All guides

IT and privacy

Privacy and your data

What Cyberact stores, who can see it, how long it is kept, and how it is exported and deleted.

This guide explains what data Cyberact handles and how. The formal account is in the privacy notice. How the data is protected is in Security and data handling.

What is stored

The user account: email address, name (if one was given), organisation, department, role and status, and when the account was created and last signed in.

Progress: completed lessons with their results and dates, answers to questions (right or wrong, how long the answer took, and the day), the memory bank's review data, daily quiz results, and the profile, which holds things like XP, the streak, streak freezes and settings.

Invitations: who was invited, with which role, who sent the invitation, and when it was sent, accepted or withdrawn.

The access log: sign-ins, failed sign-ins, code requests, invitations and access changes. Each entry records the time, the event, the email address of whoever made the change and of the account it concerned, and a keyed hash of the IP address.

The daily quiz reminder, if someone turns it on: the address and keys of the browser's push service, and the reminder's time, time zone and language.

Summaries in the manager console: your organisation's aggregated figures and the summaries written from them. They contain no names, email addresses or user identifiers.

There are no passwords. Only a keyed hash of a sign-in code is stored, and a code is valid for 10 minutes. IP addresses are never stored as they are, only as a keyed hash.

What stays in the browser

The app also keeps a copy of a person's progress in their browser, so that it keeps working through a short loss of connection. Answers given offline wait in the browser and go to the server when the connection is back.

Signing out clears the browser's cache. Once everything has reached the server, it clears the app's storage as well. Otherwise the storage stays, so that unsent answers aren't lost.

Cyberact uses no analytics, tracking or advertising, and loads nothing from third parties. The service uses one cookie: the session cookie that keeps you signed in.

Who can see what

  • Learners see their own progress.
  • Managers see their own organisation's people and their progress in the manager console, and the organisation's access log. They never see another organisation's data.
  • The leaderboard shows only people who have joined it themselves, and only within their own organisation. It never shows email addresses.
  • Cyberact's administrators see every organisation, so that they can run the service and help customers.

Where the data is

The data is on Cyberact's server at Hostinger, in a database outside the web root. The server is in Hostinger's data centre in Germany, so the data is stored in the EU. Cyberact processes an organisation's users' data on the organisation's behalf under the data processing agreement. The agreement is part of the terms for organisation customers, and its annex 2 lists the sub-processors: Hostinger, Stripe and Anthropic.

Sign-in codes, invitations and reminders are sent through Hostinger's mail server.

The AI summary

The summary in the manager console can be written by a language model. When AI is in use, your organisation's aggregated figures are sent to Anthropic's language model. The aggregate contains no names, email addresses, user identifiers or text written by learners, and groups of fewer than five people are merged. When AI is not in use, the summary is put together from the same figures by fixed rules, and nothing is sent.

AI is on by default for organisations and off for personal accounts. Your organisation's manager can ask for it to be switched off by writing to support@cyberact.io. The request is handled as a change request: Cyberact support switches AI off for your organisation only, and the change is recorded in your organisation's access log. From then on the summaries are compiled by fixed rules, and your organisation's figures are not sent to the language model. AI can be switched back on the same way.

How long data is kept

WhatHow long
Sign-in code10 minutes
Records that limit sign-in attemptsabout a day
Sessionends after a week without use, and after 30 days at the latest
A withdrawn invitation, or one that expired unused90 days, if the person isn't in the organisation
Access log24 months from the event
All of a company's data, once its paid access has ended12 months, or a longer period agreed with the customer. The main admin gets a reminder email 30 days before deletion.
All of an organisation's data, once it has been disabled at its own request or by us90 days from when it was disabled
A personal accountfor as long as it is used. When the subscription ends, the account moves to the free plan and keeps its progress. An account with no sign-in for 24 months is deleted, with a warning email 30 days before. An account is never deleted while it has a subscription running.
Backups14 days

The database is backed up every day. Deleted data is gone from the backups within 14 days.

Exporting data

One person's data: a manager can export all of a person's data in their organisation as one JSON file with Export data on the Users and access page, for a data protection request, for example.

All of the organisation's data: once your access has ended, the Users and access page has an Organisation data section where you can export everything as one JSON file. See Cancelling your subscription.

Evidence of training: the training log and the other CSV exports are in the manager console. See Evidence for your auditor.

Every export is recorded in the access log.

Deleting data

One person: a manager deletes a person and all of their data with Delete. In the access log the person's email address is replaced with an identifier. Backups keep the data for up to 14 more days.

The whole organisation: the data is deleted when the retention period is over. If you want it deleted sooner, write to support@cyberact.io.

Your rights

If you want to see your own data, or have it corrected or deleted, contact your organisation's manager, or write to support@cyberact.io from the email address the request is about. Your rights are listed in the privacy notice.