PROLOGUE Why "Cyduck"?
Cyduck is short for Cyber Duck. We picked a duck on purpose.
From above, a duck looks calm — drifting along, minding its business. Underneath the water, it's working hard the entire time. That's the posture we wanted for a security tool: serious about the job, never theatrical about it.
Cybersecurity products usually come dressed in shields, locks, and ominous typography. We thought the field could survive one company that takes the work seriously without taking itself seriously. Hence: the duck.
ARTICLE I We see nothing
All password generation and analysis runs entirely in your browser. We have no server processing your passwords — not because we're lazy, but because we designed it that way. We physically, structurally, fundamentally cannot see what you generate or type. It's like asking what's in a locked safe we've never been near.
ARTICLE II We store nothing
No tracking cookies. No personal analytics. When you close the tab on a public tool, it's like you were never here — which is either privacy nirvana or existentially unsettling, depending on your worldview.
The Cyber Scorer dashboard is the one exception, and it's an opt-in account: you sign in, you choose to monitor specific assets, and you can delete everything any time. More on that in Article IV.
ARTICLE III We share nothing
We do not sell your data. We do not share your data. We do not monetize your data.
Cyduck earns through premium features and in-app purchases inside our products — never through your personal information. The business model is straightforward: pay for the tools you find valuable, keep your data.
ARTICLE IV What Cyber Scorer actually does (and doesn't)
Cyber Scorer is our advisory app — it scores the cyber risk posture of the assets you choose to monitor (your email, your accounts, your phone), watches for breaches that involve those assets, and tells you when something looks off. When your score drops, we point you to the action that would help most.
Two important things to be honest about:
We are a recommendation system, not a guarantee. We will never tell you "you are 100% safe" — because nobody on the internet can. Not even the Duck Lord himself. What we can do is surface the signals that matter, in plain language, and nudge you toward the right next step. The decision and the action are always yours.
We collect less than your supermarket app. To do this work, we need to know what to monitor — an email address, an asset you've chosen to add. That's it. The information we ask for is the same information you already hand to any e-commerce site or rewards card, and we use it for one purpose only: telling you when something happens to it.
ARTICLE V The Duck Doctrine
If it looks safe and behaves private, that's because it is. Some tools are free, some are paid — but none of them are paid for with your data.
Cyduck was built on the principle that everyday people deserve professional-grade security tools without handing over their email address, accepting a 47-page agreement, or watching an ad for a mattress they looked at once in 2019.
Calm on the surface. Working hard underneath. Always.
ARTICLE VI When Duck Law changes
If Duck Law ever changes in a meaningful way, we'll say so clearly — not bury it in a paragraph nobody reads at 2 AM. The date below is when this version was last updated. If the date is old, nothing important has changed.
EPILOGUE Wait — is this our Privacy Policy?
No. Duck Law is a manifesto — the spirit of how we operate, written in plain language so you actually read it.
The legally binding documents live in their proper place: our Privacy Policy covers data handling, and our Terms of Service covers everything else. Read those when you need the formal version. Read this when you want to know what we actually believe.