Privacy Policy

This policy describes how CyberWatch AI handles personal data across the public scanner, the organization console, phishing simulations, training and the browser extension.

Last updated 22 September 2026

1. About CyberWatch AI

CyberWatch AI provides security awareness and human risk management software. The service comprises a public scam scanner available to anyone, a console through which organizations manage their security programme, tools for running phishing simulations and delivering training, and a browser extension that brings the scanner into the right-click menu.

CyberWatch AI is the data controller for most of the personal data described in this policy. Where an organization subscribes to the service and invites its own people into it, that organization becomes the controller of the records held inside its account and CyberWatch AI acts as its processor. Section 5 explains where the line falls, because it determines who should be approached about a particular record.

Questions about this policy, or about data held by CyberWatch AI, may be sent to info@cyberwatchai.com. The full registered company name, registration number and registered office are in the process of being added to this page; until they appear, correspondence sent to that address is treated as validly given.

2. Scope

This policy applies to the website at cyberwatchai.com and the forms it carries, to the public scanner, to the organization console used by administrators and employees, to the CyberWatch AI extension for Chrome, and to email sent by the service, including account notifications, simulation messages, reports and the newsletter.

It does not extend to other companies' websites or services reached through links in the service. From the moment a link is followed out of CyberWatch AI, the policy of the destination governs.

3. Personal data collected

Some data is provided directly. Creating an account, accepting an invitation into an organization, or completing a form on the site supplies a name and an email address, and where a password is set it is stored only as a cryptographic hash, which means it cannot be read or recovered by anyone at CyberWatch AI. Requesting a demonstration or a complimentary assessment supplies an organization name, its approximate size, its industry and whether security training is currently in place. An administrator setting up an organization supplies job roles, departments and the records of the colleagues being invited. Employees completing training or a readiness assessment supply their answers. Anything written to support, or in reply to a notification, is also held.

The substantial category is content submitted for analysis: the links, messages, emails and screenshots sent to the scanner. Section 4 deals with this separately because it deserves particular attention.

Other data is generated by use of the service rather than supplied. This includes the risk score, label and written explanation produced for each submission; a count of checks performed and the date of the most recent one, which is how limits on the free tier are enforced; the outcome of each simulated phishing message, meaning whether it was delivered, opened, clicked or reported and at what time; records of which training modules were completed, when, and with what result; individual resilience scores and organization security scores recorded periodically so that movement over time can be shown; and anything an employee has deliberately reported to their security team, together with the identity of the person who reported it.

A small amount of technical data arrives automatically. The hosting provider records the originating IP address, browser type and version, device type and the pages requested, in server logs kept as part of delivering the site and protecting it from abuse. A session token is held in the browser to keep a signed-in person signed in.

What a service declines to collect is as telling as what it gathers. CyberWatch AI operates no advertising network, no third-party analytics and no tracking pixels. It does not read, alter or record the web pages a person visits, and this holds for the browser extension as firmly as for the site. Card numbers are never requested or stored, payment being handled in its entirety by the payment provider. Special category data such as health information, religious or political views and biometric data is not collected, and should not be placed into a submission. Personal data is not purchased from data brokers, and it is not sold to anyone.

4. Content submitted for analysis

When a link, message, email or screenshot is submitted to the scanner, that content travels to CyberWatch AI servers, is passed to the AI provider for analysis, and is then stored against the submitting account so that the history remains available. A submission made without signing in is still analysed, but the result is not associated with an identified person.

Whatever the message contains forms part of the analysis. An email pasted in for checking carries with it any colleague's name, any customer's telephone number and any invoice detail that happens to be inside it. Such data is handled under this policy, but the most effective protection remains removing what is not needed before submitting.

Submitted content is not used to train artificial intelligence models. The AI provider processes it in order to return a result, not in order to improve its own models. Submitted content is not read as a matter of routine; access is confined to investigating a fault that has been reported or a suspected abuse of the service.

5. Organization accounts

Where an employer subscribes to CyberWatch AI and issues an invitation, that employer is the controller of the records within its organization and CyberWatch AI acts as its processor. Questions about why simulations are conducted, what is done with the results, or how long a record is retained are therefore properly addressed to the employer in the first instance, and CyberWatch AI will assist the employer in answering them.

The extent of an administrator's visibility is a deliberate design decision rather than an artefact of the software. An administrator can see aggregate figures for the organization and for each department, the invitations issued and accepted, the result of each simulation for each person in terms of delivery, opening, clicking and reporting, training completions and scores, individual resilience scores, and anything an employee has explicitly reported to the security team.

An administrator cannot see the content of checks an employee ran without reporting them, anything scanned on the public scanner under a personal account, the content of direct messages exchanged between two people within the console, or any password. The scanner states this before a check is run. A check that is not reported remains between the person who ran it and the model, and CyberWatch AI regards that undertaking as part of the product rather than a setting to be quietly revised.

6. Phishing simulations

A simulation is an exercise in which an organization sends its own staff realistic but harmless messages in order to measure how they respond. Where an employer conducts such exercises, CyberWatch AI processes on that employer's instructions the work email addresses and names supplied for the people being tested, and the record of whether each message was delivered, opened, clicked and reported, together with the time of each event.

Where a simulated page invites an entry, the service records the fact that something was submitted rather than the characters that were typed. CyberWatch AI has no interest in holding a password and does not retain one.

Simulations are a measurement instrument and not a disciplinary one, and every organization using the service is asked to treat them accordingly. Whether an employer has told its staff that simulations take place, and what it does with the results, is a matter between employer and employee, and in many jurisdictions is something the employer is obliged to explain in advance.

7. The browser extension

The CyberWatch AI extension requests a single permission: the ability to add entries to the right-click menu. It declares no host permissions and injects no content scripts, which in practical terms means it is incapable of reading, altering or observing the pages a person visits.

When a link or a passage of highlighted text is right-clicked and submitted for checking, the extension receives only the item selected, not the surrounding page, and sends that item for analysis together with the session token. The result appears in a window belonging to the extension; the tab being read is never navigated and never touched. Signing out of the extension clears the stored session.

8. Purposes and lawful bases

Creating and operating an account, analysing submitted content and returning a result, and delivering the service that was requested are all necessary for the performance of the contract between CyberWatch AI and the customer. The same basis covers service email that a person needs in order to use the account, such as address verification, password resets, scheduled reports and alerts.

Running simulations, training and reporting for an organization is necessary for the performance of the contract with that organization, and rests additionally on the organization's legitimate interest in securing its business against attacks that target its people.

Enforcing the limits attached to each plan, preventing abuse of the service, keeping the service secure and investigating faults rest on the legitimate interests of CyberWatch AI in operating a sustainable and trustworthy service, and in some respects on legal obligation. Responding to enquiries rests on the same legitimate interest. Accounting, tax and other statutory record-keeping rests on legal obligation.

The newsletter and other marketing email are sent only with consent, which may be withdrawn at any time without affecting anything done before withdrawal. Where processing rests on legitimate interests, CyberWatch AI has considered whether that interest is outweighed by the rights of the individual, and an objection may be raised at any time using the contact details in section 19.

9. Automated analysis

Analysis is produced by a large language model operated on behalf of CyberWatch AI by its AI provider, and it is worth being direct about what that entails.

The model errs in both directions. It may describe a harmless message as risky, and it may fail to recognise a genuine attack. A result should be treated as a well-informed second opinion rather than as a verdict. Every result is accompanied by an explanation precisely so that the reasoning can be judged rather than the number alone.

No decision producing a legal or similarly significant effect is taken about any individual by automated means. Scores presented to an employer describe conduct within exercises and training. CyberWatch AI neither makes nor permits its software to make automated decisions concerning employment. Where an employer relies on a score in reaching a decision about a person, that decision belongs to the employer, and the person is entitled to ask the employer to account for it.

10. Recipients and processors

Personal data is not sold. It is disclosed only to the providers necessary to operate the service, each engaged under a contract restricting them to acting on documented instructions.

Supabase provides the database, authentication and file storage, and therefore holds account details and the stored records of the service. Vercel provides hosting and content delivery, and its server logs carry the requests made to the site along with originating IP addresses. Groq operates the model that analyses submissions and accordingly receives the content of each submission. Resend delivers email and receives the recipient address and the message content. Paystack processes payments and receives the billing details entered with it; CyberWatch AI receives confirmation of payment and the final digits of a card, never the full number. Google distributes the browser extension through the Chrome Web Store and receives installation and listing data under its own policy.

Data is also disclosed to an organization where the service is used as one of its members, in the manner described in section 5. It is disclosed where the law requires it, on receipt of a valid court order or lawful request from an authority, and the affected person will be informed unless CyberWatch AI is prohibited from doing so. It may be disclosed where there is a good-faith belief that disclosure is necessary to prevent serious harm or to investigate fraud or an attack upon the service. Should CyberWatch AI be acquired or merged, data may transfer as part of that transaction, and this policy continues to apply until affected people are notified otherwise.

11. Storage and international transfers

The database is hosted within the European Economic Area. The site is served through a global content delivery network, which means a cached copy of static pages may be held near the person requesting them. The email and AI providers operate internationally and may process data outside the country in which it was collected.

Where personal data leaves the country in which it was collected, the transfer takes place under the terms of the contracts with those providers, which incorporate the standard protections required by applicable data protection law. Detail concerning any particular transfer is available on request.

12. Retention

An account is retained for as long as it exists, and for thirty days after deletion so that it can be restored if it was deleted in error. Scan content and the associated results are retained while the account exists, so that history remains available, and individual items may be deleted sooner by the person who submitted them. Submissions made anonymously are not tied to a person and are retained only in aggregate for service statistics.

Simulation and training records are retained for the duration of the organization's subscription and are deleted within ninety days of its ending, or sooner where the organization instructs it. Demonstration and assessment requests are retained for twenty-four months from the most recent contact. A newsletter subscription is retained until it is withdrawn, after which a record of the withdrawal is kept so that no further email is sent. Billing records and invoices are retained for as long as tax and company law requires, typically six years. Server logs are held by the hosting provider for a short rolling period.

13. Rights

Depending on place of residence, an individual holds some or all of the following rights, and CyberWatch AI honours them for everyone regardless of location, on the view that drawing a line between people according to geography would be a curious way to run a security company.

These are the right to obtain a copy of the personal data held; to have inaccurate data corrected, although most of it can be corrected directly within the account; to request erasure, where the data is not required to be retained; to receive the data in a structured, machine-readable form; to request that processing be restricted while a dispute over accuracy or legitimacy is resolved; to object to processing founded on legitimate interests, and to direct marketing at any time; to withdraw consent where consent is the basis of processing; and to lodge a complaint with the data protection authority of the country of residence.

Any of these may be exercised by writing to info@cyberwatchai.com, and a response will follow within thirty days. Verification of identity may be required first, so that data is not handed to somebody else who has asked for it. Where the data sits within an organization's account, the request will usually be referred to that organization, since the records belong to it, and the person making the request will be told when that has happened.

14. Security

Data travels over encrypted connections and is encrypted at rest by the database provider. Passwords are stored as hashes and cannot be read by anyone at CyberWatch AI. Access to an organization's records is enforced at the database level rather than only within the interface, so that one organization cannot reach another's data even if the interface were circumvented. Multi-factor authentication is available on accounts and is recommended for administrators. Access to production data by CyberWatch AI personnel is confined to those who require it, and is exercised for the correction of faults and the investigation of abuse.

No service can promise perfect security and CyberWatch AI will not pretend otherwise. What can be promised is that where something goes wrong, it will be communicated promptly and truthfully.

15. Cookies and local storage

Only what the service requires in order to function is used. Session storage keeps a signed-in person signed in, without which authentication would be required on every page. A small number of preferences, such as which sections were last left open, are remembered in the browser and never leave the device.

Advertising cookies are not used and browsing is not shared with third-party trackers. Because no non-essential cookies are set, the site carries no consent banner: there is nothing to consent to.

16. Children

The service is built for workplaces and is not directed at children. Personal data is not knowingly collected from anyone under sixteen. Where it appears that a child has supplied data, notification to the address in section 19 will result in its deletion.

An educational institution using CyberWatch AI is responsible for ensuring that any individual it enrols is old enough to use the service, and that it holds whatever permission the law requires.

17. Incidents

Where personal data held by CyberWatch AI is exposed in a manner likely to place someone at risk, the relevant supervisory authority will be notified within the period the law prescribes, and the people affected will be told directly and in plain language what occurred, which data was involved, what has been done about it and what they should do in response.

18. Changes to this policy

This policy is revised as the service changes and as the law changes, and the date at the head of the page always reflects the current version. Where a revision materially affects rights or the use of personal data, notice will be given by email or within the service before it takes effect, rather than the page being altered quietly.

19. Contact

Correspondence concerning this policy, and requests to exercise any right described in section 13, should be sent to info@cyberwatchai.com. Marking the subject line "Data request" or "Privacy question" will direct it appropriately. A response will follow within thirty days and usually a good deal sooner.

Anyone dissatisfied with the response is entitled to complain to the data protection authority of their country of residence. CyberWatch AI would nevertheless prefer to be approached first, so that the matter can be put right.