[ Legal ]·Privacy Policy
Your Privacy Matters

Privacy Policy

Clear, transparent rules about how we collect, use, and protect your data — written in plain language, not legalese.

Last Updated:February 15, 2026
Effective:March 1, 2026

You Own Your Data

All your data — events, dashboards, queries — belongs to you.

No Data Selling

We never sell your personal info or event data, period.

Encrypted Everywhere

TLS 1.3 in transit, AES-256 at rest. Always.

GDPR & CCPA Ready

Full compliance with global privacy regulations.

1. Introduction

At Cypon, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our analytics platform, website, and related services (collectively, the "Services").

By using our Services, you agree to the collection and use of information in accordance with this policy. If you disagree with any part of this policy, please discontinue use of our Services.

2. Information We Collect

We collect several types of information for various purposes:

2.1 Account Information

  • Name, email address, and company details
  • Billing information and payment method
  • Account credentials (passwords are hashed)

2.2 Usage Data

  • Dashboard interactions and feature usage
  • API request logs and query patterns
  • Browser type, device info, and IP address

2.3 Customer Event Data

  • Events you ingest into Cypon from your products (treated as your data — see Section 5)
  • Aggregated metrics and dashboards you create

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain our Services
  • Process transactions and send billing notifications
  • Improve, personalize, and expand our Services based on aggregated usage patterns
  • Communicate product updates, security alerts, and support
  • Detect and prevent fraud, abuse, or security incidents
  • Comply with legal obligations and enforce our Terms

We never sell your personal information or your customer event data to third parties.

4. How We Share Your Information

We only share your information in the following limited circumstances:

4.1 Service Providers

We work with vetted third-party providers (e.g., AWS, Stripe, Snowflake) that help us deliver our Services. These providers are contractually bound to protect your data.

4.2 Legal Requirements

We may disclose information when required by law, court order, or to protect our rights, users, or the public.

4.3 Business Transfers

In the event of a merger, acquisition, or asset sale, your information may be transferred. We will notify you before any such transfer.

5. Your Data Ownership

You own your data. All event data, dashboards, configurations, and outputs you create remain your property at all times.

You can:

  • Export your data in CSV, JSON, or Parquet at any time
  • Request a complete data dump within 30 days of cancellation
  • Permanently delete your account — we'll erase all data within 90 days

6. Data Security

We implement industry-leading security practices to protect your information:

  • Encryption in transit — TLS 1.3 for all data transmission
  • Encryption at rest — AES-256 for all stored data
  • SOC 2 Type II certified — independently audited annually
  • Role-based access control — granular permissions and SSO
  • Penetration testing — quarterly third-party security audits

7. Data Retention

We retain your information for as long as necessary to:

  • Provide our Services to you
  • Comply with legal obligations (e.g., tax records)
  • Resolve disputes and enforce agreements

Specific retention periods vary by data type. Account data is retained while your account is active. Customer event data follows retention rules you configure (default: 24 months on Growth plan, unlimited on Scale plan).

8. Your Privacy Rights

Depending on your location, you may have the following rights under GDPR, CCPA, and similar laws:

  • Right to Access — request a copy of your personal data
  • Right to Rectification — correct inaccurate data
  • Right to Erasure — request deletion of your data
  • Right to Portability — receive data in a machine-readable format
  • Right to Object — opt out of certain processing activities
  • Right to Withdraw Consent — at any time

To exercise any of these rights, email us at privacy@Cypon.io. We respond within 30 days.

9. Cookies & Tracking

We use minimal cookies to:

  • Maintain your login session (essential)
  • Remember your preferences (functional)
  • Understand product usage (anonymous, aggregated only)

We do not use third-party advertising or tracking cookies. See our Cookie Policy for details.

10. International Data Transfers

Your data may be processed in the United States, European Union, or Singapore depending on the region you select during signup. We use Standard Contractual Clauses (SCCs) for cross-border transfers and offer EU and US data residency options on Scale plans.

11. Children's Privacy

Our Services are not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us immediately.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We'll notify you of significant changes via email or in-product notification at least 30 days before the changes take effect.

Your continued use of our Services after the effective date constitutes acceptance of the updated policy.

13. Contact Us

For privacy questions, requests, or concerns, contact us:

  • Email: privacy@Cypon.io
  • Data Protection Officer: dpo@Cypon.io
  • Mail: Cypon Inc., 545 Mission St, Suite 700, SF, CA 94105

EU residents may also contact our EU representative at eu-rep@Cypon.io.

Have privacy questions?

Our Data Protection Officer is here to help. We typically respond to privacy requests within 24 hours.