All apps

Is Cyera safe with your data?

D
Cyera icon

Cyera

Cyera Inc.

44/100

Weak disclosure · high confidence

Cyera earns a D (44/100) because it leaves much about its data practices unstated.

#142

of 211 apps ranked

44

score · Security & compliance avg 48

-4

vs category average

Grade scaleA · 70–100B · 60–69C · 48–59D · 35–47F · 0–34

Cyera publishes a detailed GDPR-style marketing and platform privacy policy with named sub-processors and transfer safeguards, but it is silent on AI training, AI interaction disclosure, and breach notification, and its data subject rights are gated to residents of listed jurisdictions.

What Cyera's privacy policy and terms of service say about your data

Named sub-processors and transfer safeguards

The policy enumerates specific recipients per use case (Salesforce, Marketo, Frontegg, Mixpanel, Datadog, ZoomInfo) and names Adequacy Decisions, Standard Contractual Clauses and the EU-U.S. Data Privacy Framework as transfer mechanisms.

Rights are jurisdiction-gated, not universal

Access, deletion, portability and correction are introduced as rights that "shall apply to certain individuals" in the EU/UK and a listed set of U.S. states, each subject to exemptions, so the global default user is not clearly covered.

No AI or training disclosure at all

Neither the privacy policy nor the terms page mentions model training, AI interaction, output ownership, or AI log retention; the customer terms are behind a gated trust center login.

Security and breach handling are thin

Security is described only as "a variety of technical, organizational and security measures" with no named control, and there is no breach notification commitment or named certification anywhere in the text.

What the policy is silent or vague on

  • Not stated: keeping user inputs out of model training
  • Not stated: a way to opt out of training
  • Not stated: whether training use differs by plan
  • Not stated: your ownership of generated outputs

Cyera privacy rating

Training-data use0 of 4 disclosed
Keeps user inputs out of model training, or makes training opt-inSilent
Names a way to opt out of or into trainingSilent
Says whether training use differs by plan or tierSilent
Lets the user keep ownership of generated outputsSilent
Data-subject rights1 of 5 disclosed
Grants a right to access your dataPartial
Grants a right to delete your dataPartial
Offers data portability in a usable formatPartial
Grants a right to correct your dataPartial
Grants a way to object to or opt out of processingDisclosed
Retention and deletion0 of 4 disclosed
States a retention period for your dataPartial
States a deletion timeline after closure or requestSilent
Sets a shorter retention for AI conversation logsSilent
Commits to collecting only the data it needsPartial
Third-party sharing3 of 5 disclosed
Lists the categories of third parties it shares withDisclosed
References a sub-processor list or data processing agreementDisclosed
Does not sell or share data for advertising, or offers opt-outPartial
Names a safeguard for international data transfersDisclosed
States a standard for government and law-enforcement accessPartial
Transparency2 of 4 disclosed
Discloses that you are interacting with AISilent
Marks AI-generated or synthetic outputNot applicable
Enumerates the categories of data it collectsDisclosed
Maps processing purposes to legal basesDisclosed
Is versioned and dated, with change noticePartial
Sensitive data and children1 of 3 disclosed
Discloses automated decisions and a human-review pathPartial
Limits the use of special-category dataPartial
Governs biometric data specificallyNot applicable
States protections for children's dataDisclosed
Security and accountability1 of 3 disclosed
Describes its security safeguardsPartial
Commits to breach notificationSilent
Names a certification or a privacy contactDisclosed
DisclosedPartialSilentAdverseNot applicable

Details

Category
Security & compliance
Modalities
text
Processes biometrics
No
Policy last updated
February 12, 2026
Region scored
Global / US-default
Last assessed
2026-08-13

Documents examined

Other security & compliance apps

Each grade reflects our analysis of what an app states in its public privacy policy and terms as of the assessment date. It measures the transparency of those documents, not the company's actual data practices, security, or compliance. Grades are our opinion, offered for general information. Full disclaimer.

Is Cyera safe with your data? Grade D | AI App Trust & Transparency Index