Legal

Privacy Policy

Last updated: August 22, 2026 · Effective: August 22, 2026
ID/EN

This Privacy Policy explains how CyberAgent.id ("we", "us") collects, uses, stores, and protects your personal information when you use our platform at cyberagent.id. We are committed to protecting your privacy in accordance with the Indonesian Personal Data Protection Law (UU No. 27/2022) and related regulations in Indonesia.

1. Data We Collect

CategoryType of DataPurpose
Account DataName, email, password (hashed), profile photo (if OAuth), business typeCreating and managing accounts, authentication, OAuth authentication
Audit DataTarget URL/domain, scan results, vulnerability findings, PoCs, security scoreProviding audit services, generating reports, verifying domain ownership
Transaction DataCredit history, purchased packages, payment referencesManaging credit balance, processing payments
Technical DataIP address, user-agent, activity logs, usage dataSecurity, abuse prevention, service improvement
Webhook DataWebhook URL, bot token, chat ID (Slack/Discord/Telegram)Delivering audit result notifications to your channel

2. Data We Do NOT Collect

We do not store: passwords in plaintext form (only cryptographic hashes), your Target's database credentials, the contents of sensitive data from audited websites, private keys, or wallet mnemonics/seeds.

3. How We Use Data

4. Legal Basis for Processing

We process your personal data on the basis of: (a) your consent at the time of registration; (b) performance of the Service contract; (c) our legitimate interests in providing and securing the Service; and (d) legal obligations.

5. Data Storage & Security

6. Retention Period

7. Sharing Data with Third Parties

We do not sell your personal data. We share data with third parties only in the following situations:

PartyPurpose
LLM providers (AI models)Running audit analysis — only the target data you submit
Cloudflare (Turnstile)Anti-bot verification on login/register forms
Google / GitHubOAuth authentication (subject to their respective policies)
Payment providers (Midtrans, etc.)Transaction processing (when enabled)
Competent authoritiesWhere required by law

8. Cookies & Similar Technologies

We use cookies and local storage (localStorage) to: manage authentication sessions, store language preferences, and serve the functional needs of site preferences. You may delete cookies through your browser settings; however, some features may not function without cookies.

9. Your Rights

In accordance with Indonesia's Personal Data Protection Law, you have the right to:

To exercise your rights, contact us via the email address below. We will respond within 30 days.

10. Children's Security

Our Service is not intended for children under 13 years of age (or the age of majority under your jurisdiction). We do not knowingly collect data from children. If you believe we have collected a child's data, contact us for immediate deletion.

11. International Data Transfers

Your data may be processed on servers located inside and outside Indonesia. By using the Service, you consent to such transfers in accordance with this privacy policy and applicable regulations.

12. Changes to the Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be notified via email or an in-platform notice. Your use of the Service after a change takes effect constitutes your acceptance of it.

13. Contact

For questions, data access requests, or privacy complaints, contact: