Skip to content

Legal

Security

Last updated: August 2026

In plain language

We never ask for your passwords or banking logins, full stop. Your Cyber Health score comes from your answers, not from us logging into your accounts. Payments go through Stripe, we never see or store your card details ourselves.

1. What we never ask you for

Demysti5 never asks for, and never stores, your passwords, PINs, or banking credentials. We don't need them, and we don't want them.

If anyone contacts you claiming to be Demysti5 and asks for a password or your banking details, it isn't us. Please report it to [email protected].

2. How your Cyber Health score works

Your score is calculated from the answers you give during onboarding and your ongoing activity in the app, combined with a safe scan for publicly-known data exposure (like whether your email address shows up in a known data breach). We don't log into your accounts, and we don't need your credentials to do this.

3. How we handle payments

Pro subscription payments are processed by Stripe, a payment provider used by many major companies. Your card details go directly to Stripe; Demysti5 never sees or stores your full card number.

4. Where your data lives

The Demysti5 website and app run on Google Cloud / Firebase infrastructure, primarily hosted in Australia. We use industry-standard practices, like encrypted connections (HTTPS) between your device and our servers, to protect data in transit.

5. Reporting a security issue

If you've found a security vulnerability in the Demysti5 website or app, we'd genuinely like to know. Email [email protected] with what you found and how to reproduce it, and we'll get back to you.

Please don't publicly disclose a vulnerability before giving us a reasonable chance to look into it and fix it.

6. Your data, your rights

For the full picture of what we collect, why, and how you can access or delete it, see our Privacy Policy.

7. Contact us

Questions about security? Email [email protected].