Privacy policy
How Unwhisper handles your account data, and what happens to the content you submit for scanning. Last updated 14 August 2026.
1. Who we are
CYBERROCK LTD, registered in England and Wales (company number GB15069070), 128 City Road, London EC1V 2NX, United Kingdom. We are registered with the Information Commissioner's Office. Contact us about anything on this page at info@cyberrock.ai.
2. Content you submit for scanning
Content you submit to the scanning API or console is never retained. It is discarded once the verdict is returned. We do not log or store the text or files you scan, and we do not use them to train our models. What we keep is the verdict and the usage metrics needed to bill and operate the service, not the input.
The one exception is a forensic report, which you must explicitly request per scan. It contains extracts of the analysed content, is available only through a signed link that expires five minutes after it is issued, and is deleted automatically when that window closes.
If the content you scan contains personal data, you are the controller of it and we act as your processor, handling it only to return a verdict. Our data processing agreement sets out the Article 28 terms.
3. Data we collect as controller
Account data: your name, work email address, organisation, and authentication records.
Billing data: plan, credit balance, transaction history, and invoice records. Card details are handled by our payment provider and are never held by us.
Usage data: API requests, credits consumed, verdicts returned, and timestamps.
Technical data: IP address, request metadata and error logs, used for security and abuse prevention.
4. Why we use it, and our lawful basis
- To provide the service, performance of a contract with you.
- To bill you and keep accounting records, performance of a contract, and legal obligation under UK tax and company law.
- To secure the service and prevent abuse, our legitimate interest in keeping the service available and safe.
- To contact you about your account, performance of a contract.
- To send product or marketing email, consent, which you may withdraw at any time. Service messages about your account are not marketing and continue while you hold an account.
5. Who we share it with
We do not sell your data. We share it only with processors who help us run the service: Amazon Web Services for hosting, our payment provider for card processing and invoicing, and our transactional email provider for verification and account messages. Each acts on our instructions under contract. A current list naming each processor is available on request. We may also disclose data where required by law.
6. Where your data is held
The hosted service runs on Amazon Web Services in their London region. Account, billing and usage data is held there. Some processors may handle data outside the UK; where they do, transfers are covered by adequacy regulations or by the International Data Transfer Agreement or Addendum.
7. How long we keep it
Scanned content is not kept at all. Forensic reports are deleted automatically five minutes after they are generated. Account data is kept while your account is open and deleted within 90 days of closure. Billing and invoice records are kept for seven years after the end of the relevant financial year, as UK tax law requires. Security and error logs are kept for up to 12 months.
8. Security
Access to production systems is restricted and authenticated. Data is encrypted in transit. API keys are stored so that they cannot be read back, and can be revoked at any time. The design choice that protects you most is simply not retaining scanned content in the first place.
9. Cookies
This application sets only the cookies required to keep you signed in and to protect against cross-site request forgery. These are strictly necessary and do not require consent. We do not use advertising or cross-site tracking cookies.
10. Your rights
Under UK data protection law you have the right to access your personal data, to have inaccurate data corrected, to have data erased, to restrict or object to processing, to data portability, and to withdraw consent where we rely on it. To exercise any of these, email info@cyberrock.ai. We will respond within one month.
Where the personal data sits inside content you submitted for scanning, you should approach whoever controls that content; we hold it only transiently as a processor, and in most cases no longer hold it at all.
11. Complaints
If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority, at ico.org.uk.
12. Changes
We may update this policy. Material changes will be notified by email to your account address before they take effect. The version and date at the foot of this page identify this edition.
13. Contact
By email: info@cyberrock.ai
By post: CYBERROCK LTD, 128 City Road, London EC1V 2NX, United Kingdom
See also our terms of service.
Document version 1.0.1 · published 14 August 2026
