Legal · CyPredict
The fine print, in plain sight
The commitments behind CyPredict — privacy, terms, and risk — written in plain language, and meant to be read.
Legal
Privacy Policy
Last updated: 18 April 2026.
1. Controller
CyPredict (registered in Romania) is the data controller for personal data processed through this platform. Contact: privacy@cypredict.com.
2. What we collect
- Account: email, hashed password, plan, 2FA secret (encrypted at rest), account timestamps.
- Billing: Stripe customer id and subscription state. Payment details stay with Stripe.
- Usage: anonymous product analytics (Plausible, or PostHog with consent). Server logs with IP address and timestamp, rotated and purged after 30 days.
- No sensitive category data. We do not ask for or store government IDs, health data, or trading-account balances.
3. Why we process it
- To provide the Service (contract performance).
- To bill you and meet accounting obligations (legal obligation).
- To keep the platform secure and prevent abuse (legitimate interest).
- To send transactional email (contract performance). Marketing only with opt-in.
4. Processors & sub-processors
We share minimum necessary data with: Vercel (web hosting), Railway / Neon (database and API hosting), Stripe (payments), Resend or Postmark (transactional email), Sentry (error tracking), Plausible or PostHog (product analytics), and a third-party language-model provider for CyIntelligence summaries (content only, no user PII in prompts; full processor list available on request).
5. International transfers
Some processors are based outside the EEA. Transfers rely on Standard Contractual Clauses and supplementary measures. A current list is available on request.
6. Retention
- Account data — while your account is active.
- Server logs — 30 days.
- Audit logs — 3 years (contract & security obligations).
- Billing records — 10 years (Romanian accounting law).
- Deleted accounts — suspended for 30 days, then hard-deleted except records required by law.
7. Your rights (GDPR)
Access, rectification, erasure, restriction, portability, and objection. Export your data at any time via /app/account. File a complaint with the Romanian DPA (ANSPDCP) if you believe we have mishandled your data.
8. Cookies
Essential cookies only by default (authentication session). Analytics cookies are opt-in via the cookie banner. We do not use advertising cookies.
9. Security
TLS in transit, encrypted secrets at rest, bcrypt password hashing, 2FA available, principle of least privilege for internal access, regular backup testing.
10. Changes
We will email registered users at least 30 days before material changes take effect.
