Privacy Policy

How we collect, use, store, and protect information when you use CyberFruit to run investor-grade diligence on the public record.

Effective date: June 25, 2026

1. Introduction

This Privacy Policy explains how CyberFruit Lab - FZCO (operating as "CyberFruit", "we", "us", or "our") collects, uses, stores, and discloses information when you use our website, products, and AI-driven diligence engine (together, the "Services"). By using the Services, you agree to the practices described in this policy.

CyberFruit is an AI-native investment committee. You submit a startup — typically a company website — and our engine performs the diligence an investor would: it reads the public record, weighs the market, traction, and founder signals, labels how well each finding is evidenced, and returns a verdict, the diligence gaps to close, and the questions to ask before the first call. The same engine serves investors screening deal flow and founders preparing to raise.

2. Information We Collect

2.1 Account information

When you create an account or contact us, we collect the information you provide and the information our authentication provider passes to us — including your name, email address, and basic profile and sign-in metadata. We do not store your password; account authentication is handled by a third-party authentication provider.

2.2 Report inputs

To run a report you submit a startup to screen — usually a company website URL, and optionally additional context you choose to add about the company. We use these inputs to direct the diligence run and to produce your report.

2.3 Billing information

Payments for memberships and report credits are processed by a third-party payment processor. We receive confirmation of your transactions, your plan and credit balance, and limited billing metadata. We do not collect or store your full card number or other complete payment-instrument details.

2.4 Public-record data gathered during analysis

When you run a report, our engine collects information that is publicly available about the screened company and its founders — for example, the company's own site, product, and pricing pages; news, interviews, and press coverage; public funding databases and company registries; hiring signals and review or app-store listings; and the founders' public professional footprint, including public code repositories. Each finding is logged with its source, date, and an evidence label. We work only from the public record and do not seek to obtain private, restricted, or unlawfully sourced data.

2.5 Usage and technical data

We collect technical usage data — pages visited, features used, device and browser metadata, IP address, timestamps, and diagnostic logs — through our product-analytics provider and our own logging, to operate, secure, and improve the Services.

3. How We Use Your Information

We use the information described above to:

  • Provide, operate, and maintain the Services — including running diligence, generating reports and verdicts, and managing your credit balance and membership.
  • Tune and improve the models, prompts, and pipelines that power the diligence engine.
  • Send transactional communications about your account, billing, and product changes.
  • Detect and prevent fraud, abuse, and security incidents.
  • Comply with our legal and contractual obligations and enforce our Terms of Service.
  • Conduct internal analysis and publish aggregated, de-identified research and benchmarks that do not identify any individual user.

We do not sell personal information.

We do not sell or rent personal information. We do not use your account data or your private reports to advertise to you on behalf of third parties, and we do not share your private reports with anyone except as needed to deliver the Services or as required by law.

4. Public-Record Diligence and the People We Research

Our reports analyze information about companies and the individuals associated with them — most often founders and executives — drawn entirely from the public record. We follow the evidence wherever the public record leads, but we do not cross ethical or legal lines to obtain it: we do not bypass access controls, scrape behind logins where prohibited, or use private or unlawfully obtained data.

Findings are presented with evidence labels that distinguish a corroborated fact from an unverified claim, each tied to its source and date, so the conclusions can be audited rather than taken on faith.

If you are an individual who appears in a report and you wish to access, correct, or object to how your publicly sourced information is used, contact us at hi@cyberfruit.ai. We will review the request and respond consistent with this policy and applicable law.

5. Reports, Confidentiality, and the Curated Library

Which companies we screen for the curated library is decided independently — we pick them from public sources and other market signals, not from your private runs. We do not use your private report inputs or runs as ideas for what to review or publish. Because that selection is independent of you, we cannot guarantee that a curated report on your startup will never appear in the library if our public-signal sourcing happens to surface it. A report you run yourself stays private unless you publish it, and a curated report never exposes your account details or your private runs.

If you believe a published report contains an error or should not be public, contact us at hi@cyberfruit.ai and we will review it.

6. Data Storage and Transfer

Information is processed at our operating locations and at the locations of the subprocessors described below. By using the Services, you consent to the transfer of your information across borders, including to the United States and to other jurisdictions where our subprocessors operate. We rely on standard contractual safeguards where required by applicable law.

7. Third-Party Subprocessors

We use a small number of established infrastructure and AI providers to operate the Services. For security reasons we describe them by category rather than by name. These categories include:

  • Cloud hosting and edge-network providers — for serving the website and running the application.
  • An authentication provider — for account sign-in and identity.
  • A payment processor — for memberships, report credits, and billing.
  • Large-language-model and AI-orchestration providers — for the diligence pipeline that reads the public record and produces reports.
  • A managed database provider — for storing account, billing, and report data.
  • An object-storage provider — for storing generated report artifacts.
  • A transactional-email provider — for account and product email.
  • A product-analytics provider — for aggregate site usage and conversion measurement, routed through our own first-party endpoint and configured to mask form inputs.

We share data with these providers only as needed to deliver the Services and under data-processing terms. A current list of named subprocessors is available on request at hi@cyberfruit.ai.

8. Data Security

We apply administrative, technical, and physical safeguards designed to protect information from unauthorized access, use, alteration, and disclosure. These include encryption of data in transit and at rest, scoped access controls, audit logging, secret rotation, and continuous infrastructure monitoring. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.

9. Cookies and Similar Technologies

Our website uses cookies and similar technologies to enable core functionality (including authentication), remember preferences, and measure aggregate site performance through our analytics provider, which may set first-party cookies and local-storage entries on cyberfruit.ai. Where your browser sends a Do Not Track signal, our analytics is configured to respect it. You can modify your browser settings to manage cookie preferences; doing so may affect certain functionality.

10. Your Rights

Depending on where you live, you may have the following rights with respect to your personal information:

  • Access — request a copy of the personal information we hold about you.
  • Correction — ask us to fix inaccurate or incomplete information.
  • Deletion — ask us to delete your personal information (subject to legal retention requirements).
  • Restriction or objection — ask us to limit or stop certain processing of your information.
  • Portability — receive your personal information in a structured, machine-readable format.
  • Withdrawal of consent — withdraw consent for any processing that relies on it.

To exercise any of these rights, contact us at hi@cyberfruit.ai.

11. Data Retention

We retain personal information for as long as needed to provide the Services, meet our legal and contractual obligations, resolve disputes, and enforce our agreements. Reports and their derived data are retained for the lifetime of your account unless you instruct us otherwise in writing or applicable law requires earlier deletion. On deletion of your account, we will delete or anonymize personal information within a reasonable period unless retention is required by law.

12. Children's Privacy

The Services are intended for professional use and are not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can delete it.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Effective date" at the top of this page and, where appropriate, notify you through the Services or by email. Continued use of the Services after an update constitutes acceptance of the updated policy.

14. Contact Us

Questions?

Reach us at hi@cyberfruit.ai. We are CyberFruit Lab - FZCO, operating as CyberFruit.