Privacy Policy
1. Information We Collect & How We Use It
You retain ownership of the subscription data you enter into CyberLife. We do not claim ownership, do not use it for commercial purposes, and do not sell it to third parties. CyberLife is funded through Pro membership subscriptions and currently does not display third-party advertising.
Information You Provide
- Account: phone number or email address, and a securely hashed password
- Subscription data: service name, amount, billing cycle, reminder times you enter manually
- When you sign in with "Sign in with Apple", we receive an anonymized identifier from Apple
Information Collected Automatically
- Device data: device model, operating system version, app version
- Log data: IP address, crash diagnostics, application performance metrics
This information is used primarily for product compatibility, troubleshooting, and security purposes. We do not collect your precise location, contacts, browsing history, or microphone/camera input. The app may temporarily access your photo library only when you actively choose to save a share card image (write access only); we do not read or collect your photos.
How We Use Your Information
We use the information we collect for the following purposes:
- Identity verification — to register, sign in, and reset your password
- Subscription tracking — to store and sync your subscription records across your devices when iCloud sync is enabled
- Renewal reminders — to send local notifications, emails, or SMS based on your reminder settings
- Pro subscription fulfillment — to process Pro membership purchases via Apple StoreKit (we do not handle payment credentials)
- Device compatibility & crash diagnostics — to maintain app stability across iOS versions
- Security & fraud prevention — to detect and prevent account takeover, abuse, or attacks
Sensitive Personal Information
Under the California Consumer Privacy Act (as amended by the CPRA), categories of "sensitive personal information" include account log-in credentials in combination with passwords. We collect your account credentials (email or phone number, plus a securely hashed password) solely to authenticate you and provide the service. We do not use, disclose, or share this information for any purpose other than authentication, service provision, or as required by law. You may request limitation of the use of this information at any time (see "Your Privacy Rights").
We do not knowingly collect other categories of sensitive personal information (such as government IDs, biometric data, precise geolocation, racial or ethnic origin, religious beliefs, health information, or sexual orientation). Subscription amounts you enter manually are treated as general financial records for the purposes of this service.
Aggregated and De-identified Data
We may use aggregated, de-identified, or anonymized data (data that cannot reasonably be used to identify you) for purposes such as product analytics, service improvement, and research. Such aggregated data is not considered personal information and is not subject to this Privacy Policy.
2. Information Disclosure
We do not sell, rent, or share your personal data with any third party for advertising or marketing purposes.
We may disclose your information only in the following limited circumstances:
Service Providers
We share information with service providers who help us operate the service, such as the SMS provider used to deliver verification codes and reminders. These providers are required to protect your information consistent with applicable data protection laws and may only use it as necessary to perform services for us.
Legal Compliance
We may disclose your information when required by law, court order, or other valid legal process, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.
Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the transaction. We will require any successor entity to honor this Privacy Policy or notify you of any material changes.
With Your Consent
We may disclose your information for any other purpose with your explicit consent.
3. International Data Transfers
Your account and subscription data are stored on cloud servers located in the United States.
If you are accessing CyberLife from outside the United States (such as the European Union, United Kingdom, Japan, Korea, or other regions), please note that your information will be transferred to and processed in the United States, where data protection laws may differ from those in your country.
Transfer Mechanism for EU / UK / Swiss Users
For users in the European Economic Area, United Kingdom, or Switzerland, the transfer of your personal information to the United States is necessary for the performance of the contract between you and us, in accordance with Article 49(1)(b) of the GDPR and equivalent UK and Swiss provisions.
We use industry-standard safeguards during international transfer, including encryption in transit (HTTPS / TLS).
4. Data Retention
We retain your personal information for as long as your account is active.
When you delete your account, your data will be removed from our active production systems within 30 days. Residual copies in backups may persist for up to 90 days during routine backup rotation, after which they are permanently overwritten.
We may retain limited information for longer where required by applicable law or for the establishment, exercise, or defense of legal claims.
5. Data Security
We protect your information through industry-standard security practices:
- Transit encryption: all data in transit is protected using HTTPS / TLS
- Storage: passwords are one-way hashed before storage; we cannot read your plaintext password
- Access control: reasonable access controls limit data access to authorized personnel
- Where supported by our infrastructure providers, data is encrypted at rest
Security Incidents
In the event of a data breach, we will notify affected users without undue delay via in-app notification, email, or other reasonable means. We will also notify the relevant supervisory authorities (such as EU Data Protection Authorities) within the timeframes required by applicable law (e.g., 72 hours under GDPR Art. 33 where applicable).
For California residents, we will provide breach notification in accordance with California Civil Code §1798.82.
No method of internet transmission or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
6. Your Privacy Rights
Depending on your location and applicable law, you have certain rights regarding your personal information.
EU / UK Users (GDPR)
Under the General Data Protection Regulation, you have the right to:
- Access your personal data and receive a copy
- Rectify inaccurate or incomplete data
- Erase your personal data
- Restrict or object to our processing
- Data portability — receive your data in a structured, machine-readable format
- Withdraw consent at any time
- Lodge a complaint with your local supervisory authority (Data Protection Authority)
California Users (CCPA / CPRA)
Under the California Consumer Privacy Act (as amended by the CPRA), California residents have the right to:
- Know what personal information we collect, use, disclose, or sell
- Delete personal information we have collected
- Correct inaccurate personal information
- Opt out of the sale or sharing of personal information (we do not sell or share for advertising)
- Limit the use and disclosure of sensitive personal information (we use your account credentials solely for authentication; you may contact us to request further limitation)
- Non-discrimination — we will not deny services or charge different prices for exercising your rights
You may designate an authorized agent to make a request on your behalf. We may require the agent to provide written authorization signed by you and may require you to verify your identity directly before processing the request.
CyberLife does not sell or share personal information for cross-context behavioral advertising.
Other Jurisdictions
Users in other regions may have similar rights under local data protection laws (e.g., Japan's APPI, Korea's PIPA, Brazil's LGPD).
How to Exercise Your Rights
To exercise any of the rights above, contact privacy@sixpawcat.com. We will respond within the timeframes required by applicable law (typically 30 days under GDPR, up to 45 days under CCPA, with possible extensions for complex requests). To verify your identity, we may require additional verification (such as confirming the request from your registered email address).
Account Deletion
You can delete your account directly in the app:
Settings → Account → Delete Account
Your data will be removed from our active production systems within 30 days; residual copies in backups will be permanently overwritten in routine backup rotation. Account deletion is irreversible — please export your data first via Settings → Data Export if needed.
7. Third-Party Services
CyberLife integrates with the following third-party services, each invoked only when the corresponding feature is used:
- Apple StoreKit (Apple Inc., iOS only) — Pro membership in-app purchase. Apple handles all payment processing; we do not access your payment credentials.
- Apple iCloud / CloudKit (Apple Inc., iOS only) — Used only when iCloud sync is enabled, to synchronize subscription data across devices on the same Apple ID.
- Sign in with Apple (Apple Inc., iOS only) — Invoked only when you choose "Sign in with Apple"; passes an anonymized identifier from Apple.
- Supabase (Supabase, Inc., hosted on AWS in the United States) — Backend database and authentication service. Stores your account credentials (hashed) and subscription data when you sign in with email or phone. See https://supabase.com/privacy for their privacy policy.
- Twilio (Twilio Inc.) — Used only when you enable SMS-based renewal reminders or sign in with phone number, to deliver verification codes and reminder messages. The phone number and message content are passed to Twilio. See https://www.twilio.com/legal/privacy for their privacy policy.
- Email delivery (managed via Supabase Auth) — Used to deliver authentication emails (verification, password reset) and renewal reminder emails when you enable email reminders.
We use Apple's built-in crash logging for diagnostics and do not currently use any third-party analytics or advertising SDKs.
When CyberLife launches on Android or other platforms, this section will be updated to include corresponding third-party services and SDK details.
External Links
The service may contain links to third-party websites or services that are not operated by us. We are not responsible for the content, privacy practices, or policies of those third-party sites. We encourage you to review the privacy policies of any third-party services you visit.
8. App Permissions
CyberLife requests the following system permissions on iOS:
- Notifications — to send subscription renewal reminders
- Calendar — to sync subscription expiration events to your system calendar (optional)
- Photos — write access only, used solely when you save a share card image to your photo library (the app does not read or scan your existing photos)
- Network access — for sign-in, data sync, and exchange-rate refresh
All permissions can be revoked at any time in iOS Settings → CyberLife. Disabling a permission will disable the related feature.
CyberLife does not request access to your contacts, microphone, camera, precise location, or motion data.
When CyberLife launches on Android or other platforms, this section will list permission requests for those platforms.
9. Children's Privacy
This service is not directed to children under the age of 13 (or the equivalent minimum age in your jurisdiction, e.g., 16 in some EU countries).
We do not knowingly collect personal information from children under 13. If we discover that we have collected personal information from a child under 13 without verifiable parental consent, we will delete it as soon as possible.
We recommend that older minors use this service under parental guidance and with parental consent.
If you are a parent or guardian and become aware that your child has submitted personal information to us, please contact privacy@sixpawcat.com so we can promptly delete it.
10. Changes to This Privacy Policy
We may revise this Privacy Policy from time to time. The "Last Updated" date at the top of this policy reflects the most recent revision.
For material changes that affect your rights, we will notify you via in-app notification, email, or other reasonable means before the changes take effect. Your continued use of the service after the effective date constitutes acceptance of the updated policy.
We encourage you to review this Privacy Policy periodically.
11. About Us / Contact Us
About Us
Company: Hangzhou Six Paw Cat Technology Co., Ltd.
Address: Hangzhou, China
Email:
· privacy@sixpawcat.com — privacy and data protection inquiries
· support@sixpawcat.com — product and service inquiries
Contact Us
If you have questions, comments, or wish to exercise your privacy rights, please contact privacy@sixpawcat.com. We will respond within the timeframes required by applicable law after verifying your identity.
If you are not satisfied with our response, you may also lodge a complaint with your local Data Protection Authority (EU/UK), the California Attorney General (California), or any other competent regulatory body in your jurisdiction.