Legal

Privacy Policy

Effective 6 September 2026 Version 1.0

This policy covers cyberwarriornetwork.com, the Trust Gate console and demo environment, and the public API, operated by Cyber Warrior Network. It says what we collect, why, how long we keep it, and how to make us delete it.

The short version. We do not sell your data and we do not share it with advertisers. We collect analytics about how the site is used, and we keep the email address and details you type into a form. If you connect a social account, we hold the access token that account issues us and nothing else from it. You can have all of it deleted by emailing us.

1 What we collect

WhatWhenWhyHow long
Usage analytics
pages viewed, clicks, approximate location from IP, browser and device, session recordings
Every visit To understand what works on the site and what does not 12 months
Contact details
name, email, company, role, and whatever else you type
Only when you fill in a form: waitlist, early access, feedback survey, or a demo request To reply to you and to tell you when the thing you asked about is ready Until you ask us to delete it
Account and API credentials
account identifier, hashed secrets, API keys
If you are issued console or API access To authenticate you and rate limit the API Life of the account, plus 30 days
Connected platform tokens
OAuth access and refresh tokens, the account name and avatar the platform returns. For TikTok, connected through our CWN Postiz scheduling tool: the scopes user.info.basic, user.info.profile, user.info.stats, video.list, video.upload, and video.publish
Only if you connect a social or publishing account yourself To post on your behalf, at your instruction, to that account. See the CWN Postiz product page for what each TikTok scope is used for Until you disconnect
Whatever you submit to the gate
the action, the policy context, and the resulting signed receipt
Every evaluation, including in the demo To evaluate the action and produce the record that is the point of the product Receipts are permanent
Server logs
IP address, request path, status, timestamp
Every request Security, abuse prevention, and debugging 90 days

2 Receipts are permanent, and that is deliberate

A Trust Gate receipt is a cryptographically signed, append-only record of one decision. It exists so that nobody, including us, can rewrite what happened after the fact. That is the entire value of the product, and it has a consequence you should understand before you use it:

We cannot edit or delete an issued receipt. We can mark one superseded, and we will delete the account and contact data attached to it on request, but the signed record itself stays. So do not put personal data, secrets, or anything confidential into the demo environment. Use synthetic data there. The demo exists to show you the mechanism, not to process anything real.

3 Who we share it with

We do not sell personal data. We do not share it for advertising. We use a small number of processors who handle data on our behalf, under contract, only to run the Service:

We will also disclose data where the law requires it, or where it is necessary to investigate abuse or protect someone's safety. If we are ever part of a merger or acquisition, data may transfer with the business, and we will say so on this page before it happens.

4 Cookies and similar technology

We use cookies and browser storage to keep you signed in, to remember your preferences, and for the analytics described above. You can block or delete cookies in your browser. Some of the console will stop working if you block the ones that keep you signed in.

5 Legal bases, if you are in the UK, EU, or EEA

We are based in the United States, so using the Service involves transferring your data there. Where required we rely on the European Commission's Standard Contractual Clauses.

6 Your rights

Wherever you are, you can ask us to show you what we hold about you, correct it, delete it, or stop using it for a particular purpose. Depending on where you live you may also have the right to a portable copy, to object to processing, and to complain to your data protection authority. If you are in California, you have the rights under the CCPA and CPRA, including the right to know and the right to delete; we do not sell or share personal information as those laws define it, and we will not discriminate against you for exercising a right.

To exercise any of this, email [email protected]. We will respond within 30 days. We may need to verify who you are first.

7 Security

Access to production data is restricted and authenticated. Traffic is encrypted in transit. Secrets are not stored in source code. We scan dependencies and code for vulnerabilities on a schedule. No system is perfectly secure, and we do not claim otherwise. If you find a vulnerability, report it to [email protected] and please give us a reasonable chance to fix it before publishing.

8 Children

The Service is not for anyone under 18 and we do not knowingly collect data from children. If you believe a child has given us data, tell us and we will delete it.

9 Changes to this policy

The version in force is the one on this page, with its effective date at the top. If we make a material change we will post notice on the site before it takes effect.

10 Contact

Cyber Warrior Network, [email protected]. See also the Terms of Service.