Privacy

Privacy Policy

Last updated September 27, 2026. This policy covers the CyberArmor AI website and every product surface we ship: the endpoint agents, the browser extensions, the iOS and Android apps, and the control plane they report to.

The short version

  • CyberArmor is security software bought by organisations and installed on the devices they manage. In almost every case your employer decides what is collected, and we process it on their instructions.
  • We do not sell personal information, and we do not use anything collected by the product for advertising, profiling, or any purpose other than delivering the security service.
  • The Android app uses a VPN connection. It is used only to filter DNS lookups against your organisation’s policy. It does not route, read, or record your other network traffic.
  • We tell you what each surface can and cannot see, including where the platform prevents us from seeing anything at all.

Who controls your data

This distinction matters more than anything else on the page, and it changes who you ask about your data.

When we are the controller

For the public website, sales enquiries, and support correspondence, CyberArmor AI decides how the data is used. Contact us directly to access, correct, or delete it.

When we are a processor

For everything the product collects on a managed device, the organisation that deployed CyberArmor is the controller. They choose the policies, decide what evidence is captured, and control retention. We act on their documented instructions under a data processing agreement. If you are an employee asking what is collected on your work device, your employer holds that answer — but this page tells you what the software is technically capable of collecting, which is the part they cannot change.

When you subscribe as an individual or family

If you subscribe to CyberArmor yourself, as an individual or for your family, no organisation stands between us: CyberArmor AI is the controller for the product data your enrolled devices and browsers send. It goes to the CyberArmor-hosted service, and we use it only to provide the protection you subscribed to: checking links, catching sensitive data before it reaches an AI service, and showing you what was blocked, redacted or warned about. We do not sell it, use it for advertising, or build profiles from it. Each surface collects exactly what the table below describes; nothing more is collected because the subscriber is a person rather than a company. Contact us directly to access, export or delete it, and cancelling your subscription ends collection.

On a family subscription, the account holder chooses which devices to enroll and can see the protection events from them. If you enroll a device that someone else uses, tell them, as you would with any monitoring software.

Customers may also self-host CyberArmor entirely on their own infrastructure, including fully air-gapped. In those deployments no product data reaches us at all.

What each surface collects

Capability differs by platform, and we state the difference rather than describing the most capable surface and letting you assume the rest match it.

SurfaceWhat it collectsWhy
Website (cyberarmor.ai)Contact details you submit — name, business email, company, role — and standard server logs.Responding to your enquiry, and operating and securing the site. We are the controller for this data.
Android app — DNS filter (VpnService)Domain names looked up on the device while protection is on. Only two categories are recorded or transmitted: lookups the policy blocked, and lookups to known AI services. Aggregate counters (packets, queries, answers, blocks) are also reported.Enforcing your organisation's AI-use policy on the device and giving its administrators evidence that the control ran. Your employer is the controller; if you subscribed as an individual or family, we are.
iOS appThe same domain-level signals, plus — only where the organisation has installed a trusted certificate and told users so — the URLs and request content the on-device proxy is configured to evaluate.Same as above, at the granularity the platform permits.
Browser extensions (Chrome, Edge, Firefox, Safari)Three things, all sent to your organisation's own CyberArmor deployment: the address of each page you navigate to, so it can be checked for phishing and hidden instructions before it loads; a record of each enforcement decision (a warning, a redaction, a block, an upload attempt), with the AI service and the category of what was found; and, where your organisation's policy requires it, files you upload to AI services, so they can be scanned. Text you type or paste into AI services is evaluated inside the browser and is never transmitted; a redaction sends the category and the text lengths, not the text.Checking links before you land on them, keeping sensitive data out of AI assistants, governing uploads to them, and recording that the control ran. Your employer is the controller; if you subscribed as an individual or family, we are.
Endpoint agents (macOS, Windows, Linux)Policy decisions, detections, file and process metadata for security events, and device inventory. Content is captured only where the administrator has explicitly enabled it.Endpoint protection and the audit record your organisation is required to keep.

The Android VPN connection, specifically

The CyberArmor Android app establishes a VPN connection using Android’s VpnService API. Android shows a key icon in the status bar whenever it is active. Here is exactly what it does.

What the VPN is for

It is core functionality, not an add-on: it is the only mechanism Android provides for an app to see and answer DNS lookups made by other apps. We use it to enforce your organisation’s policy about which AI services this device may reach.

What is actually routed through it

Only DNS. The tunnel is configured with routes for two addresses — the DNS resolvers it provides — and nothing else. Your web browsing, app traffic, messages, video, and everything else travel their normal path and never enter the tunnel. We could not read them if they did: Android has prevented apps from trusting externally installed certificates since Android 7, in every management mode, so no VPN app can see inside another app’s encrypted traffic.

What leaves the device

Two categories of domain name: lookups your organisation’s policy blocked, and lookups to recognised AI services. Plus aggregate counters that let an administrator tell a working filter from a broken one. Domain lookups outside those categories are evaluated in memory and are neither stored nor transmitted.

Which resolver answers your lookups

The app forwards allowed lookups to the DNS resolvers your current network provides. If the network does not provide any, it falls back to a public resolver and says so on the main screen, naming the resolver in use, because moving a device’s DNS to a third party is not a decision software should make silently.

Affirmative commitments

  • The VPN is not used to collect data unrelated to the app’s security function.
  • The VPN is not used for advertising, analytics, tracking, or profiling.
  • We do not sell, rent, or share VPN-derived data with data brokers.
  • We do not inject, modify, or proxy web content through it.
  • Turning protection off in the app ends the VPN connection immediately.

The browser extensions, specifically

CyberArmor Protect for Chrome, Edge, Firefox and Safari is installed by, or at the direction of, your organisation, and does nothing until it is enrolled against that organisation’s CyberArmor deployment with a one-time token from your administrator. Here is exactly what it sends, what it keeps to itself, and where it goes.

What leaves the browser

  • Page addresses. The address of each page you navigate to is sent to your organisation’s URL Trust Gate before the page loads, so phishing, credential-harvesting and hidden instructions aimed at AI assistants can be blocked first. The gate fetches the page itself; the extension does not send page content.
  • Enforcement events. Each warning, redaction, block or blocked upload is recorded with the page or AI service involved and the category of what was found (for example “national ID”), together with the enrollment identity your organisation issued to this browser.
  • Uploaded files, when policy says so. A file you upload to an AI service may be sent to your organisation’s detection service to be scanned for sensitive content before it leaves, and blocked if policy requires it.

What stays in the browser

  • What you type or paste into an AI service. Detection and redaction run locally; a redaction reports the category and the before-and-after lengths, never the text.
  • Your clipboard. It is inspected only on a paste into a monitored AI service, locally, and its contents are never transmitted.
  • The content of the pages you read. The extension does not send page text anywhere.

Where it goes

Only to the CyberArmor deployment the extension was enrolled against: infrastructure your organisation runs itself, the CyberArmor-hosted service your organisation has contracted for, or, if you subscribed as an individual or family, the CyberArmor-hosted service. In the first case CyberArmor never receives the data at all. Nothing is sent to any other party, and nothing is sent before enrollment.

Affirmative commitments

  • The extension does not send the text of pages, and does not send the text of prompts unless the “Log AI Prompts” option is switched on. It is off by default; when on, up to 500 characters of each prompt are sent, with detected personal data redacted first when automatic redaction is on.
  • It is not used for advertising, analytics, tracking or profiling.
  • It loads no code from the network; policy it fetches is data, never executed.
  • Its reviewer demo mode connects to nothing and transmits nothing.
  • Uninstalling it removes the enrollment credential and everything it stored.

What we never do

  • We do not sell personal information, and we never have.
  • We do not use customer or end-user data to train models offered to other customers.
  • We do not read the contents of messages, prompts, documents, or files on Android. The platform makes it impossible and we do not claim otherwise.
  • We do not collect location, contacts, photos, microphone, or camera data on any mobile surface.
  • We do not show advertising, and we embed no advertising or third-party analytics SDKs in the mobile apps.
  • We do not use a device identifier that survives uninstalling the app. The Android app’s identifier is generated at install and is regenerated if you reinstall.

Enterprise deployment and employee notice

CyberArmor includes data-loss-prevention features. Where an administrator enables content evidence — for example, capturing the text that triggered a policy — that content may include personal information the user typed. This is a deliberate administrative choice with a real privacy cost, so the product treats it as one.

  • Content capture is off by default and must be turned on explicitly.
  • Administrative changes to policy are recorded in an audit log, including who made them.
  • We require, by contract, that deploying organisations give their users legally adequate notice. In many jurisdictions monitoring employees without notice is unlawful, and we are not able to provide that notice on your employer’s behalf.
  • The apps state their own scope on screen, so a user can see what the software on their device is capable of without needing to ask.

How we share information

We do not sell personal information. We share it only with infrastructure and service providers that operate the platform — hosting, email delivery, and error reporting — under contracts limiting them to that purpose; with your own organisation, when the data came from a device it manages; and where we are legally compelled, in which case we will tell the affected customer unless we are prohibited from doing so. A current list of subprocessors is available to customers on request.

Retention

Website enquiries are kept while the conversation is active and for a reasonable period afterwards. Product data is retained according to the deploying organisation’s configured retention, since it is their record; when a customer’s agreement ends, their data is deleted or returned on request. For individual and family subscriptions we hold the data while the subscription is active, and delete it on request or when the subscription ends. Self-hosted and air-gapped deployments retain data entirely under the customer’s control.

Security

Data is encrypted in transit. Devices authenticate to the control plane with per-device credentials issued at enrolment, and the apps refuse to send credentials over an unencrypted connection. Access to customer environments is restricted and logged. No system is perfectly secure, and we will not tell you otherwise; our commitment is to disclose material incidents promptly to affected customers.

Your rights

Depending on where you live, you may have rights to access, correct, delete, or port your personal information, to object to or restrict processing, and to lodge a complaint with a supervisory authority. For data we control, contact us and we will respond within the period the applicable law requires. For data collected on a device your employer manages, direct the request to your employer; if you send it to us, we will forward it and tell you we have.

We do not sell or share personal information as those terms are defined under California law, and we do not process it for cross-context behavioural advertising.

International transfers

Our managed infrastructure may process data outside your country. Where required, we rely on appropriate safeguards such as the European Commission’s standard contractual clauses. Customers with data residency requirements can self-host, which keeps all product data within their own infrastructure.

Children

CyberArmor is not directed to children. A family subscription is held by an adult, who decides which devices to enroll; we do not knowingly open an account for anyone under 16, and we do not collect more from a device because a child uses it. If you believe a child’s information reached us outside a family subscription an adult set up, contact us and we will delete it.

Changes to this policy

We will update the date at the top when this policy changes. If a change materially expands what a product surface collects, we will notify customers before it takes effect — and the app-store listings and in-app disclosures will change at the same time, not afterwards.

Contact

Privacy questions, data requests, and security disclosures: privacy@cyberarmor.ai. For security vulnerabilities, see our security page. Our terms of service govern use of the platform.