Skip to main content
CyberCookie
HomeAcademyEnterpriseAboutContact
Join the beta
Legal

Privacy Policy

Effective date: August 7, 2026

CyberCookie, LLC ("CyberCookie," "we," "our," or "us") provides cybersecurity education services (including CyberCookie Academy) and cybersecurity software for organizations (including Astraea). This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use our websites, applications, and related services.

1. Information we collect

We collect information you provide directly, information generated while using our services, and limited technical data collected automatically.

Information you provide

  • Contact details such as name, email address, company name, and role.
  • Account details such as login credentials and profile information.
  • Communications you send to us, including support and beta inquiries.

Information generated through service use

  • Learning and progression data in Academy (for example training history, submitted answers, and completion status).
  • Configuration and usage data in Astraea required to provide defensive security workflows and reporting.

Automatically collected information

  • Device and browser metadata, IP address, timestamps, and basic diagnostics required to secure and operate our services.

2. How we use information

  • Provide, maintain, and improve our education and software services.
  • Authenticate users, secure accounts, and prevent abuse.
  • Respond to support requests and communicate service updates.
  • Analyze product performance and reliability.
  • Comply with legal obligations and enforce our terms.

3. Legal bases for processing

Where applicable, we process personal information based on contract necessity, legitimate interests, consent, and legal obligations.

4. Sharing of information

We do not sell personal information. We may share information with:

  • Service providers who help us host, secure, and operate our services.
  • Enterprise customers as needed to administer customer-managed accounts and workspaces.
  • Legal or regulatory authorities when required by law.
  • Successors in connection with a merger, acquisition, or asset transfer.

5. Data retention

We retain information for as long as necessary to provide services, meet legal obligations, resolve disputes, and enforce agreements. Retention periods vary by data type and service context.

6. Security

We implement administrative, technical, and organizational safeguards designed to protect personal information. No method of transmission or storage is completely secure, but we continuously work to reduce risk and improve controls.

7. Your choices and rights

  • You may access and update account profile information in product settings.
  • You may request deletion of your account and associated personal data, subject to legal and contractual obligations.
  • You may opt out of non-essential communications at any time.
  • Depending on your location, you may have rights to access, correct, delete, restrict, or object to certain processing.

8. Children's privacy

Our services are not directed to children under 13 (or the minimum age required by local law). We do not knowingly collect personal information from children without appropriate consent.

9. International data transfers

If information is transferred across borders, we use appropriate safeguards consistent with applicable data protection laws.

10. Changes to this policy

We may update this Privacy Policy from time to time. If changes are material, we will provide notice through our services or by other appropriate means.

11. Contact us

For privacy questions or requests, contact hello@cybercookie.org.

CyberCookie

Practical security for everyone
ready to learn.

PRODUCTSAcademyAstraeaAboutContact
LEGALPrivacy PolicyTerms of Service
SOCIALGitHubLinkedIn
© 2026 CyberCookieLearn deeply. Defend thoughtfully.