Privacy Policy
What this website collects, why we collect it, how long we keep it, and what you can ask us to do about it.
1.Who is responsible for your data
| Website | cyberdilmeth.com |
| Data controller | CyberDilmeth |
| Privacy contact | [email protected] |
| General contact | [email protected] |
CyberDilmeth is an independent cybersecurity publication. Where the EU or UK General Data Protection Regulation applies to you, we follow it. The rights set out in section 12 we extend to everyone who contacts us, wherever you are.
If you need further details about the controller for a data-protection request or a regulatory enquiry, write to [email protected] and we will provide them.
2.Scope
This policy covers cyberdilmeth.com and its subdomains.
It does not cover external websites we link to. When you follow a link to a vendor advisory, a government agency page, or any other third-party site, that site's own privacy policy applies. We have no control over, and accept no responsibility for, how those sites handle your data.
3.What we collect at a glance
Collected automatically
IP address, browser and device type, pages requested and timestamps, written to server and security logs so the site stays online and attacks get blocked.
Information you give us
Your email address if you subscribe to the newsletter, and whatever you write if you email us. We do not ask for your name.
Analytics and advertising
Analytics showing how the site is used, and cookies used by our advertising partner. In Europe and the United Kingdom these are set only if you accept them in the consent banner. Elsewhere you can control them from your browser. Section 7 explains both.
| What | Lawful basis | How long |
|---|---|---|
| Server and security logs | Legitimate interests | A short operational period |
| Your cookie consent choice | Legal obligation / consent | Up to 12 months |
| Newsletter subscription | Consent | Until you unsubscribe |
| Analytics | Consent where required, otherwise our legitimate interest in improving the site | A limited period set in our analytics configuration |
| Advertising | Consent where required, otherwise our legitimate interest in funding the site | As set by our advertising partner |
We do not sell, rent or trade your personal data. This site carries advertising, and advertising cookies are set only if you consent to them. Advertisers never receive our subscriber list, and they have no influence over what we publish.
4.What we collect automatically
4.1 Server and security logs
Like every website, our server records requests made to it. This typically includes your IP address, the page requested, the time, your browser and operating system version, and the page you arrived from.
Our hosting provider processes this data on our behalf in order to serve the website.
We use these logs to operate the site, diagnose faults, and identify malicious traffic. We do not use them to identify you personally or to build a profile of you.
4.2 Content delivery and attack filtering
Traffic to this site passes through a content delivery and security network before it reaches our server. That provider processes your IP address and request metadata in order to filter attacks, mitigate denial-of-service traffic, and serve pages quickly.
It sets a small number of strictly necessary cookies for this purpose. These are listed in section 7.
4.3 Application firewall
We run a security layer that inspects requests for attack patterns and may temporarily block IP addresses that behave maliciously. It records IP addresses and request details associated with blocked or suspicious activity.
If you are blocked in error, contact us and we will look into it.
5.Information you give us
5.1 Newsletter
Our newsletter is delivered through a third-party email service and uses double opt-in. You enter your email address, we send you a confirmation email, and you are subscribed only if you click the link in it. That prevents you being signed up by someone else and gives us a record that consent was given.
We store your email address, the date and time you confirmed, and which page you subscribed from. We do not require your name.
Our email provider also records standard delivery and engagement events, such as whether a message was delivered, opened, or a link clicked. We use this to understand which content is worth writing more of, and to stop sending to addresses that bounce.
Every email we send contains a one-click unsubscribe link. When you unsubscribe we retain a minimal suppression record, essentially a note that your address has opted out, so that we do not contact you again by accident. You can ask us to delete that too.
5.2 Contacting us
If you email us, we receive your email address and whatever you write. We use it to respond to you and for nothing else. We will not add you to a mailing list because you contacted us.
We keep correspondence only as long as it is useful for handling your enquiry and any follow-up, then delete it.
5.3 Comments
Reader comments are disabled on this site. We do not operate a comment system and collect no data through one. If we introduce comments in future, this policy will be updated before we do so.
6.Our interactive tools
6.1 Tools that transmit nothing
The following tools run entirely inside your web browser. The values you type are processed by JavaScript on your own device. They are not sent to our servers, not stored, and not logged:
- Password Generator
- Passphrase Generator
- PIN Generator
- Password Analyzer, the strength checker
- Password Policy Checker
These tools continue to work if you disconnect from the internet after the page has loaded.
6.2 The Password Breach Check
The breach check works differently. To tell you whether a password has appeared in a known data breach, it has to be compared against a corpus far too large to load into your browser. This is done using a technique called k-anonymity, so the comparison happens without your password being revealed.
What happens when you check a password
- Your browser calculates a SHA-1 hash of your password on your device.
- Your browser sends only the first five characters of that hash to the Pwned Passwords service operated by Have I Been Pwned.
- That service returns a list of several hundred hash suffixes beginning with those five characters.
- Your browser compares the rest of your hash against that list locally and shows you the result.
Your password never leaves your device. Neither does the full hash of it.
Those five characters are shared by many thousands of different passwords, so they cannot identify yours. The service on the other end cannot know which password you were checking, and by design does not log the queries.
Your IP address is unavoidably visible to that service in the course of making the request, as it would be for any web request. If you would prefer not to make that request at all, do not use the breach check. Every other password tool on the site works without it.
6.3 Advertising and analytics on tool pages
Password Studio loads no advertising and no analytics. Several of its tools ask you to type a password you actually use, and we do not allow third-party code near those fields.
That rule is based on what a tool handles rather than where it sits. Any tool that asks you to enter a password, a secret or a token is treated the same way. Tools that take no sensitive input, such as a generator that produces a value for you, may carry advertising and analytics like the rest of the site.
No analytics or error-reporting script anywhere on this site is permitted to capture the contents of an input field.
7.Cookies, analytics and advertising
7.1 What a cookie is
A cookie is a small text file that a website asks your browser to store. When you return, the browser sends it back, which lets the site remember something. Some technologies work similarly without technically being cookies, such as local storage, session storage and tracking pixels. Where this policy says cookies, it covers those too.
Cookies are not inherently harmful. The problem is not the technology, it is what people use it for. We use them for site function, for security, for analytics and for advertising.
7.2 What we use them for
- Strictly necessary. Filtering malicious traffic, validating requests, and remembering any cookie choice you have made. These are always active, because the site cannot run securely without them. They do not track you and are not used for marketing.
- Analytics. Google Analytics, used to understand which articles are read and which are ignored, which tools people reach for, where readers arrive from, and where they give up. We use that to decide what to write next and how to improve the site and the tools.
- Advertising. Used by our advertising partner to select and deliver advertising, to limit how often you see the same advertisement, and to measure whether it worked.
- Functional. We use none. Nothing in this category is set.
7.3 What is stored
Storage periods are maximums. Many entries expire sooner.
| Purpose | Set by | Party | Category | Duration |
|---|---|---|---|---|
| Telling human visitors apart from bots, as part of attack filtering | Content delivery and security network | Third party | Strictly necessary | Up to 30 minutes |
| Applying per-visitor rate limits | Content delivery and security network | Third party | Strictly necessary | Session |
| Recording that a security challenge was passed, so you are not challenged repeatedly | Content delivery and security network | Third party | Strictly necessary | Up to 1 year |
| Telling one visitor apart from another, and keeping analytics session state | Google Analytics | Third party | Analytics | Up to 24 months |
| Selecting and delivering advertising, limiting how often you see the same advertisement, and measuring whether it worked | Advertising partner | Third party | Advertising | As set by that partner |
The three attack-filtering entries are set at the network edge, before a request reaches our server. Without them we cannot filter automated attacks against this site.
We describe cookies here by purpose rather than by name, because names change when infrastructure changes and a stale list is worse than none. If you find something in your browser from this site that is not covered above, tell us and we will either document it or remove it.
7.4 Analytics in more detail
Analytics records pages viewed, an approximate location derived from your IP address, device and browser type, the referring site, and basic interaction events. We use it in aggregate to understand patterns, not to identify you. Google acts as our data processor for this.
7.5 Advertising in more detail
This site carries advertising. Advertising is what keeps the guidance here free to read.
Our advertising partner may collect your IP address, device and browser information, and the pages you view, in order to select, deliver and measure advertising. It determines its own purposes for that processing and acts under its own privacy policy.
Advertising buys space, never coverage. Advertisers get no influence over what we publish, no advance sight of articles or advisories, and no placement in threat intelligence. Anything sponsored is labelled as sponsored, every time.
7.6 Controlling cookies yourself
Your browser gives you control regardless of where you are. You can usually block all cookies, block third-party cookies only, delete existing cookies, or clear everything when you close the browser. You will find these under Settings and then Privacy in Chrome, Firefox, Safari, Edge and Brave. Blocking strictly necessary cookies entirely may cause parts of this or any other site to stop working.
You can opt out of Google Analytics across every website you visit using Google's browser add-on at tools.google.com/dlpage/gaoptout.
If your browser sends a Global Privacy Control signal, we treat it as a refusal of non-essential cookies. If you send GPC and still see a cookie you did not expect, tell us and we will investigate.
7.7 Signed-in users only
If you log in to the site as an author, editor or administrator, WordPress and our security layer set additional cookies to keep you signed in and to validate firewall sessions. These are never set for ordinary readers.
8.Threat intelligence content
Our Threat Intelligence section is compiled from public sources including the CISA Known Exploited Vulnerabilities catalog, the National Vulnerability Database, and EPSS data published by FIRST.org.
This content describes software vulnerabilities. It contains no personal information about you, and reading it does not tell us anything about you beyond the ordinary server log described in section 4.1.
9.Who else processes your data
Each service below is used because it is necessary to run the site.
| Category of provider | What they do | What they see |
|---|---|---|
| Hosting provider | Runs the server that serves this site | Server logs; anything stored on the site |
| Content delivery and security network | Caching, attack filtering, denial-of-service protection | IP address, request metadata |
| Email and newsletter delivery | Sends the newsletter and our correspondence | Email address, consent record, delivery and engagement events |
| Analytics provider (Google) | Website analytics, only with your consent | Pageviews, approximate location, device and browser data |
| Advertising partner | Selects, delivers and measures advertising, only with your consent | IP address, device and browser data, pages viewed, ad interactions |
| Pwned Passwords service | Answers breach-check queries | A five-character hash prefix and your IP address, only when you use that tool |
Our hosting, delivery, email and analytics providers act on our instructions under a data processing agreement, and none is permitted to use your data for its own marketing purposes. Our advertising partner determines its own purposes and acts under its own privacy policy. We will tell you which specific provider sits behind any category if you ask.
10.International transfers
The providers described above are based in, or process data in, the United States. Your data may therefore be processed outside your own country.
Where that happens we rely on the safeguards those providers offer, including Standard Contractual Clauses, the EU to US Data Privacy Framework where the provider is certified, and equivalent binding commitments. We keep the amount of data transferred to the minimum the service needs to work.
If you would like details of the safeguards applying to a specific provider, ask us and we will tell you.
11.How long we keep things
We keep personal data only as long as it serves the purpose it was collected for, and then delete or irreversibly anonymise it.
| Data | Retention |
|---|---|
| Server and security logs | A short operational period, sufficient to diagnose faults and investigate attacks |
| Cookie consent records, where a choice was made | Up to 12 months, then you are asked again |
| Email correspondence | As long as needed to handle your enquiry and any follow-up |
| Confirmed newsletter subscribers | Until you unsubscribe |
| Unconfirmed newsletter sign-ups | Purged periodically if never confirmed |
| Unsubscribe suppression records | Kept unless you ask us to delete them, solely to avoid contacting you again |
| Analytics data | A limited period set in our analytics configuration and reviewed periodically |
| Advertising cookies | As set by our advertising partner, listed in the Cookie Notice |
If you want to know the current retention period applied to a specific category, ask and we will tell you what it is set to.
12.Your rights
Depending on where you live, you have rights over your personal data. We extend the following to everyone who contacts us, regardless of location.
You may ask us to:
- Access. Tell you what data we hold about you and give you a copy.
- Rectify. Correct anything inaccurate.
- Erase. Delete your data, where we have no overriding reason to keep it.
- Restrict. Pause our use of your data while a dispute is resolved.
- Port. Provide your data in a structured, machine-readable format.
- Object. Object to processing we carry out on the basis of legitimate interests.
- Withdraw consent. At any time, without giving a reason, and without affecting anything done before you withdrew it.
To exercise any of these, email [email protected]. We will respond within 30 days, at no charge. We may need to ask a question or two to confirm you are the person the data relates to, and we will ask for the least information necessary to do that.
Given how little we collect, the answer to most access requests will be your email address and the date you subscribed.
Complaints
If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the data protection regulator in the country where you live.
13.Children
This site is intended for a general adult audience and is not directed at children under 16. We do not knowingly collect personal data from children.
If you believe a child has provided us with personal information, contact us and we will delete it.
14.How we protect your data
Measures in place include:
- HTTPS enforced across the entire site
- A web application firewall and content delivery network in front of the origin server
- Access controls and strong authentication on administrative access
- Minimal third-party code, reviewed before installation
- Regular, access-controlled backups
No system is completely secure, and we will not claim otherwise. If a breach affecting personal data occurs, we will notify the relevant authority within the required timeframe and tell affected individuals directly where there is a significant risk to them. We will also publish an account of what happened.
If you have found a security issue in this website, report it to [email protected] and give us reasonable time to fix it before disclosing publicly. We will not pursue action against researchers who act in good faith, avoid privacy violations, avoid degrading the service, and do not access or alter data beyond what is needed to demonstrate the issue.
15.Changes to this policy
We will update this policy when our practices change. The version number and "last updated" date at the top always reflect the current version.
If we make a change that materially affects your rights or how we use your data, we will say so prominently on the site rather than quietly editing the page.
16.Contact
| Purpose | Address |
|---|---|
| Privacy, data requests, complaints | [email protected] |
| Security vulnerability reports | [email protected] |
| Editorial corrections | [email protected] |
| Contributing to CyberDilmeth | [email protected] |
| Everything else | [email protected] |
CyberDilmeth Privacy Policy v1.0, 22 December 2025.
See also: Terms of Use