Privacy Policy

Last Updated: September 5, 2026

This Privacy Notice explains how Ivy Cyber LLC (“Ivy Cyber”, “we”, “our”, “us”) collects, uses, shares, protects, and retains Personal Data when you use ivycyber.com, the Ivy Cyber shop and checkout, cryptopay.ivycyber.com, our Learning Commons, and other commercial products, software services, classes, consulting services, support channels, and hardware offerings that link to this Notice.

By using an Ivy Cyber service, you acknowledge that you have read and understand this Privacy Notice. Our Terms of Service and Community Guidelines also apply where relevant.

TLDR: Privacy is our goal

We build software, products, and services that are designed to collect as little information as feasible for the context in which they are used.

For example, you can download and install our PrivacySafe applications without giving us your name, email address, phone number, or other account information. If you want to reduce network-level exposure, you can use a trustworthy VPN or an anonymity network such as Tor or I2P. We can help you with these methods and we operate Tor .onion services for many resources.

In general, you volunteer information only when it is needed: when buying a product, subscribing to a service, enrolling in a class, requesting consulting, opening a support request, shipping hardware, or otherwise asking us to provide something that requires identifying or transactional information. When information is required, we aim to provide multiple options so that you can make an informed choice. That includes multiple payment options such as cryptocurrency, as well as addon services such as shipping with tamper-evident packaging.

Our PrivacySafe projects are 100% Free/Libre and Open Source Software (FLOSS) and can be self-hosted, so you can deploy on your infrastructure. If you choose to host with us, additional service-specific terms may apply. Depending on the service and arrangement, we host or support services in Canada, the United States, and Iceland (EEA), and we can discuss which jurisdiction may make the most sense for your privacy and operational needs.

Privacy is central to how we design our technology and run our organizations. Our founder is a privacy and cybersecurity expert, and we have built our work and professional reputations around privacy-by-design principles. If you have questions about our privacy practices, contact privacy@ivycyber.com.


Table of Contents

  1. Introduction and Scope
  2. What is Personal Data?
  3. Third-Party Services
  4. Personal Data We Collect
  5. Cookies and Website Metrics
  6. How We Use Personal Data
  7. How We Share Personal Data
  8. Payments and Cryptocurrency
  9. PrivacySafe Commercial Services
  10. Learning Commons
  11. Affiliate Program
  12. International Data Transfers and Hosting
  13. Your Privacy Choices and Rights
  14. Retention of Personal Data
  15. Supplemental Notice for Certain Jurisdictions
  16. Security and Breach Response
  17. Children’s Personal Information
  18. GDPR Impact Assessment and Legitimate Interests Assessment
  19. Contact Us

1. Introduction and Scope

Ivy Cyber is a Connecticut limited liability company that sells and supports software services, software products and digital educational products, consulting and professional services, and hardware products. This Notice applies to Ivy Cyber’s commercial websites and services, including the Ivy Cyber shop and our privacy-oriented cryptocurrency checkout.

This Notice does not govern the public-interest services operated by PrivacySafe Foundation, Inc., including PrivacySafe Social, PrivacySafe Search, PrivacySafe Bot, and PrivacySafe Locker. Those services are covered by the Foundation’s Privacy Notice and, where applicable, service-specific notices. Ivy Cyber may provide technical, hosting, infrastructure, security, administrative, and support services to the Foundation without thereby becoming the owner of Foundation services, funds, or Foundation-controlled cryptocurrency wallets.

2. What is Personal Data?

Personal Data” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked directly or indirectly with a person or household, where that definition applies under relevant law.

Deidentified, aggregated, or anonymized information that cannot reasonably be linked to an identifiable person is not treated as Personal Data to the extent permitted by applicable law. Where we maintain information in deidentified form, we do not attempt to reidentify it except as permitted or required by law.

3. Third-Party Services

Our services may contain links to or interact with third-party websites, applications, payment services, financial networks, shipping carriers, embedded media, or other resources. Their privacy practices apply when you choose to use them. We try to minimize third-party scripts and avoid advertising trackers, but we do not control independent third parties.

4. Personal Data We Collect

Depending on how you interact with Ivy Cyber, we may collect or process the following categories of Personal Data:

  • Account and contact information: name, username, email address, telephone number, organization, mailing or billing address, and account credentials.
  • Order and subscription information: products or services ordered, order identifiers, amounts, discounts, billing status, subscription status, shipping details, tax information, and customer-service history.
  • Payment-related information: payment method, processor-generated identifiers, transaction status, and limited payment metadata. We do not intentionally store full card numbers or bank-account credentials on Ivy Cyber servers.
  • Cryptocurrency information: invoice identifiers, wallet addresses, transaction hashes, network, asset, amount, memo or order designation, and information you provide to associate a payment with an order.
  • Learning Commons information: registration or enrollment information, coursework, submissions, discussion content, attendance or participation records, instructor communications, and related administrative records where our courses use these features.
  • Consulting and support information: information you provide in requests, tickets, contracts, project documents, technical materials, or correspondence.
  • Affiliate information: name, email, username or display name, country or region, payout information, referral metrics, coupon use, and commission records.
  • Technical and security information: IP address, browser or application information, device and session information, authentication events, server logs, error records, security signals, and information needed to detect fraud, abuse, or attacks.
  • Approximate geographic information: regional information derived from IP addresses using locally maintained geographic databases for storefront functionality, diagnostics, fraud prevention, and high-level metrics.
  • Communications: messages sent to Ivy Cyber through email, forms, support systems, social media, or other channels.

We collect Personal Data directly from you, automatically from your browser or device, from service providers that process a transaction or requested service, and from other sources you direct to provide information to us.

5. Cookies and Website Metrics

Ivy Cyber uses cookies and local storage where needed for account authentication, security, shopping and checkout functions, preferences, subscriptions, and affiliate attribution. We do not use advertising cookies or cross-site behavioral advertising trackers.

High-level website metrics may be collected through our self-hosted privacy-oriented metrics service at privacysafe.click. We use these metrics to understand aggregate traffic and site reliability, not to build advertising profiles. We may use the static MaxMind GeoLite database locally to perform approximate regional lookups. We do not use GeoLite to build behavioral profiles of individual visitors.

Affiliate referral links may set a temporary first-party cookie used to apply a coupon or attribute a completed purchase to an affiliate. We design affiliate reporting so affiliates do not receive customer names, email addresses, IP addresses, detailed product lists, or other unnecessary customer information.

6. How We Use Personal Data

We use Personal Data only for reasonably necessary business and operational purposes, including to:

  • provide, sell, license, deliver, host, configure, or support products and services;
  • create and administer accounts, subscriptions, enrollments, orders, and customer relationships;
  • process payments, refunds, chargebacks, cryptocurrency invoices, and accounting records;
  • ship hardware and handle warranty, repair, and return requests;
  • operate the Learning Commons and communicate about classes, coursework, and educational services;
  • provide consulting and professional services;
  • administer the Affiliate Program and calculate commissions;
  • authenticate users, prevent fraud and abuse, secure systems, diagnose errors, and respond to security incidents;
  • comply with tax, accounting, consumer-protection, sanctions, export, legal-process, and other legal obligations;
  • establish, exercise, or defend legal claims; and
  • improve the reliability, accessibility, and usability of our services using privacy-respecting operational information.

We do not sell Personal Data, use Personal Data for targeted advertising, or use Personal Data for profiling that produces legal or similarly significant effects.

7. How We Share Personal Data

We disclose Personal Data only as reasonably necessary for the purposes described in this Notice. Recipients may include:

  • payment and financial-service providers selected at checkout;
  • hosting, infrastructure, email, support, shipping, fulfillment, and security providers;
  • professional advisers such as accountants, auditors, and legal counsel;
  • government authorities or other parties when disclosure is required by law or reasonably necessary to protect rights, users, systems, or safety; and
  • another party in connection with a merger, financing, reorganization, sale of assets, or similar business transaction, subject to applicable law.

We do not disclose customer Personal Data to affiliates for their own marketing. Affiliate dashboards are limited to the information reasonably necessary to administer commissions.

8. Payments and Cryptocurrency

Ivy Cyber accepts conventional payments through providers presented at checkout. These may include Stripe for card payments and supported bank or ACH/direct-debit methods, and PayPal or Venmo where offered. The selected provider processes payment credentials under its own privacy notice and terms. We intentionally keep this Notice focused on providers we actually use rather than listing every card brand, bank network, wallet, or payment feature a provider may support.

Ivy Cyber also accepts cryptocurrency. A regular Ivy Cyber checkout may generate an invoice that asks the customer to send funds directly to an Ivy Cyber-controlled wallet using the displayed address or QR code. Assets offered through this route may include Bitcoin, Dogecoin, Ethereum, Litecoin, Monero, Solana, Tether on Ethereum, and USD Coin, depending on what is displayed at checkout. Because this payment is part of an ordinary commercial order, the transaction may remain associated with the customer, invoice, or order record.

Customers may also use our self-hosted BTCPay Server for a more privacy-preserving cryptocurrency checkout. We may offer Bitcoin over the Lightning Network, Monero, Litecoin, and Dogecoin through that service. BTCPay reduces reliance on conventional payment processors, but we do not promise anonymity: privacy depends on the asset, network, wallet behavior, information already supplied to Ivy Cyber, and other circumstances.

Bitcoin Lightning payments may also be arranged through Radar.chat at ivycyber@radar.cash. Other cryptocurrency arrangements may be available by agreement. Cryptocurrency transactions are generally irreversible. Customers are responsible for confirming the correct asset, network, address, amount, and invoice before sending funds.

9. PrivacySafe Commercial Services

Ivy Cyber publishes and supports commercial PrivacySafe offerings. Current identity tiers may include free Silver identities at @privacysafe.xyz, Gold identities at @privacysafe.me, Platinum identities at @privacysafe.gg, and enterprise deployments using an approved customer domain.

PrivacySafe is designed around user-held cryptographic keys and zero-knowledge storage principles. Where a PrivacySafe component is end-to-end encrypted and only the user controls the relevant private keys, Ivy Cyber cannot decrypt the protected content. Operational metadata, account records, billing records, service logs, or information outside an encrypted content envelope may still be processed as described in this Notice.

Depending on the plan and deployment, synchronized paid-plan storage may be hosted in Ontario, Canada, or another contracted region. Enterprise deployments may use the United States, Iceland or another EEA location, or another agreed region. The applicable order, enterprise agreement, or deployment documentation controls where it provides more specific information.

10. Learning Commons

Ivy Cyber may offer online classes, asynchronous courses, workshops, live sessions, downloadable educational products, and related learning activities through a Learning Commons environment. The exact platform or hostname may change over time.

We use Learning Commons Personal Data to administer enrollment, deliver course material, facilitate discussions, evaluate submissions, communicate with participants, protect the integrity of the learning environment, and provide support. Participants must also follow our Community Guidelines.

11. Affiliate Program

Approved affiliates may receive referral links or coupon codes and may receive commissions or other incentives for eligible referred purchases. Affiliate accounts may require a name, email address, username or display name, country or region, and payout information.

Affiliate dashboards are designed to minimize customer-data exposure. Affiliates may receive limited information such as a randomized referral or order identifier, order date, eligible order value, discount amount, refund or cancellation status, and commission information. Affiliates do not receive customer names, customer email addresses, IP addresses, detailed product lists, or device metadata through the ordinary affiliate dashboard.

12. International Data Transfers and Hosting

Ivy Cyber operates from the United States and may process Personal Data in the United States, Canada, the European Economic Area, and other jurisdictions where a customer or service arrangement requires it. Information processed in another jurisdiction may be subject to lawful access by courts, law-enforcement, or national-security authorities there.

Where the GDPR or UK GDPR applies to a transfer outside the EEA or United Kingdom, we use an applicable legal transfer mechanism where required, such as an adequacy decision, standard contractual clauses, or another permitted safeguard.

13. Your Privacy Choices and Rights

Depending on where you live and the law that applies, you may have rights to:

  • confirm whether we process your Personal Data;
  • access Personal Data we hold about you;
  • correct inaccurate Personal Data;
  • delete Personal Data, subject to legal exceptions;
  • restrict or object to certain processing;
  • receive certain Personal Data in a portable format;
  • withdraw consent where processing is based on consent;
  • opt out of covered sale, targeted advertising, or significant-effect profiling; and
  • appeal a denied request where applicable law provides an appeal right.

Submit privacy requests to privacy@ivycyber.com. We may need to verify a request before acting on it. We will respond within the timeframe required by applicable law.

14. Retention of Personal Data

We retain Personal Data for no longer than reasonably necessary for the purpose for which it was collected, including fulfillment, customer support, security, fraud prevention, accounting, tax, warranty, contract, dispute, and legal requirements. Retention differs by record type.

  • Server and security logs: ordinarily rotated on a short operational schedule; some may be retained longer when needed for an active incident, abuse investigation, or legal requirement.
  • Order, subscription, payment, tax, and accounting records: retained as required for business records, tax, accounting, fraud prevention, chargebacks, and legal obligations.
  • Support and consulting records: retained while needed to provide the service, document work performed, resolve disputes, maintain security, or satisfy contractual and legal requirements.
  • Learning Commons records: retained according to the course, enrollment, educational, contractual, and legal needs of the program.
  • Affiliate records: retained for commission administration, accounting, fraud prevention, and legal obligations.

Backups may persist for a limited rotation period after information is deleted from production systems.

15. Supplemental Notice for Certain Jurisdictions

United States State Privacy Laws

Where a state comprehensive privacy law applies to Ivy Cyber, this section supplements the rest of this Notice. We do not sell Personal Data, use Personal Data for targeted advertising, or use Personal Data for profiling that produces legal or similarly significant effects.

Connecticut

Where the Connecticut Data Privacy Act (“CTDPA”) applies, Connecticut residents may have rights to access, correct, delete, and obtain a portable copy of Personal Data, and to opt out of covered sale, targeted advertising, and significant-effect profiling. Connecticut law also provides an appeal process for certain denied requests. We honor a valid universal opt-out preference signal, such as Global Privacy Control, where the CTDPA or another applicable law requires it. Ivy Cyber does not use dark patterns to obtain consent for covered processing.

California

Where the California Consumer Privacy Act, as amended, applies, California residents may have rights to know, access, correct, delete, and receive information about categories of Personal Data collected or disclosed, and to opt out of covered sale or sharing. Ivy Cyber does not sell Personal Data or share Personal Data for cross-context behavioral advertising.

EU and UK GDPR

Where the EU GDPR or UK GDPR applies, Ivy Cyber acts as a controller for the Personal Data described in this Notice unless a specific contract states otherwise. We process Personal Data on one or more of these legal bases:

  • Performance of a contract: where processing is necessary to provide a product, service, subscription, class, consulting engagement, account, or support service you requested.
  • Legitimate interests: where necessary to operate, secure, maintain, improve, and protect our business and services, prevent fraud and abuse, administer customer and affiliate relationships, and establish or defend legal claims, provided those interests are not overridden by your rights and freedoms.
  • Legal obligation: where processing is required for tax, accounting, consumer, sanctions, export, legal-process, security, or other legal obligations.
  • Consent: where we specifically ask for consent and consent is the appropriate legal basis.

You may also have the right to lodge a complaint with the data-protection authority in the country where you live or work, or where you believe a violation occurred.

Canada

Where Canada’s Personal Information Protection and Electronic Documents Act (“PIPEDA”) applies to Ivy Cyber’s commercial activities, we use Personal Data for identified and appropriate purposes, limit collection and retention to what is reasonably necessary, use safeguards appropriate to the sensitivity of the information, and provide access and correction rights as required by law.

Some PrivacySafe synchronized storage may be processed in Ontario, Canada through 3NSoft or another contracted infrastructure arrangement. Personal Data may also be processed outside Canada. When a service provider processes Personal Data on our behalf, we remain responsible for using appropriate contractual and organizational measures and for providing appropriate transparency about cross-border processing. Information processed in another country may be subject to lawful access under that country’s laws.

16. Security and Breach Response

We use technical and organizational safeguards designed for the nature of the information and service, including TLS in transit, access controls, cryptographic protections, system hardening, security monitoring, staff practices, and data minimization. No system can be guaranteed perfectly secure.

Security vulnerabilities should be reported through our Vulnerability Disclosure Policy and Bug Bounty Program or to security@privacysafe.net. For sensitive reports, use the published GPG key.

If a security incident triggers notification or reporting obligations under applicable law, we will provide required notices within the applicable timeframe.

17. Children’s Personal Information

Ivy Cyber’s commercial services are not directed to children under 13, and we do not knowingly solicit Personal Data from children under 13 through our commercial websites. Some products, classes, or services may have a higher minimum age stated at registration or in program materials. If we learn that Personal Data was collected in violation of an applicable child-privacy law, we will take appropriate steps to address it.

18. GDPR Impact Assessment and Legitimate Interests Assessment

This section documents Ivy Cyber’s current high-level screening of privacy risks and legitimate-interest processing. It is not a substitute for a project-specific Data Protection Impact Assessment (“DPIA”) when Article 35 of the GDPR or another applicable law requires one.

Processing Reviewed

  • account authentication and customer administration;
  • orders, subscriptions, payments, shipping, returns, and warranties;
  • Learning Commons administration and educational records;
  • affiliate attribution and commission administration;
  • support, consulting, and customer communications;
  • security logging, fraud prevention, and incident response;
  • privacy-respecting aggregate website metrics; and
  • encrypted PrivacySafe service operations and associated metadata.

Purpose and Necessity

The processing above supports delivery of requested products and services, secure operation, customer support, accounting, fraud prevention, legal compliance, and maintenance of business systems. Ivy Cyber seeks to minimize collection and use less intrusive means where reasonably available, including self-hosted metrics, limited affiliate data, zero-knowledge encryption, and direct cryptocurrency options.

Legitimate Interests and Balancing

Our legitimate interests include securing systems, preventing abuse and fraud, maintaining service reliability, administering customer and affiliate relationships, responding to inquiries, and protecting legal rights. We balance these interests against the rights and expectations of the people whose Personal Data is processed. Safeguards include purpose limitation, access controls, retention limits, encryption where appropriate, restricted third-party disclosure, user rights, and avoidance of behavioral advertising.

DPIA Screening

Based on the processing described in this Notice, we do not treat this general assessment as a permanent conclusion that a DPIA is unnecessary. New or materially changed processing involving systematic monitoring, large-scale sensitive data, biometrics, high-risk profiling, new technologies, or another likely high risk to individuals must be screened separately and a DPIA completed when required.

Review

We review this assessment when our services, providers, technologies, data practices, or legal obligations materially change.

19. Contact Us

Ivy Cyber LLC
1204 Main St Num 1197
Branford, CT 06405-3787 USA
+1 (929) 748-7233
privacy@ivycyber.com