← Back

Privacy Policy

Last updated: May 2026

What we collect

  • Account data: email, display name, optional public handle.
  • Gameplay data: scenario attempts, scores, streaks, captured flags.
  • Reported scams: text or links you paste into the report tool. AI redacts PII before storage.
  • Technical: minimal logs needed to operate the service (errors, abuse signals).

What we don't do

  • We don't sell your data.
  • We don't use your gameplay data for advertising.
  • We don't share individual scores publicly unless you opt in to a public profile.

Subprocessors

Authentication and database: Supabase (EU-hosted by default for our managed deployment). AI triage and moderation: Lovable AI Gateway. Each subprocessor processes only what is necessary to deliver the feature.

Organizations

If your organization invited you, your administrator can see your completion of assigned compliance scenarios and aggregated risk metrics for their workspace. They cannot see scenarios you complete outside their workspace.

Your rights

You can export or delete your account data at any time. Email privacy@cybermamushka.app.

Children

The Service is not directed at users under 13.

Changes

Material changes will be communicated in-app at least 14 days before they take effect.