Last updated: 1 June 2026

Privacy Policy

CyberSage Ltd, operating Sage Vault ("we", "our", "us"), is committed to protecting your personal information. This policy explains what data we collect, how we use it, and your rights.

1. Data We Collect

We collect the following categories of data when you use Sage Vault:

  • Account data: Email address, display name, role (Student / Instructor / Recruiter), university, profile fields you choose to fill in (bio, skills, CV URL, LinkedIn, GitHub, company, job title).
  • Activity data: Lab attempts and progress, simulation session events, learning path progress, competition entries, leaderboard scores.
  • Simulation data: Decisions made during simulations, timing, scores, and the generated company/scenario context for each session.
  • Classroom data: Classroom enrollments, lab assignments, instructor-posted announcements.
  • Payment data: Stripe customer ID and subscription status. We do not store card numbers — all payment processing is handled by Stripe.
  • Technical data: Session token cookie set by NextAuth (our authentication provider) and two httpOnly cookies we set for role and onboarding state.

2. How We Use Your Data

  • Provide and operate the Sage Vault platform
  • Generate your skill profile, certificates, and debrief reports
  • Allow instructors to track student progress in their classrooms
  • Allow recruiters to browse simulation-assessed candidate profiles (only with your consent via public profile settings)
  • Send transactional emails (welcome, classroom join confirmations, certificate notifications)
  • Process subscription payments via Stripe
  • Improve the platform through aggregated, anonymised analytics

3. Data Sharing

We do not sell your personal data. We share data only with:

  • Google / GitHub — OAuth sign-in via NextAuth
  • Stripe — payment processing for paid subscriptions
  • Resend — transactional email delivery
  • Supabase / Neon — PostgreSQL database hosting
  • Vercel — application hosting and edge functions
  • OpenAI — generation of AI debrief reports (your scenario context is sent; no PII is included in prompts)

Recruiters with an Enterprise plan can view your public simulation profile only if your profile is set to visible. Simulation scores and certificates are not shared without your action.

4. Data Retention

  • Active accounts: Data is retained for the lifetime of your account.
  • Deleted accounts: Personal data is deleted within 30 days of account deletion. Anonymised aggregate analytics may be retained indefinitely.
  • Simulation events: Session event logs are retained to power debriefs, certificates, and verification. They are deleted when you delete your account.
  • Payment records: Stripe retains billing records as required by financial regulations (typically 7 years).

5. Your Rights

Under GDPR and UK data protection law, you have the right to:

  • Access a copy of the data we hold about you
  • Correct inaccurate data
  • Request deletion of your account and associated data
  • Object to processing for marketing purposes
  • Data portability (export your profile and simulation history)

To exercise any of these rights, email us at support@cybersage.uk. We will respond within 30 days.

6. Cookies

We use the following cookies:

  • next-auth.session-token — Authentication session. Required for login.
  • sage_onboarded — Whether you've completed onboarding. httpOnly, expires in 1 year.
  • sage_role — Your current role for edge routing. httpOnly, expires in 1 year.

We do not use advertising cookies or third-party tracking.

7. Security

All data is transmitted over HTTPS. Authentication is handled via NextAuth with industry-standard JWT tokens. Database access is restricted to application servers. Simulation sessions are isolated per user. We conduct periodic security reviews and address vulnerabilities promptly.

8. Contact

For privacy questions or data requests, contact us at support@cybersage.uk.