Security Practices
Last updated: June 16, 2026
MyCyberScan takes the privacy and security of submitted information seriously. This Security Practices page explains the practical steps we use to receive, handle, protect, use, deliver, and delete information submitted through MyCyberScan.
This page should be read together with our Terms of Use, Privacy Policy, Cookie Policy, and Refund Policy.
Security practices at a glance
| Area | Our ordinary practice |
|---|---|
| Scan submissions | Collected through our website intake form and related email systems |
| Report delivery | Sent to the email address used at checkout, usually as a PDF attachment |
| Payment card details | Handled by third-party payment processors, not intentionally collected or stored by MyCyberScan |
| Submitted scan information | Temporarily used to complete the requested scan |
| Deletion target | We aim to delete submitted scan information from active systems within 24 hours after report delivery |
| Report retention | We do not ordinarily keep a copy of the final report after delivery |
| Security guarantee | No online service, email system, payment platform, or storage method can be guaranteed completely secure |
Important: MyCyberScan uses practical security measures, but no internet-based service can guarantee complete security. Users are responsible for keeping their own email accounts, devices, passwords, and delivered reports secure.
1. About MyCyberScan
MyCyberScan provides cyber scan reports designed to help individuals, professionals, families, and authorised third parties identify potential online exposure risks. These may include exposed personal information, impersonation accounts, deepfakes, explicit content, and identity-related reputation risks.
For the purposes of this Security Practices page, “MyCyberScan,” “we,” “us,” and “our” refer to MyCyberScan.
2. Information submitted for a scan
To perform a scan, users may submit the following information through our intake process:
- name;
- country;
- city or town;
- state or region;
- optional email address for scan-identification purposes; and
- optional selfie image.
Selfie image uploads may be accepted in supported image formats, including .jpg, .jpeg, .png, .heic, and .heif.
We do not intentionally request social media handles, phone numbers, links, usernames, unrelated notes, identity documents, payment card numbers, passwords, or unrelated files through the standard scan intake form.
Users must not submit unnecessary, excessive, unlawful, misleading, harmful, exploitative, or unauthorised information.
3. How scan submissions are received
Scan submissions are received through our website intake form and through official email systems connected to that form.
Our official contact email is:
At the time this page was last updated, this is the official email address used by MyCyberScan for user communications. Users should not send scan information, payment information, identity information, personal information, or security-related enquiries to any email address claiming to represent MyCyberScan unless that email address is clearly published by us as an official contact channel.
4. Website and transmission security
Our website uses HTTPS/SSL to help protect information transmitted through the website.
We also use practical website security measures, which may include:
- access controls;
- login protection;
- security monitoring;
- malware scanning;
- software, plugin, and theme updates;
- hosting-level security tools;
- form security measures;
- spam and abuse-prevention measures; and
- other technical or operational safeguards we consider appropriate.
These measures are designed to reduce security risk. They do not eliminate all risk.
No website, form, hosting environment, email system, payment system, internet transmission, storage method, device, or third-party platform can be guaranteed completely secure, private, uninterrupted, or free from unauthorised access.
5. Email and report delivery security
Final scan reports are usually delivered by email as PDF attachments.
The final scan report is sent to the email address used at checkout. If an express checkout method is used, the report may be delivered to the email address associated with that express checkout method.
Users are responsible for ensuring that the email address used at checkout is:
- accurate;
- accessible;
- authorised for their use;
- secure; and
- able to receive the report.
MyCyberScan is not responsible for delays, failed delivery, misdirected delivery, unauthorised access, or other issues caused by an incorrect, inaccessible, compromised, unauthorised, or insecure email address provided or used by the user, except to the extent responsibility cannot be excluded by law.
Email security depends on multiple systems, including the sender’s email provider, the recipient’s email provider, internet routing, device security, account security, and user behaviour. We do not guarantee that email transmission will be completely secure, private, uninterrupted, error-free, or free from interception, delay, filtering, misdirection, or unauthorised access.
6. Report security after delivery
Once a report has been sent, the user is responsible for storing, securing, sharing, deleting, or backing up the report.
Users should take reasonable steps to protect their report, including:
- using a secure email account;
- using strong passwords and multi-factor authentication where available;
- avoiding shared or public devices when accessing the report;
- not forwarding the report to unauthorised people;
- not uploading the report to insecure platforms; and
- securely deleting the report when it is no longer needed.
Reports are not password-protected by default. Password protection may be available upon request, but it may not be available in all circumstances and does not guarantee complete security.
Users must not publish, sell, alter, manipulate, misrepresent, redistribute, or use a report in a way that is unlawful, misleading, harmful, unauthorised, exploitative, or inconsistent with our Terms of Use.
7. Temporary storage of submissions
User submissions may be temporarily stored in our website form system, website hosting environment, official email system, and internal working systems so that we can process the scan request and prepare the final report.
This temporary storage is necessary for us to perform the service requested by the user.
We do not intentionally retain scan submissions longer than needed for the ordinary operation of the service, unless retention is reasonably necessary for security, safety, legal, dispute, fraud-prevention, abuse-prevention, operational, accounting, regulatory, or law-enforcement reasons.
8. Access controls
Access to scan submissions is limited to authorised MyCyberScan personnel who need access to perform the service, manage the website, respond to enquiries, address security issues, investigate suspected misuse, or comply with legal, safety, or operational requirements.
We use internal access controls and account security practices designed to reduce unauthorised access to submitted information.
Users must not attempt to access, interfere with, bypass, test, scrape, overload, reverse engineer, disrupt, damage, or misuse any MyCyberScan website, form, system, email address, payment process, report, account, security measure, or related technology.
9. Deletion after scan completion
After the final scan report has been sent, MyCyberScan aims to delete submitted scan information from active systems within 24 hours.
This may include deleting, where applicable:
- the website form entry;
- the email submission;
- uploaded selfie images;
- active working copies; and
- temporary materials used to prepare the report.
Once deleted from active systems, submitted scan information and final reports are generally not recoverable by MyCyberScan.
Users are responsible for saving, securing, and backing up their own report after delivery.
10. Final report retention
MyCyberScan does not ordinarily keep a copy of the final scan report after delivery as part of its standard process.
The user usually receives the final scan report by email as a PDF. Unless otherwise stated, required, or reasonably necessary, the user receives the only retained copy of the final report.
We do not ordinarily keep internal scan notes after completion, except where retention is reasonably necessary for legal, safety, security, dispute, fraud-prevention, abuse-prevention, chargeback, operational, or law-enforcement reasons.
11. Limits of deletion
Although MyCyberScan aims to delete submitted scan information from active systems within 24 hours after report delivery, deletion may be subject to technical, legal, security, operational, backup, or third-party limitations.
For example, some information may temporarily or lawfully remain in:
- system logs;
- email routing records;
- website security logs;
- payment records;
- transaction metadata;
- hosting or infrastructure systems;
- backup systems;
- fraud-prevention systems;
- accounting or tax records;
- legal, dispute, or chargeback records;
- third-party provider systems; or
- records required for safety, security, legal, regulatory, or law-enforcement purposes.
We do not intentionally use these records to continue processing completed scan submissions, except where reasonably necessary for security, safety, legal, dispute-resolution, fraud-prevention, abuse-prevention, operational, regulatory, or law-enforcement purposes.
12. Payments and card information
Payments are processed through third-party payment systems.
MyCyberScan does not intentionally collect, view, store, or process full payment card numbers. Payment information is handled by the relevant payment processor according to its own systems, terms, policies, security practices, and legal obligations.
MyCyberScan is not responsible for the security practices, outages, errors, processing delays, payment failures, account actions, payment reversals, chargebacks, fraud controls, or data handling practices of third-party payment providers, except to the extent responsibility cannot be excluded by law.
Refunds, payment disputes, chargebacks, and payment-related issues are handled in accordance with our Refund Policy, our Terms of Use, and any applicable payment provider requirements.
13. Third-party service providers
MyCyberScan may rely on third-party service providers to operate the website, receive form submissions, process payments, host website infrastructure, provide email services, maintain security tools, deliver reports, and support the operation of the service.
Although we take practical steps to use suitable providers and limit unnecessary handling of submitted information, third-party systems are not fully controlled by MyCyberScan.
Third-party providers may process, store, transmit, log, retain, secure, or delete information according to their own terms, policies, systems, retention practices, security standards, and legal obligations.
MyCyberScan is not responsible for third-party systems, outages, delays, errors, unauthorised access, data handling practices, account restrictions, service interruptions, or security incidents outside our reasonable control, except to the extent responsibility cannot be excluded by law.
14. Technical data, logs, and security records
When users visit or interact with our website, certain technical information may be processed by our website, hosting provider, security tools, payment systems, analytics tools, email systems, or other service providers.
This may include information such as:
- IP address;
- browser type;
- device information;
- timestamps;
- referral information;
- form submission metadata;
- checkout metadata;
- security logs;
- spam-detection signals;
- error logs; and
- cookie or similar technology data.
This information may be used to operate the website, protect the service, prevent fraud and abuse, troubleshoot issues, process transactions, maintain security, and comply with legal or operational requirements.
For more information about personal information handling, see our Privacy Policy. For more information about cookies and similar technologies, see our Cookie Policy.
15. User responsibilities
Users are responsible for:
- submitting accurate information;
- ensuring they have authority to submit information about themselves or another person;
- ensuring the checkout email address is correct, authorised, accessible, and secure;
- securing their own email accounts, devices, passwords, and inboxes;
- not submitting information they are not authorised to provide;
- not submitting false, misleading, harmful, unlawful, abusive, exploitative, or unnecessary information;
- not forwarding reports to unauthorised third parties;
- not using reports for harassment, stalking, discrimination, intimidation, blackmail, exploitation, doxxing, fraud, impersonation, or unlawful activity;
- not modifying, misrepresenting, reselling, publishing, or redistributing reports without permission; and
- understanding that no online service can guarantee complete security.
A user’s failure to follow these responsibilities may result in refusal of service, suspension of processing, deletion of submissions, non-delivery of a report, account or order restrictions, or other action we consider appropriate, subject to applicable law.
16. Third-party scans and consent
Users may only submit information about another person if they have lawful authority and appropriate consent to do so.
This includes, where applicable, scans requested by employers, recruiters, HR teams, businesses, family members, parents, guardians, or other third parties.
By using MyCyberScan, the user represents that they are authorised to submit the information provided and to request the scan.
MyCyberScan may request further information, refuse a scan, delete a submission, suspend processing, decline service, or take other appropriate action where we reasonably suspect that consent, authority, legality, safety, or good-faith use is unclear.
Further requirements relating to authorized use are set out in our Terms of Use.
17. Minors
MyCyberScan may process scan requests relating to a person under 18 only where the request is made or authorized by a parent or legal guardian, or where the minor has permission from a parent or legal guardian.
We may refuse, delete, suspend, restrict, or report any submission involving a minor where we reasonably suspect abuse, exploitation, harassment, unauthorised surveillance, grooming, coercion, fraud, illegal conduct, unsafe conduct, or any other harmful purpose.
We do not knowingly assist with unsafe, exploitative, unlawful, or unauthorised scans involving minors.
18. Suspicious, harmful, or unlawful submissions
MyCyberScan may refuse, suspend, delete, restrict, or decline any submission, order, report, enquiry, or user communication where we reasonably believe it may involve:
- unlawful activity;
- harassment;
- stalking;
- threats;
- exploitation;
- abuse;
- doxxing;
- impersonation;
- fraud;
- identity misuse;
- blackmail;
- coercion;
- unauthorised scanning;
- misuse of another person’s information;
- harm to a person, group, business, or community;
- attempted misuse of MyCyberScan;
- breach of our Terms of Use; or
- conduct we consider unsafe, suspicious, abusive, or inconsistent with the purpose of our service.
We are not required to provide a report, explanation, refund, response, or continued service where a user has misused or attempted to misuse MyCyberScan, except where required by law.
19. Preservation and reporting for safety or legal reasons
Although MyCyberScan’s ordinary practice is to delete submitted scan information after completion, we may preserve, retain, disclose, or report information where we reasonably believe it is necessary to:
- prevent harm;
- protect a person’s safety;
- investigate suspected misuse;
- respond to fraud, abuse, threats, exploitation, or unlawful conduct;
- comply with legal obligations;
- respond to a regulator, court, tribunal, payment provider, platform, or law-enforcement authority;
- enforce our Terms of Use;
- resolve a dispute, complaint, refund request, or chargeback;
- protect MyCyberScan’s rights, property, users, staff, systems, reputation, or legal interests; or
- notify a potential victim, affected person, platform, regulator, payment provider, or law-enforcement authority.
20. Data incidents
If MyCyberScan becomes aware of a security incident involving submitted information, we will assess the incident and take steps we consider appropriate in the circumstances.
Depending on the nature of the incident, this may include:
- investigating what happened;
- taking steps to contain or reduce risk;
- working with relevant service providers;
- securing affected systems where possible;
- reviewing whether submitted information was involved;
- notifying affected individuals where appropriate or legally required;
- notifying regulators, law-enforcement authorities, payment providers, or other relevant parties where appropriate or legally required; and
- taking reasonable remedial steps.
Not every technical issue, attempted attack, spam submission, blocked login attempt, provider outage, or security alert will require user notification.
Where notification is legally required, we will take steps that we consider appropriate having regard to the circumstances and applicable law.
21. No guarantee of complete security
MyCyberScan takes practical and reasonable steps to protect submitted information, but we do not guarantee that our website, email systems, forms, reports, payment systems, third-party services, hosting providers, devices, internet transmissions, or related technology will always be secure, uninterrupted, error-free, private, available, or immune from unauthorised access.
To the maximum extent permitted by law, MyCyberScan is not liable for loss, damage, misuse, unauthorised access, disclosure, delay, failed delivery, misdirected delivery, technical error, third-party failure, provider outage, user error, account compromise, or security incident arising from circumstances outside our reasonable control.
Nothing in this Security Practices page is intended to exclude, restrict, or modify any right, guarantee, remedy, or protection that cannot lawfully be excluded, restricted, or modified.
22. Changes to these Security Practices
We may update this Security Practices page from time to time to reflect changes to our services, website, systems, providers, legal obligations, operational practices, or security practices.
The updated version will be published on our website with a revised “Last updated” date.
Users should review this page periodically to stay informed about our current security practices.
23. Contact about security practices
Users may contact MyCyberScan with questions about this Security Practices page or our handling of submitted information.
You can contact us anytime through our contact page.
Where email contact is necessary, our official contact email is:
Related legal pages
For the full legal framework that applies to MyCyberScan, please review: