Privacy Policy

Last updated: 24 March 2026

1. Introduction

How's My Cyber Pty Ltd ("HMC", "we", "us", "our") operates the How's My Cyber platform (howsmycyber.com). This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our Service.

We are committed to protecting your privacy and handling your data responsibly. We comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth) and take reasonable steps to comply with the EU General Data Protection Regulation (GDPR) where applicable.

2. Information We Collect

2.1 Account Information

When you register, we collect:

  • Full name
  • Email address
  • Organisation name
  • Password (stored as a cryptographic hash, never in plaintext)
  • Role and permissions within your organisation

2.2 Organisation Data

As part of platform configuration, we collect:

  • Organisation domains, industry sectors, and regions of operation
  • Technology stack information (for threat intelligence relevance)
  • Regulatory obligations and compliance requirements
  • Team member details (names, email addresses, roles)

2.3 Assessment and Operational Data

Through your use of the platform, we process:

  • Cybersecurity assessment responses and maturity scores
  • Risk register entries and risk assessments
  • Policy documents and governance records
  • Incident reports and response actions
  • Vendor assessment questionnaires and responses
  • Strategy goals, initiatives, and tasks

2.4 Email Analysis Data (PhishSee)

When you submit emails for analysis, we process email headers, body content, attachments, URLs, sender information, and authentication results (SPF, DKIM, DMARC). This data is analysed for threat indicators and stored as part of your tenant's analysis history.

2.5 Domain and Infrastructure Data

For monitoring features, we collect:

  • DNS records, DMARC reports, and email authentication data
  • SSL/TLS certificate information for monitored domains
  • Asset discovery results (subdomains, IP addresses, open ports)
  • Dark web monitoring results (credential exposures, brand mentions)

2.6 Technical Data

We automatically collect:

  • IP address and browser user agent
  • Session tokens (encrypted, stored as HTTP-only cookies)
  • Language preference
  • Audit logs of platform actions (login, data changes, exports)

3. How We Use Your Information

We use your information to:

  • Provide, operate, and maintain the Service
  • Authenticate your identity and manage access controls
  • Process cybersecurity assessments and generate posture reports
  • Analyse submitted emails and files for security threats
  • Monitor your domains and infrastructure for security issues
  • Deliver threat intelligence relevant to your organisation's profile
  • Generate AI-powered recommendations, analysis, and reports
  • Process payments and manage subscriptions via Stripe
  • Send transactional emails (account verification, alerts, reports)
  • Maintain audit trails for compliance and governance purposes
  • Improve and develop the Service

4. Data Sharing and Third Parties

We share your data only with the following categories of service providers, and only to the extent necessary:

AI Analysis Providers

We send relevant data to AI model providers (currently Anthropic) for analysis features including PhishSee, AI Coach, threat intelligence enrichment, and content generation. Data is transmitted securely and processed under data processing agreements. We do not permit AI providers to use your data for model training.

Payment Processing

Stripe processes your payment information. We do not store credit card numbers, bank account details, or other payment instrument data. See Stripe's privacy policy for details.

Email Delivery

Resend delivers transactional emails on our behalf (account notifications, alerts, reports).

Threat Intelligence Sources

We query external threat intelligence feeds (including CISA, NIST NVD, and other public and commercial sources) to enrich security analysis. Domain names and IP addresses may be sent to these services for lookup purposes.

Analytics

Google Analytics (Google LLC) and Microsoft Clarity (Microsoft Corporation) collect anonymised usage data to help us improve the Service. This includes pages visited, session duration, and interaction patterns. No personally identifiable information is shared with these providers for advertising purposes. See Section 7 for details and opt-out options.

Infrastructure Providers

The Service is hosted on Fly.io with Neon (PostgreSQL) for database, Upstash (Redis) for caching, and Cloudflare R2 for file storage. All data is encrypted in transit and at rest.

We do not sell your personal information. We do not share your data with advertisers. We will disclose information if required by law, regulation, or legal process.

5. Data Isolation and Security

The Platform uses a multi-tenant architecture with strict data isolation between tenants. Your organisation's data is logically separated from other tenants and cannot be accessed by other users or organisations. Security measures include:

  • Tenant-scoped database queries with row-level security
  • Encrypted session tokens with HMAC-SHA256 verification
  • Role-based access control (RBAC) with 10 permission levels
  • TLS encryption for all data in transit
  • Encryption at rest for database and file storage
  • Immutable audit logs for sensitive operations
  • CSRF protection and rate limiting on all endpoints
  • API key authentication with scoped permissions

6. Data Retention

  • Active accounts: Data is retained for the duration of your subscription.
  • Cancelled accounts: Data is retained for 30 days following cancellation, then permanently deleted.
  • Audit logs: Retained for a minimum of 12 months for compliance purposes.
  • PhishSee analysis results: Retained for the duration of your subscription to support trend analysis and historical review.
  • Session data: Session tokens expire after the configured session duration (default: 24 hours).
  • Backups: Database backups are retained for 7 days and then automatically purged.

7. Cookies and Tracking

We use the following cookies and tracking technologies:

7.1 Essential Cookies

  • hmc_session: Authentication session cookie (HTTP-only, secure, same-site strict)
  • NEXT_LOCALE: Language preference cookie

7.2 Analytics

We use the following analytics services to understand how the Service is used and to improve the user experience:

  • Google Analytics (Google LLC):Collects anonymised usage data including pages visited, session duration, referral source, and general location (country/region). Google Analytics may set cookies on your device. Data is processed under Google's Privacy Policy. You can opt out using the Google Analytics Opt-out Browser Add-on.
  • Microsoft Clarity (Microsoft Corporation):Records anonymised session replays and heatmaps to help us understand user interactions. Clarity may set cookies and uses tracking scripts. Data is processed under Microsoft's Privacy Statement.

These analytics services collect data in aggregate form. We do not use advertising cookies, pixel trackers, or social media tracking widgets. We do not sell analytics data or use it for ad targeting.

8. Your Rights

Depending on your jurisdiction, you may have the following rights:

  • Access: Request a copy of your personal data
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your personal data (subject to legal retention requirements)
  • Portability: Request export of your data in a machine-readable format
  • Restriction: Request restriction of processing in certain circumstances
  • Objection: Object to processing based on legitimate interests

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

9. International Data Transfers

Your data may be processed in jurisdictions outside your country of residence, including Australia, the United States, and the European Union (depending on infrastructure provider locations). Where data is transferred internationally, we ensure appropriate safeguards are in place, including standard contractual clauses and data processing agreements with our service providers.

10. Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification at least 14 days before they take effect. The "Last updated" date at the top of this page indicates when the policy was last revised.

12. Contact

If you have questions about this Privacy Policy or our data practices, contact us at: