Last Updated: January 14, 2026
At Cyqle, we are committed to protecting your privacy and providing transparent information about how we collect, use, and protect your data. This Privacy Policy complies with 2026 privacy regulations including GDPR, CCPA, and the EU AI Act.
Privacy 3.0 Compliant - Full Transparency & User Control
Session data is wiped instantly when you close unless you enable persistence
We clearly disclose when AI systems are used and how they work
Your data may transit through peer nodes with Standard Contractual Clauses
Full access, deletion, portability, and objection rights under GDPR/CCPA
We distinguish between two primary categories of data: Account Data (necessary for billing and account management) and Session Data (ephemeral data generated within your virtual desktop environment).
We collect and store the following information to manage your account and provide billing services:
Legal Basis: Contractual Necessity - This data is required to fulfill our contract with you to provide the Cyqle service.
Data generated during your use of virtual desktop sessions. This category is inherently ephemeral due to our jailed environment architecture:
Legal Basis: Contractual Necessity - Processing session data is essential to provide you with an isolated, functional virtual desktop environment.
Important: Session data in ephemeral sessions is encrypted with unique, per-session keys and is cryptographically erased upon session termination. This data cannot be recovered after deletion.
Critical Privacy Guarantee: Cyqle does NOT have access to or interfere with anything inside your jailed session. We cannot read your files, access your data, or monitor your activities within the session. The only operational data we may collect is anonymized logging (session duration, resource usage) and only when you expressly allow us (bug reports, support requests).
We collect limited technical data to maintain platform stability and security:
Legal Basis: Legitimate Interest - We have a legitimate interest in maintaining platform security, preventing fraud, and optimizing service performance.
Cyqle incorporates AI-powered features to enhance your productivity. Under the 2026 EU AI Act, we are required to provide clear disclosure when you interact with or are affected by AI systems.
When you use Cyqle's automation features (browser recording, task delegation, workflow scheduling), you may interact with our "AI Operator" - an AI system designed to execute repetitive web tasks on your behalf.
The AI Operator uses the following logic to assist you:
The AI Operator operates under your direct supervision. It does not make autonomous decisions that affect your account, billing, or access rights. All critical operations require explicit user confirmation. The AI does not access or process your session data for training purposes without explicit opt-in consent.
Cyqle uses limited automated decision-making systems to ensure platform security and fair resource allocation. Under 2026 CCPA requirements, you have the right to opt out of certain automated processing.
Our system analyzes account creation patterns, payment behaviors, and IP reputation scores to detect and prevent fraudulent sign-ups. False positives are reviewed by human operators within 24 hours.
An automated load balancer allocates your session to available infrastructure nodes based on current capacity, geographic proximity, and subscription tier priority.
We monitor resource consumption patterns (CPU, memory, network) to detect violations of our Acceptable Use Policy (e.g., cryptocurrency mining, DDoS attacks).
If an automated system flags your account or denies access, you have the right to request human review and contest the decision. You may also opt out of certain automated processing (excluding critical security functions).
To exercise this right, contact privacy@cyqle.in with your account email and the subject line: "ADMT Opt-Out Request."
Cyqle's peer-to-peer (P2P) architecture means that session data may transit through various geographic nodes during real-time collaboration. We take specific measures to ensure compliance with international data transfer regulations.
When you collaborate with other users in real-time, your session data is transmitted directly between peers using libp2p. This means:
To protect your data during international transfers, we implement the following safeguards:
While we cannot guarantee the exact geographic path of P2P-routed data, you can control where your persistent session data is stored by selecting your preferred data center region in your account settings (available for Pro and Power tier users).
One of Cyqle's core privacy features is the ephemeral nature of our jailed environment architecture. Here's exactly how we handle data retention and deletion:
By default, all sessions are ephemeral. This means:
If you enable persistence (available on Lite, Pro, and Power tiers), your session data is retained as follows:
Account data (email, billing information, usage logs) is retained for as long as your account is active, plus an additional 90 days after account closure to comply with financial record-keeping requirements. After this period, all personal identifiers are permanently deleted.
You may request deletion of all your personal data at any time by contacting privacy@cyqle.in. We will complete your deletion request within 30 days, except where retention is required by law (e.g., tax records, fraud prevention).
Under GDPR (for EEA residents) and CCPA (for California residents), you have the following rights regarding your personal data:
You can request a copy of all personal data we hold about you
You can update or correct inaccurate personal information
You can request deletion of your personal data
You can request your data in a machine-readable format
You can object to certain types of processing (e.g., marketing)
You can request that we limit how we use your data
To exercise any of these rights, email privacy@cyqle.in with your account email and specify which right you wish to exercise. We will respond within 30 days.
We implement industry-leading security measures to protect your data from unauthorized access, disclosure, or destruction:
In the unlikely event of a data breach affecting your personal information, we will notify you within 72 hours via email and provide details about the nature of the breach, affected data categories, and remediation steps.
Cyqle uses minimal cookies and tracking technologies. We do not use third-party advertising trackers or sell your data to data brokers.
Session authentication token (httpOnly, secure, sameSite=strict) - expires after 30 days or logout
We use privacy-respecting analytics (Plausible Analytics) that does not track individual users or use cookies. You can opt out via your browser's Do Not Track (DNT) header.
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of material changes via email at least 30 days before they take effect. Your continued use of Cyqle after the updated policy takes effect constitutes acceptance of the changes.
If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact our Data Protection Officer:
privacy@cyqle.in