CYPHER
Privacy Policy

What we do with your data.

Last updated: April 23, 2026

This is the short version: we store the minimum needed to run the product, we don't sell it, and we don't track you across the rest of the web. The long version is below.

1. Who we are

CYPHER is operated from cyphertheculture.com. If you need to reach us about privacy, email privacy@cyphertheculture.com.

2. What we collect

When you visit

Our infrastructure providers (Vercel for hosting, Cloudflare for DNS) receive your IP address and user agent string as part of any normal web request. We use these transiently for rate-limiting (to stop abuse) and for serving the page. We don't build a long-term log of your visits.

When you sign up

We store your email address. That's it. We don't ask for your name, phone, address, or birthday. Authentication is passwordless — we email you a one-time magic link, and Supabase (our auth provider) holds the session token.

When you use the product

If you run a Deep Rabbit Search, we log that it happened (timestamp, user id, and a counter) so we can enforce the free-tier 1-per-day limit. We don't log the text of your query against your account in a way that's queryable by us — search inputs are used to answer the request and flushed.

If you pick a preferred listening platform (YouTube, Apple Podcasts, Spotify, Overcast) we save that choice on your account so the "Listen On" buttons work how you want.

When you pay

Stripe handles payment. We never see your card number. We store the Stripe customer id and subscription status so we know who has Pass access. Stripe has its own privacy policy that governs the payment data itself — see stripe.com/privacy.

What we don't collect

No third-party analytics cookies. No Google Analytics. No Facebook pixel. No advertising trackers. No browser fingerprinting for ad targeting. No session replay.

3. Who we share it with

We share data only with the service providers needed to run CYPHER:

  • Supabase — database + auth. Your email, account id, and usage counters live here.
  • Vercel — hosting. Server logs with IPs pass through here.
  • Stripe — payments (Pass subscribers only).
  • Resend — sending transactional email (magic links).
  • YouTube Data API — we query YouTube for public video metadata. YouTube does not receive any data about who specifically queried.

We do not sell, rent, or trade your data. We do not share it with advertisers. We will share it with law enforcement only when compelled by valid legal process and only the minimum that the process requires.

4. Cookies

We use one category of cookie: the session cookie set by Supabase Auth after you sign in. It is HttpOnly and Secure, it lets us know you're signed in on return visits, and it expires when you sign out or after a defined period. No advertising cookies. No cross-site tracking cookies.

5. Your rights

You can:

  • Export your data — email privacy@cyphertheculture.com and we'll send you everything we have tied to your account, typically within 7 days.
  • Delete your account — email privacy@cyphertheculture.com. We'll delete your user row, listening preference, quota counter, and any saved collections. If you had an active Pass subscription, we'll cancel it. Stripe and our logging infrastructure may retain anonymized records as required by law (typically 7 years for payment records).
  • Correct anything wrong — for email changes, reach out the same way.
  • Opt out of processing — by deleting your account, since we don't do processing beyond what's required to run the product.

If you're in the EU/UK, these map to your GDPR rights (access, rectification, erasure, portability, objection). If you're in California, these satisfy your CCPA rights.

6. Children

CYPHER is not directed at children under 13 and we don't knowingly collect data from them. If you believe a child has created an account, email privacy@cyphertheculture.com and we'll remove it.

7. Security

Passwords don't exist here — we only use magic-link sign-in, so there's no password to leak. All data in transit is TLS encrypted. Database access is restricted with row-level security policies (you can't read another user's data, even if the app had a bug). Payment data is handled entirely by Stripe and never touches our servers.

If we ever have a data incident that affects you, we'll notify you by email within 72 hours of becoming aware of it.

8. International users

Our infrastructure is primarily in the United States. By using CYPHER you consent to your data being processed in the US. We apply the same privacy standard to all users regardless of location.

9. Changes to this policy

If we make a meaningful change we'll post the new version here with an updated date, and if the change materially expands what we collect or who we share with, we'll notify signed-in users by email before the change takes effect.

10. Contact

Privacy questions: privacy@cyphertheculture.com
General support: support@cyphertheculture.com

← Back to CYPHER · Terms of Service