Privacy policy
Last updated: September 2026
1. Overview
This Privacy Policy explains what personal data Cybersec Revolution ("we", "us") collects when you use our website, courses, shop and services, why we collect it, how we protect it, and the rights you have over it. We designed this site to collect as little data as possible — you can browse everything except account features without sharing anything.
2. What data we collect
Account data — when you register: your name, username, email address, an scrypt-hashed password (we never see or store your actual password), and optional profile fields (phone, company, job title, bio).
Messages you send us — contact form submissions, order requests and account-deletion requests, including the content you write and the time it was sent.
Technical data — a random session identifier stored in a strictly-scoped cookie, and a one-way salted hash of your IP address used solely for abuse prevention and rate limiting. We do not run advertising or cross-site tracking of any kind.
3. How we use your data
- To authenticate you and keep your session secure.
- To deliver courses, products and services you request.
- To reply to your messages and process orders and deletion requests.
- To protect the service against abuse, brute force and automated attacks.
- To meet legal and accounting obligations where required.
We never sell your data. We never share it for marketing. Full stop.
4. Cookies & sessions
We use exactly one cookie: a strictly necessary session cookie (csr_sid). It is HttpOnly (invisible to JavaScript), SameSite=Strict (blocks cross-site requests) and marked Secure on HTTPS connections. It contains a random identifier — no personal data. We set no analytics, advertising or social media cookies.
5. How we protect your data
Because we are a security company, our own bar is high. Passwords are hashed with scrypt and per-user salts. All input is validated server-side against strict allowlists. Every response ships with a strict Content-Security-Policy. Forms are protected by CSRF verification, captchas and rate limiting. Data files are written atomically with restrictive permissions. The application itself has zero third-party dependencies, eliminating supply-chain risk. No system is perfectly secure, and we do not claim otherwise — but we practice what we preach, every day.
6. Retention
Account data is kept until you delete your account, which erases your profile permanently and immediately. Contact messages and order records are kept for up to 24 months for warranty, accounting and legal purposes, then deleted or anonymized. Sessions expire after 7 days of inactivity (30 days absolute).
7. Third parties
We embed no third-party scripts, fonts or trackers. Our tutorial sections link to and may embed content from YouTube (youtube-nocookie.com) — when you interact with YouTube, their privacy policy applies. Payment is completed on our payment provider’s secure page; card data never touches our servers.
8. Your rights
You may access, correct or export your profile data at any time from your account page. You may delete your account permanently from the profile danger zone — no email, no waiting period. If you cannot access your account, submit a deletion request from the Delete Account page and we will verify you manually. You may also contact info@cybersecrevolution.com for any privacy question.
9. Children
Our services are intended for users aged 16 and above. We do not knowingly collect data from children; if we learn we have, we delete it immediately.
10. Changes to this policy
If we change this policy materially, we will announce it on this page and, for registered users, by email. Continued use after changes means you accept the updated policy.