages visited and features used
- Date and time of access
- IP address
3. How We Use Your Information
We use collected information for the following purposes:
- Threat Detection: Scanning emails and network traffic to identify and block cyber threats
- Account Management: Creating and maintaining your account, authenticating access
- Service Improvement: Analyzing usage patterns to improve our platform's effectiveness
- Communication: Sending security alerts, password resets, trial notifications, and service updates
- Billing: Processing payments and managing subscriptions
- Compliance: Meeting legal and regulatory obligations
4. Data Sharing and Disclosure
We do not sell your personal information to third parties. We may share data only in the following circumstances:
- Service Providers: With trusted partners who help operate our Service (e.g., Paystack for payments, cloud hosting providers for data storage), under strict confidentiality agreements
- Legal Requirements: When required by law, court order, or governmental authority
- Safety: To protect the rights, property, or safety of Ciphrai Security, our users, or the public
- Business Transfers: In connection with a merger, acquisition, or sale of assets, with prior notice to affected users
5. Data Security
We implement industry-standard security measures to protect your data:
- Encryption in Transit: All data transmitted between your browser and our servers is encrypted using TLS/HTTPS
- Password Security: Passwords are hashed using bcrypt with salt rounds, making them irreversible
- Access Controls: JWT-based authentication with configurable session timeouts
- Rate Limiting: Protection against brute-force attacks on all authentication endpoints
- OAuth Security: Email integrations use industry-standard OAuth 2.0 protocols — we never see or store your email provider passwords
6. Data Retention
- Account Data: Retained for as long as your account is active. Upon account deletion, all personal data is permanently erased within 24 hours (not 30 days — deletion is immediate via the in-app delete flow).
- Threat Logs: Security event data is retained for up to 12 months for audit and reporting purposes.
- Email Content: Not stored. Scanned in real-time and discarded after analysis.
- App Passwords (IMAP): AES-256-GCM encrypted at rest. Permanently deleted when the connected account is removed or when the company account is deleted.
- OAuth Tokens: Stored encrypted. Revoked and deleted when the email account is disconnected or the company account is deleted.
- Trial Abuse Prevention: Upon account deletion, an anonymized, cryptographically hashed representation (SHA-256) of your email address is retained indefinitely. This hash cannot be decrypted, reversed, or used to identify or contact you. It is retained strictly under legitimate interest (GDPR Art. 6(1)(f) and POPIA Sec. 11(1)(f)) to verify free trial eligibility upon re-registration.
- Payment Records: Retained as required by applicable tax and financial regulations.
7. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Permanently delete your account and all associated data instantly via Settings → Delete Account in your dashboard, or by contacting us. Deletion is immediate and irreversible.
- Portability: Request your data in a machine-readable format
- Objection: Object to processing of your data for certain purposes
- Withdrawal of Consent: Withdraw Google OAuth consent at any time via myaccount.google.com/permissions, or disconnect email accounts from within your Ciphrai dashboard.
To exercise any of these rights, contact us at ciphrai.sec@gmail.com.
8. POPIA Compliance (South Africa)
In accordance with the Protection of Personal Information Act (POPIA):
- We process personal information lawfully and in a reasonable manner
- We collect information for a specific, explicitly defined purpose
- We take reasonable measures to ensure data quality and security
- You have the right to lodge a complaint with the Information Regulator of South Africa
9. International Data Transfers
Our Service is available globally. Your data may be processed in countries outside your jurisdiction. When transferring data internationally, we ensure adequate protection through:
- Use of reputable cloud service providers with appropriate data protection certifications
- Encryption of data in transit and at rest
- Compliance with applicable international data transfer frameworks
10. Cookies and Tracking
We use minimal cookies necessary for the Service to function:
- Authentication tokens: Stored in your browser's local storage to keep you logged in
- Session data: Essential for maintaining your active session
We do not use third-party tracking cookies or advertising networks.
11. Children's Privacy
Our Service is designed for business use and is not intended for individuals under the age of 18. We do not knowingly collect information from children.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. Continued use of the Service after changes constitutes acceptance of the revised policy.
13. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us: