Privacy Policy

Effective date: May 13, 2026 ยท Governing law: Virginia, USA

The short version: The free assessment runs entirely in your browser โ€” we never see your answers. If you join the waitlist, we store your email address in Resend to notify you at launch. We don't sell data, use tracking cookies, or build advertising profiles. That's it.

1. Who we are

CyberPosture ("we," "us," or "our") is a cybersecurity self-assessment tool operated from Virginia, USA. You can contact us at hello@cyberposture.app.

2. What data we collect and why

Free assessment

The free assessment runs entirely in your browser. Your industry selection, domain name, and all question answers are processed locally on your device and are never transmitted to our servers. We have no access to your assessment answers. When you close the tab, everything is gone.

Waitlist sign-up

If you submit your email address to join the waitlist, we collect:

Website analytics

We use Cloudflare Web Analytics to understand how visitors use the site. Cloudflare Web Analytics is cookieless and collects no personally identifiable information. It processes aggregate data โ€” page views, referrer sources, country-level location, and device type โ€” without creating individual user profiles or storing IP addresses. No consent banner is required because no personal data is collected.

3. How we use your data

We do not use your data for advertising, profiling, or any purpose beyond what is listed above.

4. Third-party service providers

We use the following third-party services, each of which processes data on our behalf under their own data processing terms:

We do not sell, rent, or share your personal data with any other third parties.

5. Cookies and tracking

We do not use cookies or any client-side tracking technology. Cloudflare Web Analytics operates without cookies. No consent banner is required or shown.

6. Data retention

Waitlist email addresses are retained until you request removal or until the product launches and the waitlist is no longer active. You can request deletion at any time by emailing hello@cyberposture.app.

7. Your rights

Depending on where you are located, you may have the following rights regarding your personal data:

Virginia residents (VCDPA)

EU and UK residents (GDPR / UK GDPR)

Our legal basis for processing EU/UK personal data is legitimate interest (sending a single launch notification you requested) and consent (implied by voluntarily submitting your email).

Canadian residents (PIPEDA)

All users

To exercise any of these rights, email hello@cyberposture.app. We will respond within 30 days.

8. Data security

Your email address is stored by Resend, which maintains industry-standard security controls. The site is served over HTTPS with HSTS enabled. The free assessment never leaves your device, so there is nothing to secure on our end.

9. Children's privacy

CyberPosture is not directed at children under 13. We do not knowingly collect personal data from children. If you believe a child has submitted their email, contact us and we will delete it immediately.

10. International transfers

Our service providers (Resend, Cloudflare) may process data in the United States and other countries. Both providers maintain appropriate safeguards for international data transfers, including standard contractual clauses where required by GDPR.

11. Changes to this policy

We may update this policy as the product evolves โ€” particularly when the Pro tier launches. We will update the effective date at the top and, if changes are material, notify waitlist members by email.

12. Contact

Questions, requests, or complaints: hello@cyberposture.app

CyberPosture ยท Virginia, USA