Loading


Privacy Policy

Last updated: 16 June 2026

This Privacy Policy explains how MyCyberScan (“MyCyberScan”, “we”, “us”, or “our”) collects, uses, stores, protects, discloses, and deletes personal information in connection with our website, scan request forms, checkout process, communications, reports, and related services.

MyCyberScan is based in New South Wales, Australia. This Privacy Policy should be read together with our Terms of Use, Cookie Policy, Refund Policy, and Security Practices.

By accessing our website, submitting information, purchasing a scan, requesting a report, communicating with us, or otherwise using our services, you acknowledge that you have read and understood this Privacy Policy.

Privacy at a Glance

TopicSummary
What we collectInformation needed to process scan requests, deliver reports, communicate with users, process payments, maintain security, and operate our website.
Optional selfie uploadsSelfies are optional. If submitted, they may be used for reverse image searching, visual comparison, impersonation checks, and deepfake-related checks.
ReportsReports are normally delivered by email as PDF attachments. Reports are informational only and may include findings from third-party sources.
DeletionWe aim to delete scan submission data and final working files from active systems within 24 hours or less after report delivery, unless a valid exception applies.
Third-party toolsWe may use payment processors, hosting providers, WordPress tools, security tools, search tools, image tools, breach tools, AI tools, and other relevant services.
We do not sell scan dataWe do not sell scan submission data or report contents to advertisers.
ContactPrivacy questions can be sent through our contact page or to official@mycyberscan.com.

1. About MyCyberScan

MyCyberScan provides online scan and reporting services designed to help individuals, professionals, families, businesses, and authorised third parties identify potential online exposure risks.

These risks may include:

  • exposed personal information;
  • impersonation accounts;
  • catfish or fake-profile risks;
  • deepfake-related risks;
  • explicit-content exposure;
  • breach-related or leak-related exposure;
  • public online records;
  • harmful old or recent posts;
  • identity-related, employment-related, or reputation-related risks.

Our reports are provided for informational and awareness purposes only. MyCyberScan does not:

  • guarantee that every online risk will be found;
  • guarantee that any finding is complete, current, permanent, or accurate;
  • remove content unless a separate service expressly states otherwise;
  • guarantee content removal;
  • provide legal advice;
  • make employment, hiring, credit, insurance, suitability, security-clearance, or official background-check decisions;
  • act as a law-enforcement, regulatory, investigative, or court authority.

2. Information We Collect

We collect only the information reasonably needed to process scan requests, deliver reports, communicate with users, process payments, maintain security, prevent misuse, comply with legal obligations, and operate our website.

Depending on how you use MyCyberScan, we may collect the following categories of information.

3. Scan Request Information

When a scan request is submitted, we may collect:

  • name;
  • country;
  • city or town;
  • state or region;
  • optional email address submitted in the scan form;
  • optional selfie image;
  • any additional information you voluntarily provide through our forms or communications.

The email address used for report delivery is generally the email address provided during checkout, including where express checkout or third-party checkout services are used.

As part of our standard scan form, we do not intentionally request:

  • phone numbers;
  • dates of birth;
  • usernames;
  • social media handles;
  • aliases;
  • previous names;
  • profile links.

You should not submit unnecessary sensitive information unless it is specifically requested and relevant to the service.

4. Optional Selfie Images

Uploading a selfie image is optional. You can request a scan without submitting a selfie.

If you choose to upload a selfie, it may be used to support:

  • reverse image searching;
  • visual comparison;
  • face-matching support;
  • impersonation detection;
  • catfish or fake-profile checks;
  • deepfake-related checks;
  • visual verification of potentially related online material.

A selfie may be manually reviewed by the MyCyberScan team. Where reasonably necessary to perform the requested scan, a selfie may also be submitted to third-party tools, platforms, search engines, image search services, face-matching services, AI tools, or similar services.

Important selfie notice:
Do not upload a selfie unless you are comfortable with MyCyberScan and relevant third-party tools processing the image for scan-related purposes. Third-party tools may process images under their own systems, terms, privacy policies, security practices, retention periods, and jurisdictional rules.

MyCyberScan does not intentionally create or retain facial templates, faceprints, biometric databases, stored facial embeddings, or biometric identifiers. However, third-party tools used during the scan process may process images using their own technologies and practices.

Selfie images are not included in the final report unless we expressly state otherwise and obtain appropriate consent.

5. Checkout and Payment Information

Payments are processed by third-party payment providers, including Stripe or other checkout providers that may be used on our website.

MyCyberScan does not receive or store full payment card numbers.

Payment providers may collect and process information such as:

  • billing details;
  • payment method details;
  • card information;
  • transaction records;
  • fraud-prevention data;
  • chargeback and dispute information;
  • payment verification information;
  • other information required to process payments.

Payment providers handle payment data under their own terms, privacy policies, security standards, and legal obligations.

We may retain receipts, transaction confirmations, limited payment records, refund records, chargeback records, accounting records, or tax records where necessary for accounting, tax, fraud-prevention, dispute-handling, compliance, legal, or operational purposes.

For payment and refund terms, please see our Refund Policy.

6. Communications

If you contact us by email, through our contact form, or through any official MyCyberScan communication channel, we may collect:

  • your name;
  • your email address;
  • message contents;
  • attachments;
  • metadata;
  • any information you choose to provide.

Our official contact email is official@mycyberscan.com.

You should avoid sending unnecessary sensitive information by email.

You can also contact us anytime through our website.

7. Technical and Website Information

MyCyberScan does not intentionally ask users to provide IP addresses, device details, or browser data in the scan request form.

However, our website, hosting provider, payment processors, WordPress functionality, form tools, anti-spam tools, security tools, server logs, cookies, and similar technologies may automatically process technical information such as:

  • IP address;
  • browser type;
  • device information;
  • operating system;
  • cookie identifiers;
  • session information;
  • timestamps;
  • referral information;
  • checkout or payment session data;
  • security logs;
  • error logs;
  • spam-prevention data.

We may use this information where necessary to operate the website, process forms, secure the website, prevent abuse, process payments, troubleshoot errors, maintain website functionality, and comply with legal obligations.

For more information, see our Cookie Policy.

8. Sensitive Information

Our services may involve sensitive or potentially sensitive information, including:

  • selfie images;
  • identity-related information;
  • explicit-content exposure;
  • deepfake-related findings;
  • breach-related or leak-related exposure;
  • impersonation risks;
  • public-record findings;
  • reputationally sensitive material;
  • information involving minors;
  • safety-related or harm-related information.

By submitting a scan request, you consent to MyCyberScan processing the submitted information and relevant scan findings for the purpose of performing the requested scan, preparing the report, delivering the report, handling support requests, maintaining security, preventing misuse, and complying with legal obligations.

If you submit information about another person, you must have that person’s consent, lawful authority, or another valid legal basis to do so.

9. Information About Other People

You may submit information about another person only where you have consent, lawful authority, or another valid legal basis to do so.

By submitting information about another person, you represent and warrant that:

  • you have permission, lawful authority, or another valid legal basis to submit that information;
  • the submission is not for stalking, harassment, doxxing, blackmail, extortion, revenge, abuse, unlawful surveillance, discrimination, exploitation, intimidation, or any unlawful or harmful purpose;
  • where the scan relates to employment, recruitment, HR, applicant screening, professional review, due diligence, or a similar process, the relevant person has been properly informed and has agreed to the applicable policy, consent process, authorisation, or lawful basis allowing the scan;
  • the information you provide is accurate to the best of your knowledge;
  • you will not misuse the report or any findings.

We may request evidence of consent, authority, identity, or legal basis where we reasonably believe it is necessary.

We may refuse, suspend, cancel, delete, preserve, or report a submission where we reasonably believe it is unlawful, harmful, abusive, misleading, unauthorised, fraudulent, unsafe, or inconsistent with this Privacy Policy or our Terms of Use.

10. Minors

MyCyberScan does not knowingly collect personal information directly from children under 18 without appropriate involvement from a parent or legal guardian.

Parents or legal guardians may request scans involving minors where they have lawful authority to do so. We may request proof of identity, parental responsibility, guardianship, or authority where reasonably necessary.

If we become aware that information has been submitted by or about a minor without appropriate authority, we may delete the submission, refuse the service, request further verification, or take any other action we reasonably consider necessary.

Where we reasonably believe information involving a minor indicates child exploitation, abuse, threats, blackmail, serious harm, illegal activity, or immediate safety risk, we may preserve and disclose relevant information to law enforcement, regulators, child protection bodies, payment providers, hosting providers, or other appropriate authorities where required or permitted by law. We may do this without notifying the user where notification would be unlawful, unsafe, inappropriate, or likely to prejudice an investigation or safety response.

11. How We Collect Information

We may collect information when:

  • you submit a scan request form;
  • you upload an optional selfie image;
  • you complete checkout or payment;
  • you contact us by email or through our contact form;
  • you communicate with us about a report, privacy request, refund request, complaint, or support matter;
  • you use our website;
  • our website, hosting provider, payment processor, plugins, security tools, or related systems automatically process technical information;
  • third-party tools or sources return scan-related information from public, semi-public, indexed, search-based, or third-party sources.

12. How We Use Information

We may use personal information for the following purposes:

  • to process scan requests;
  • to verify submitted details;
  • to conduct manual and automated searches;
  • to use third-party tools, search engines, databases, breach tools, image search services, face-matching tools, AI tools, public records, social platforms, and other relevant sources;
  • to identify possible exposed personal information, impersonation risks, deepfake risks, explicit-content exposure, breach exposure, reputation risks, and related online findings;
  • to prepare and deliver PDF reports;
  • to communicate with users;
  • to respond to privacy requests, correction requests, deletion requests, complaints, refund requests, and support enquiries;
  • to process payments, refunds, disputes, chargebacks, accounting records, and tax records;
  • to prevent misuse, fraud, abuse, unauthorised scanning, unlawful conduct, or safety risks;
  • to protect the rights, safety, security, reputation, and operations of MyCyberScan, users, scan subjects, third parties, and the public;
  • to comply with legal obligations, lawful requests, court orders, subpoenas, warrants, regulators, law enforcement, or government authorities;
  • to improve our services using anonymised, aggregated, or de-identified information where reasonably possible;
  • to send service-related, transactional, support, policy-related, or marketing communications where permitted by law.

13. Scan Reports

Reports are normally delivered as a PDF attachment by email to the email address used at checkout.

Reports may include:

  • findings;
  • summaries;
  • comments;
  • risk indicators;
  • links to third-party pages;
  • screenshots or references where appropriate;
  • classifications such as confirmed, possible, unconfirmed, likely, or similar wording.

Although we aim to assess findings carefully, scan results may be uncertain, incomplete, outdated, incorrectly attributed, inaccessible, removed, changed, duplicated, misindexed, or dependent on third-party sources.

MyCyberScan does not guarantee that all information in a report is complete, current, accurate, permanent, accessible, correctly attributed, or exhaustive.

Important report notice:
We do not generally retain a copy of the final report after delivery. You are responsible for securely storing, deleting, forwarding, or managing copies of reports in your own email inbox, devices, systems, accounts, downloads, backups, and cloud storage.

We may retain a report or related information where reasonably necessary for legal, safety, fraud-prevention, dispute, chargeback, compliance, operational, or law-enforcement reasons.

14. Manual Review, Automated Tools, and AI

MyCyberScan may use both manual review and automated tools to conduct scans and prepare reports.

We may use third-party tools, AI tools, search engines, databases, public sources, image search tools, breach tools, people-search tools, social platforms, public records, and other online sources.

AI-assisted or automated processing may be used to support:

  • scan preparation;
  • research;
  • classification;
  • drafting;
  • comparison;
  • summarisation;
  • analysis;
  • quality control.

MyCyberScan does not use automated processing to make legal, employment, credit, insurance, eligibility, official suitability, security-clearance, or similarly significant decisions about any person.

Reports are provided for informational and awareness purposes only.

15. Third-Party Sources and Tools

To perform scans, process payments, operate our website, and maintain security, MyCyberScan may use third-party tools and service providers, including:

CategoryExamples
Website infrastructureHosting providers, WordPress, plugins, forms, security tools, anti-spam tools, technical service providers
Payment servicesStripe, checkout providers, fraud-prevention tools, payment processors
Scan tools and sourcesSearch engines, public records, breach tools, leak tools, image search tools, reverse image search tools, social platforms, public profile platforms
Visual and identity toolsFace-matching support tools, visual comparison tools, impersonation-detection tools, catfish-detection sources, deepfake-related sources
AI and analysis toolsAI tools, summarisation tools, classification tools, research-support tools
Professional supportLegal, accounting, tax, security, compliance, and technical advisers

These third parties may process information under their own terms, privacy policies, security standards, retention periods, and jurisdictional rules.

MyCyberScan is not responsible for the independent privacy practices, security practices, availability, accuracy, content, decisions, actions, or conduct of third-party platforms, services, tools, websites, or providers.

16. Cookies and Similar Technologies

Our website may use cookies and similar technologies that are necessary or useful for:

  • website functionality;
  • forms;
  • checkout;
  • payment processing;
  • security;
  • spam prevention;
  • session management;
  • basic website operation.

WPForms, WordPress, checkout providers, payment processors, hosting services, plugins, and security tools may set or use cookies or similar technologies.

We do not currently use analytics or marketing cookies unless stated in our Cookie Policy. If our cookie practices materially change, we may update this Privacy Policy and/or our Cookie Policy.

17. Marketing Communications

We may send:

  • service-related emails;
  • transactional emails;
  • report delivery emails;
  • payment or refund-related emails;
  • support replies;
  • privacy or policy-related notices;
  • security-related notices;
  • other communications necessary to provide our services.

We may also send marketing or promotional communications where permitted by law. Where required, we will seek consent or rely on another lawful basis. Marketing emails will include an unsubscribe option where required by applicable law.

We do not sell scan submission data or report contents to advertisers.

We do not intentionally use sensitive scan details, report contents, selfie images, explicit-content findings, breach findings, or similarly sensitive information for advertising or promotional purposes without appropriate consent.

18. Storage and Security

We take reasonable technical, organisational, and administrative steps to protect personal information.

Our security practices may include:

  • HTTPS website access;
  • encrypted email services or email-provider security features;
  • limited access to submissions;
  • manual deletion procedures;
  • malware scanning;
  • two-factor authentication;
  • password-protected devices;
  • security plugins or hosting security tools;
  • cache clearing or cache sweeping;
  • restricted internal handling by the MyCyberScan team.

However, no website, email system, server, device, payment system, plugin, form tool, cloud service, internet transmission, or storage method is completely secure.

We cannot guarantee that information will be immune from unauthorised access, loss, misuse, disclosure, alteration, interception, corruption, downtime, provider failure, human error, or cyber incidents.

Users submit information at their own risk and should avoid submitting unnecessary sensitive information.

More information is available in our Security Practices.

19. Where Information Is Stored or Processed

Scan submissions may be temporarily stored or processed through:

  • encrypted email;
  • WPForms;
  • WordPress or website systems;
  • website hosting systems;
  • local password-protected devices used to prepare reports;
  • payment processors;
  • security tools;
  • backup, plugin, or hosting systems where technically applicable;
  • third-party scan tools used to perform the requested service.

Although we aim to minimise retention, some systems may temporarily retain logs, sent emails, deleted items, server records, security records, payment records, backups, cache records, or technical data.

20. Retention and Deletion

MyCyberScan aims to delete scan submission data and final report working files from active systems within 24 hours or less after the final report is sent, unless retention is reasonably necessary for legal, safety, fraud-prevention, dispute, chargeback, compliance, operational, or law-enforcement reasons.

This may include deleting information from:

  • WPForms;
  • email inboxes;
  • local working files;
  • downloads;
  • temporary folders;
  • active report-preparation locations;
  • other active processing locations where reasonably practicable.

Some records may remain temporarily or separately in:

  • email sent folders;
  • deleted items or trash folders;
  • server logs;
  • plugin records;
  • hosting systems;
  • security records;
  • cache systems;
  • backups;
  • payment systems;
  • accounting systems;
  • provider-controlled systems.

These systems may retain limited information depending on technical settings, provider systems, deletion cycles, legal requirements, or manual deletion processes.

We do not generally retain a copy of the final report for support or disputes. Once a report and related scan data are deleted from our systems, they may not be recoverable by MyCyberScan.

Users are responsible for deleting any copies of reports, emails, attachments, downloads, screenshots, forwarded messages, or related materials from their own inboxes, devices, accounts, backups, cloud storage, and systems.

21. Exceptions to Deletion

We may retain, preserve, use, or disclose information where we reasonably believe it is necessary or appropriate to:

  • prevent, investigate, or report crime;
  • prevent harm to a person, child, vulnerable person, group, user, third party, or the public;
  • report suspected child exploitation, abuse, stalking, blackmail, threats, fraud, identity theft, impersonation, doxxing, extortion, exploitation, or serious misconduct;
  • investigate misuse of MyCyberScan;
  • respond to unlawful, abusive, harmful, fraudulent, misleading, suspicious, or unsafe conduct;
  • comply with court orders, subpoenas, warrants, lawful requests, regulators, government bodies, or law enforcement agencies;
  • establish, exercise, defend, or enforce legal rights;
  • handle payment disputes, chargebacks, fraud, refunds, accounting, or tax obligations;
  • protect the rights, safety, security, reputation, or operations of MyCyberScan, users, scan subjects, or others.

We reserve the right not to notify a user before preserving or disclosing information where we reasonably believe notification may be unlawful, unsafe, inappropriate, harmful, prejudicial to an investigation, or contrary to the purpose of the disclosure.

22. Disclosure of Information

We may disclose personal information to:

  • payment processors, including Stripe;
  • website hosting providers, including Hostinger or any replacement hosting provider;
  • email service providers;
  • WordPress, WPForms, plugins, and website infrastructure providers;
  • security, anti-spam, malware scanning, or technical service providers;
  • third-party scan tools, search tools, AI tools, image search tools, face-matching tools, breach tools, public-record sources, and related service providers;
  • professional advisers, including legal, accounting, tax, security, or compliance advisers;
  • regulators, courts, law enforcement, child protection authorities, government bodies, or other authorities where required or permitted by law;
  • any person or organisation where disclosure is necessary to prevent harm, investigate misuse, protect rights, respond to legal claims, or comply with law;
  • other parties with your consent or where otherwise permitted by law.

We do not sell scan submission data or report contents.

23. Overseas Users and International Processing

MyCyberScan is based in Australia but may accept users globally.

Information may be processed in Australia and in other countries depending on:

  • where users are located;
  • where service providers are located;
  • where payment processors operate;
  • where hosting providers operate;
  • where email providers operate;
  • where third-party scan tools operate;
  • where online sources or platforms are hosted.

Privacy laws in other countries may differ from those in your country.

By using our services, you acknowledge that your information may be processed, stored, accessed, transferred, or disclosed internationally where necessary to provide the service, process payments, operate the website, use third-party tools, comply with law, or protect safety and legal rights.

For users in regions with additional privacy rights, including the European Economic Area, United Kingdom, California, or similar jurisdictions, we will handle applicable privacy requests in accordance with applicable legal requirements where those laws apply to MyCyberScan.

24. Legal Bases for Processing

Where a legal basis is required, we may process personal information on one or more of the following bases:

  • your consent;
  • performance of a contract or steps taken before entering into a contract;
  • legitimate business interests, including providing services, preventing misuse, improving services, maintaining security, and communicating with users;
  • compliance with legal obligations;
  • protection of vital interests or safety;
  • establishment, exercise, or defence of legal claims;
  • public interest or lawful disclosure to authorities where applicable.

Where sensitive information, selfie images, or similar information is processed, we rely on consent or another applicable legal basis or exception where required by law.

You may withdraw consent where consent is the applicable legal basis, but this may affect our ability to provide the service. Withdrawal of consent does not affect processing that occurred before consent was withdrawn, or processing that is required or permitted for legal, safety, compliance, dispute, or enforcement reasons.

25. Access, Correction, and Deletion Requests

You may contact us to request access to, correction of, or deletion of your submitted information.

Where reasonably practicable, we aim to respond to privacy requests within 30 days.

You may request:

  • access to submitted information before deletion;
  • correction of submitted information before report completion;
  • deletion of submitted information before report completion;
  • information about how your data has been handled;
  • a response to a privacy complaint.

If a deletion request is made after the report has already been sent and the relevant information has already been deleted from our systems, MyCyberScan may be unable to retrieve, access, correct, delete, or resend that information.

Users are responsible for deleting copies of reports or related information from their own email inboxes, devices, accounts, downloads, backups, and systems.

Privacy requests can be sent to official@mycyberscan.com or through our website’s contact page.

We may request reasonable information to verify your identity, authority, or relationship to the request before responding.

We may refuse, limit, or delay a request where permitted by law, including where the request is fraudulent, abusive, unsafe, unlawful, unreasonable, technically impossible, or would affect the rights, safety, or privacy of another person.

26. Accuracy of Information

Users are responsible for ensuring that information submitted to MyCyberScan is accurate, lawful, authorised, and complete.

Because scan results may depend on third-party sources, public information, indexed content, search engines, databases, social platforms, image tools, public records, breach tools, and other external sources, MyCyberScan cannot guarantee that every finding is accurate, complete, current, permanent, accessible, correctly attributed, or exhaustive.

Some findings may be marked as confirmed, possible, unconfirmed, likely, or similar, depending on the available information.

Users should not treat a report as a final legal, employment, disciplinary, safety, criminal, or official determination.

27. User Responsibilities

Users must not submit information to MyCyberScan for unlawful, harmful, abusive, misleading, unauthorised, discriminatory, exploitative, or unsafe purposes.

Users must not use our services or reports for:

  • stalking;
  • harassment;
  • blackmail;
  • extortion;
  • doxxing;
  • revenge;
  • unlawful surveillance;
  • discrimination;
  • impersonation;
  • fraud;
  • identity theft;
  • abuse;
  • exploitation;
  • unauthorised employment screening;
  • unlawful investigation;
  • intimidation;
  • threats;
  • misuse of sensitive information;
  • any activity that may harm a person, group, business, or the public.

Users are responsible for how they use, store, share, disclose, secure, and delete any report they receive.

More information about acceptable use is available in our Terms of Use.

28. Testimonials and De-Identified Information

We may use testimonials in the future.

We will not use a testimonial containing personal scan details unless we have obtained appropriate written consent.

We may use anonymised, aggregated, or de-identified information to:

  • improve our services;
  • understand common risk categories;
  • improve scan workflows;
  • improve report quality;
  • enhance safety controls;
  • improve website functionality;
  • strengthen security.

We will not intentionally use de-identified information in a way that identifies a specific person.

29. Data Incidents and Breach Response

If we become aware of a suspected data incident affecting personal information, we may take steps to assess, contain, investigate, and respond to the incident.

Where required by applicable law, we may notify affected users, regulators, law enforcement, service providers, or other relevant parties.

We may also take steps to reduce harm, secure systems, preserve evidence, suspend services, revoke access, reset credentials, or cooperate with appropriate authorities.

30. Privacy Complaints

If you have a privacy concern or complaint, contact us at official@mycyberscan.com or through our website’s contact page.

Please include enough information for us to understand and respond to your concern.

We aim to respond within 30 days where reasonably practicable.

If you are located in Australia and are not satisfied with our response, you may have the right to contact the Office of the Australian Information Commissioner or another relevant privacy authority.

If you are located outside Australia, you may also have rights under privacy laws that apply in your region.

31. Official Contact Channel

Our official contact email is official@mycyberscan.com.

Our website’s contact page may also be used to contact us.

At the time this Privacy Policy was last updated, communications through our website contact form are routed to our official email address.

We may refuse to respond to messages, submissions, or requests that we reasonably believe are unlawful, abusive, harmful, fraudulent, misleading, threatening, exploitative, irrelevant, spam, unsafe, or inconsistent with our policies.

32. Related Legal Pages

This Privacy Policy should be read together with:

33. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, website, technology, providers, laws, risk controls, or business practices.

The updated version will be posted on our website with an updated “Last updated” date.

Your continued use of MyCyberScan after changes are posted means you accept the updated Privacy Policy, to the extent permitted by law.

Contact

For privacy questions, requests, or complaints, you can contact us anytime or email official@mycyberscan.com.