Privacy Policy

Last updated: 24 May 2026

Your privacy matters to us. This Privacy Policy explains clearly and honestly what data Your Cyber Buddy collects when you use our service, why we collect it, how we protect it, and what rights you have over it.

We have written this policy in plain English because we believe you deserve to understand it — not just sign it.

1. Who We Are

Your Cyber Buddy ("we", "us", "our") operates the website yourcyberbuddy.co.uk and the AI-powered cybersecurity career assessment quiz.

Data Controller: Your Cyber Buddy

Contact: info@yourcyberbuddy.co.uk

For any privacy-related questions or to exercise your data rights, please contact us at the email address above. We aim to respond within 5 working days.

2. What Data We Collect

We take data minimisation seriously. Here is everything we collect — nothing is hidden:

2.1 When You Take the Quiz

DataWhy We Collect ItRequired?
Your quiz answers and responsesTo generate your personalised career assessment resultsYes — the quiz cannot function without this
Anonymous session ID (randomly generated)To associate your answers with your results during the sessionYes — generated automatically, not linked to your identity
Basic analytics (pages visited, time spent, general region)To understand how people use the site so we can improve itYes — anonymised, no personal identifiers

We do not collect your name, age, location, phone number, or any form of payment information at the quiz stage.

2.2 If You Voluntarily Provide Your Email Address

If you choose to receive your quiz results by email, or sign up to our waitlist for future features:

DataWhy We Collect ItRequired?
Email addressTo send you your results, or to notify you of new featuresOnly if you choose to provide it
Feature preferences (waitlist)To understand which features matter most to our usersOnly if you choose to provide it

Providing your email is entirely optional. The quiz works fully without it.

2.3 If You Submit Feedback

If you choose to complete any optional post-quiz feedback:

DataWhy We Collect It
Your written feedbackTo improve the quiz and our service

Feedback submission is always optional.

3. What We Do Not Collect

We want to be explicit about what we do not collect:

  • Your name
  • Your age or date of birth
  • Your precise location or IP address (beyond general regional analytics)
  • Payment or financial information
  • Your device fingerprint or persistent tracking identifiers
  • Your social media profiles or login credentials
  • Any data from third-party sources about you

4. How We Use Your Data

We use your data only for the purposes described below. We do not use your data for advertising, profiling, or selling to third parties — ever.

PurposeLawful Basis (UK GDPR)
Generating your AI-powered career recommendations from your quiz responsesLegitimate interest — this is the core function of the service
Sending your results to your email addressConsent — you actively choose to provide your email
Notifying you of new features via waitlistConsent — you actively choose to sign up
Improving our quiz using anonymised, aggregated analyticsLegitimate interest — improving a free service

5. How AI Processing Works

Your quiz responses are processed in real-time by Claude, an AI model developed by Anthropic, to generate your personalised career recommendations.

Here is exactly how this works:

  • Your responses are sent to Anthropic's API for processing
  • No personally identifying information is included in what is sent to the AI — only your anonymised quiz answers
  • The AI does not retain your data after processing is complete
  • We do not store AI conversation logs beyond your session results
  • Anthropic processes data in accordance with their own privacy policy and data processing agreements

By using our quiz, you consent to your anonymised quiz responses being processed by Anthropic's AI to generate your results.

For more information about how Anthropic handles data, see: anthropic.com/privacy

6. Cookies and Analytics

6.1 Analytics

We use Google Analytics to understand how visitors use our website. This collects anonymised information such as:

  • Pages visited and time spent on each page
  • Approximate geographic region (country/region level only, not precise location)
  • Device type and browser used
  • How you arrived at our website

Google Analytics does not collect your name, email address, or any information that identifies you personally. Data is aggregated and anonymised.

You can opt out of Google Analytics tracking at any time by installing the Google Analytics Opt-out Browser Add-on.

6.2 Cookies

We use only the cookies necessary to make the website function correctly and to support our analytics. We do not use advertising cookies, tracking pixels, or third-party marketing cookies.

A cookie notice is displayed when you first visit the website. You can manage your cookie preferences at any time through your browser settings.

7. Who We Share Your Data With

We do not sell, rent, or trade your personal data to any third parties.

We only share data with the following service providers, strictly as necessary for the service to function:

Service ProviderPurposeData Shared
AnthropicAI processing to generate career recommendationsAnonymised quiz responses only — no personal identifiers
ResendSending your results to your email addressYour email address, only if you provide it
Google AnalyticsAnonymised website analyticsAnonymised usage data only

Each of these providers operates under their own privacy policies and data processing agreements. We have assessed each provider for data protection compliance before using their services.

8. Your Rights Under UK GDPR

If you are based in the United Kingdom, you have the following rights over your personal data:

RightWhat It Means
Right of accessYou can request a copy of the personal data we hold about you
Right to rectificationYou can ask us to correct any inaccurate personal data
Right to erasureYou can ask us to delete your personal data ("right to be forgotten")
Right to restrictionYou can ask us to restrict how we process your data in certain circumstances
Right to portabilityYou can request your personal data in a structured, machine-readable format
Right to objectYou can object to processing based on legitimate interests
Right to withdraw consentWhere processing is based on your consent, you can withdraw it at any time

To exercise any of these rights, contact us at info@yourcyberbuddy.co.uk. We will respond within 30 days, as required by law.

If you are unsatisfied with how we handle your request, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

9. Data Retention — How Long We Keep Your Data

Data TypeRetention Period
Anonymised quiz session dataUp to 12 months, for service improvement purposes
Email addresses (results delivery)Until you request removal, or 12 months after last interaction
Email addresses (waitlist signups)Until you unsubscribe or request removal
Optional feedback submissionsUp to 12 months, anonymised after 3 months
Anonymised analytics dataAs per Google Analytics standard retention settings

You may request deletion of your personal data at any time by contacting info@yourcyberbuddy.co.uk. We will process deletion requests within 30 days.

10. Data Security

We take the security of your data seriously. Our measures include:

  • Data stored on secure, encrypted servers
  • Industry-standard encryption for data in transit (HTTPS/TLS)
  • Quiz responses are stored with a randomly generated session ID — not linked to any personal identity unless you voluntarily provide your email
  • Access to personal data is restricted to those who need it to operate the service
  • Regular review of our security practices as the service evolves

While we take all reasonable steps to protect your data, no internet transmission or storage system is 100% secure. If you have concerns about data security, please contact us.

11. International Data Transfers

Our primary service operates within the United Kingdom. However, some of our third-party providers (including Anthropic and Google) may process data outside the UK.

Where data is transferred internationally, we ensure that appropriate safeguards are in place in accordance with UK GDPR requirements — including standard contractual clauses or adequacy decisions where applicable.

12. Children's Privacy

Our service is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us with personal data, please contact us immediately at info@yourcyberbuddy.co.uk and we will take steps to delete that information.

Users aged 13–17 are welcome to use the service with parental awareness. We do not knowingly use data from users under 16 for any profiling purposes.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time as our service evolves. When we make changes, we will:

  • Update the "Last updated" date at the top of this page
  • Post the revised policy on this page

We encourage you to review this page periodically. Where changes are material, we will make reasonable efforts to draw them to your attention. Your continued use of the service after changes are posted constitutes your acceptance of the updated policy.

14. Contact Us

For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact:

We aim to respond to all privacy-related enquiries within 5 working days and to fulfil all data rights requests within 30 days, as required under UK GDPR.