Privacy Policy
Last updated: May 2026
Who We Are
CrownWell Labs LLC ("CrownWell Labs", "Cyfirx", "we", "us", or "our") operates cyfirx.com and the Cyfirx desktop application. This Privacy Policy describes how we collect, use, store, and protect your personal information when you use our website or services.
Information We Collect
We collect information you provide directly to us:
- Account information — name, email address, company or organization name
- Payment information — billing is handled entirely by Paddle.com (our Merchant of Record); we do not store or process card numbers or payment credentials
- Contact and support communications — messages you send via our contact form or to our support email
- License and subscription records — your subscription tier, license key, and billing history (provided to us by Paddle)
We also collect limited technical data automatically: IP address, browser type and version, pages visited on cyfirx.com, and referring URLs. This is used solely for security monitoring and to improve the website.
Desktop Application & Forensic Data
Cyfirx Desktop operates entirely offline. Your forensic case data, evidence files, analysis results, and investigation notes remain exclusively on your local machine. This data is never transmitted to our servers.
If you use the cloud sync feature (available on Professional and Enterprise plans), case metadata and findings are encrypted in transit and stored securely on our servers solely to enable access from the web portal. You can disable cloud sync at any time from your account settings, which stops all future uploads and allows you to request deletion of any previously synced data.
How We Use Your Information
We use collected information to:
- Create and manage your Cyfirx account and license
- Deliver and improve our software and services
- Process your subscription and communicate billing-related information
- Respond to support requests and customer inquiries
- Send important notices about your account, security updates, or changes to our services
- Detect, investigate, and prevent fraudulent or unauthorized activity
- Comply with legal obligations
We do not sell your personal information to third parties. We do not use your data for advertising purposes.
Payment Processing (Paddle)
All Cyfirx payments are processed by Paddle.com, which serves as our Merchant of Record. When you subscribe, your payment details are submitted directly to Paddle and are governed by Paddle's Privacy Policy.
Paddle provides us with transaction records (order ID, subscription status, amount, country) for billing and tax compliance. We do not receive or store your card number, CVV, or full payment credentials.
Third-Party Services
We use a limited number of trusted third-party services:
- Paddle — payment processing and subscription management
- Cloudflare — DNS, CDN, and security (DDoS protection, WAF)
- Email provider — transactional emails (account verification, receipts, support replies)
We do not use Google Analytics, Facebook Pixel, or other third-party tracking or advertising scripts.
Cookies
cyfirx.com uses only essential cookies required for session management (keeping you logged in to the dashboard) and security. We do not use tracking, analytics, or advertising cookies. No third-party cookies are set by our website.
Data Retention
We retain account information for the duration of your account and for a reasonable period thereafter to comply with legal obligations or resolve disputes. Support communications are retained for 2 years. If you request account deletion, we will remove your personal data within 30 days, subject to any legal retention requirements.
Data Security
We implement industry-standard security measures including encrypted communications (HTTPS/TLS), server-side access controls, and regular security reviews. Passwords are stored as salted hashes; we never store plaintext passwords. No method of transmission or storage is 100% secure — we cannot guarantee absolute security, but we take reasonable precautions to protect your information.
Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you
- Rectification — request correction of inaccurate or incomplete data
- Erasure — request deletion of your personal data (subject to legal obligations)
- Restriction — request that we restrict processing of your data in certain circumstances
- Portability — receive your data in a structured, machine-readable format
- Objection — object to certain types of processing
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
International Transfers
Your information may be processed in the United States or other countries where we or our service providers operate. We take appropriate steps to ensure that transfers are conducted in compliance with applicable data protection laws.
Children's Privacy
Cyfirx is a professional tool intended for users 18 years of age or older. We do not knowingly collect personal information from children under 13. If we learn we have collected information from a child under 13, we will delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last updated" date at the top of this page and, where required, by sending an email notification. Continued use of Cyfirx after the changes take effect constitutes acceptance of the updated policy.
Contact
For privacy-related questions, requests, or concerns, contact us at [email protected] or via our contact page.