Legal
CyberLens AI privacy policy
This policy explains how we collect, use, and protect your information.
CyberLensAI is operated by Astra Devs.
Information We Collect
When you create an account, we collect account information. When you perform security scans, we collect scan data. We also automatically collect usage information.
- Account Information: Email address, name and company name if provided, and password (encrypted).
- Scan Data: Target URLs and domain information; vulnerability findings and security reports; bounded website-integrity evidence; a private browser screenshot only when the integrity scanner identifies a suspicious content signal; scan configurations and preferences; and database connection metadata (not credentials).
- Usage Information: IP addresses and device information; browser type and operating system; pages visited and features used; and scan frequency and patterns.
How We Use Your Information
We use collected information to provide and improve our security scanning services, generate vulnerability reports and remediation guidance, authenticate users and maintain account security, send important service updates and security alerts, analyze usage patterns, prevent fraud, and comply with legal obligations.
Data Sharing and Disclosure
We do NOT sell your personal information. We may share data only in these limited circumstances:
- Service Providers: Trusted third parties who assist in operating our platform (cloud hosting, isolated browser rendering, AI analysis, and analytics).
- Legal Requirements: When required by law or to protect rights and safety.
- Business Transfers: In connection with mergers or acquisitions (with notice to users).
- With Your Consent: Any other sharing requires your explicit permission.
Connected AI assistants
When you connect the hosted, read-only CyberLensAI MCP service to an AI assistant and use it to request saved scan information, we return data for your authenticated account through that connection. This can include an account identifier and email address to identify the connected account, plus scan targets, types, status, dates, recorded scores, and total and assessed test counts. During sign-in, an assistant may also request OAuth identity scopes that share your account ID, email, profile details, and phone number if one is saved, and may request a refresh token to stay connected. The consent screen shows the requested scopes. The assistant provider receives and processes this information under its own privacy terms. You can remove an authorized connection in Settings. This hosted connection does not return finding evidence or start a new scan.
CyberLensAI browser extension
The extension performs a limited page-level check locally after the user starts it. If the user connects a CyberLensAI account and explicitly starts a cloud scan, it sends the current page URL to CyberLensAI over HTTPS and stores the resulting report in that account.
- No continuous or passive browsing monitoring
- Local quick-check signals and results remain on the device
- A revocable account credential is stored locally in Chrome
- User data is not sold or used for personalized advertising
Shopify Storefront Integrity App
When you install the CyberLens Storefront Integrity app, Shopify supplies your store’s Shopify domain, name, installation identifier, primary storefront URL, and API version. We use these to authenticate the installation and identify the correct public storefront when a scan is available. For password-protected stores, the app can query Shopify’s password setting and domain SSL flags to generate an unscored prelaunch configuration snapshot. That snapshot is generated when requested, without storing a separate copy. We keep the app session, installation context, scan state and findings, optional badge preferences, and public badge and certificate identifiers while the app is installed. Hosting and scan processing for the Shopify app may occur in the United States. The app does not request Shopify customer, product, order, payment, checkout, or theme-source records. It does not automatically change your theme or security settings; you choose whether to add its badge block in Shopify’s theme editor.
Data Security
We implement security measures including encryption in transit and at rest, access controls, monitoring, audits, and incident response procedures.
Your Privacy Rights
To exercise these rights, contact us at privacy@cyberlensai.com.
- Access: Request a copy of your personal data.
- Rectification: Correct inaccurate or incomplete data.
- Deletion: Request deletion of your data.
- Portability: Receive your data in a machine-readable format.
- Opt-Out: Unsubscribe from marketing communications.
- Restriction: Limit how we process your data.
Cookies and Tracking
We use cookies and similar technologies for authentication and session management, remembering your preferences, analytics and performance monitoring, and security and fraud prevention. You can control cookies through your browser settings. The iOS app does not load optional analytics or advertising cookies and does not track you across other companies’ apps or websites.
Data Retention
We retain your data only as long as necessary for operational and legal purposes:
- Account Data: Until you delete your account.
- Scan Data: 90 days for free website accounts, longer for paid website accounts; bounded integrity evidence follows the related scan’s retention and deletion lifecycle. The Shopify app displays its latest scan and retains its scoped scan results while installed, until uninstall or shop redaction.
- Usage Logs: 12 months for security and compliance.
- Deleted Data: Permanently removed within 30 days.
- Terms of Service Acceptances: 7 years, including IP addresses, timestamps, and version accepted.
- Scan Authorizations: 3 years for per-domain authorization records with attestations.
- IP Address Logs: 12 months for fraud prevention and security.
- Payment Records: As required by tax and financial regulations, typically 7 years.
Chrome Web Store Limited Use
CyberLensAI’s use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements.
Contact Us and Policy Updates
For privacy-related questions or concerns, email privacy@cyberlensai.com. We may update this policy periodically. Material changes will be communicated via email or prominent notice on our platform.
Security references
CyberLens AI guidance is informed by established security standards and public vulnerability intelligence.
- OWASP Top 10: Common web application security risks used as a baseline reference.
- OWASP Application Security Verification Standard: Application security verification guidance for web application controls.
- NIST Cybersecurity Framework: Cybersecurity risk management guidance from NIST.
- CISA Known Exploited Vulnerabilities Catalog: Known exploited vulnerability intelligence for prioritization context.