SafeCyber Living

Privacy Policy

Effective Date: July 27, 2026  ·  Last Updated: July 28, 2026

On this page

  1. Introduction
  2. Notice at Collection — Summary
  3. Information We Collect
  4. How We Use Your Information
  5. Cookies and Tracking
  6. How We Share Information
  7. Data Retention
  8. How We Protect Your Information
  9. Confidentiality of Your Assessment
  10. Your Privacy Rights
  11. Children’s Privacy
  12. Third-Party Links
  13. International Visitors
  14. Changes to This Policy
  15. Accessibility
  16. Contact Us

1. Introduction

SafeCyber Living (“SafeCyber Living,” “we,” “us,” or “our”) helps individuals and small organizations understand and reduce their cybersecurity risk. Because our work is about protecting people’s information, we hold ourselves to the same standard we ask of our clients: collect only what we need, protect it properly, keep it only as long as it is useful, and tell you plainly what we are doing.

This Privacy Policy explains what personal information we collect through safecyberliving.com (the “Site”) and in the course of providing consultations and risk assessments, how we use and protect it, who we share it with, and what choices and rights you have.

This policy applies to the Site and to our consulting services. It does not apply to third-party websites or services we may link to, which have their own privacy practices.

If you do not agree with this policy, please do not use the Site or submit information to us.

2. Notice at Collection — Summary

The table below is a plain-language summary of what we collect and why. Details follow in the sections after it.

What we collectWhy we collect itHow long we keep itDo we sell or share it?
Name, email, phone, and message from contact and consultation formsTo respond to your inquiry and schedule a consultation24 months after our last contact with youNo
Your answers, scores, and risk tier from the Cybersecurity Risk AssessmentTo prepare for and personalize your consultation36 months, or until you ask us to delete themNo
Email address and subscription preferencesTo send you the security updates you signed up forUntil you unsubscribe, plus 12 months for recordkeepingNo
IP address, device and browser information, pages viewed, referring siteTo keep the Site secure and understand how it is usedUp to 6 months for platform cookies; about 30 days for web server logs held by our hosting providerNo
Our commitment

We do not sell your personal information, and we do not share it for cross-context behavioral advertising or targeted advertising. We have never done so, and we do not have a business model that depends on it.

3. Information We Collect

3.1 Information You Provide Directly

Consultation and contact requests. When you request a free consultation or contact us through a form on the Site, we collect the information you enter — typically your name, email address, phone number, and any message or context you choose to include. These forms are hosted and processed through our customer relationship management platform (see Section 6).

Cybersecurity Risk Assessment responses. Our Cybersecurity Risk Assessment asks you to rate your awareness across five categories: Scam Communication Tactics, Financial and Identity Threats, Device and Account Security, Privacy and Social Media, and Emerging and Household Risks. If you complete the assessment, we collect:

  • your responses to each item;
  • the section subtotals, grand total score, and resulting risk tier; and
  • any notes you or we record during a follow-up conversation.

We treat your assessment responses as confidential. We use them for one purpose: to understand where you would benefit from help so that your consultation addresses your actual gaps rather than generic material. See Section 9 for the specific commitments we make about these results.

Email newsletter and marketing. If you subscribe to our mailing list, we collect your email address and your subscription preferences. Our email platform also records whether messages were delivered, opened, or clicked, which we use to gauge whether our content is useful and to manage list hygiene.

Consulting engagement information. If you become a client, we may collect additional information you share with us in the course of the engagement, including details about your devices, accounts, home or office network, and prior security incidents. We collect this only to the extent it is necessary to advise you.

3.2 Information Collected Automatically

When you visit the Site, we and our service providers may automatically collect:

  • Device and connection data: IP address, browser type and version, operating system, device type, and screen resolution.
  • Usage data: pages viewed, time on page, links clicked, referring website or search term, and the dates and times of your visits.
  • Cookies and similar technologies: small files placed on your device to keep the Site functioning, remember your preferences, and produce aggregate analytics. See Section 5.

3.3 Information We Deliberately Do Not Collect

We think it is as important to state what we avoid collecting:

  • We never ask for your passwords, passphrases, PINs, or multi-factor authentication codes. No legitimate security professional will. If anyone claiming to represent SafeCyber Living asks you for a credential, treat it as a scam and contact us directly.
  • We do not collect Social Security numbers, driver’s license numbers, financial account numbers, or government identification numbers through the Site.
  • We do not collect or store payment card numbers on the Site. If we bill you for services, payment is handled by a third-party processor that receives your payment details directly.
  • We do not collect precise geolocation data.
  • We do not collect biometric information.
  • We do not collect health information. Our Cybersecurity Risk Assessment contains no questions about your health, medical conditions, medications, treatments, healthcare providers, patient portals, health apps, or health-related devices, and we do not collect, infer, or store consumer health data of any kind. This is a deliberate design constraint on the assessment, not merely a description of it.
  • We do not knowingly collect information from children. See Section 11.

3.4 Sensitive Personal Information

We do not collect “sensitive personal information” as that term is defined under California law for the purpose of inferring characteristics about you. Your risk assessment responses are treated as confidential regardless of how they are legally classified.

3.5 Consumer Health Data (Washington Residents)

Washington’s My Health My Data Act regulates the collection of “consumer health data.” As stated in Section 3.3, SafeCyber Living does not collect consumer health data. We do not maintain a separate consumer health data privacy policy because we have no consumer health data to describe. If that ever changes, we will publish a stand-alone consumer health data privacy policy and link it prominently from our homepage before collecting any such data.

4. How We Use Your Information

We use the information described above for the following purposes:

  1. To respond to you — answering inquiries, scheduling consultations, and following up.
  2. To deliver our services — preparing for and conducting risk assessments and consultations, and tailoring recommendations to your situation.
  3. To send communications you requested — newsletters, security alerts, and educational content you opted into.
  4. To improve our services — understanding which assessment items and topics are most useful, and refining our materials.
  5. To secure and maintain the Site — detecting and preventing abuse, fraud, malicious traffic, and technical failures.
  6. To meet legal and recordkeeping obligations — including tax, accounting, and responding to lawful requests.

We do not use your information for automated decision-making that produces legal or similarly significant effects about you. We do not use your information to build advertising profiles.

5. Cookies and Tracking Technologies

We use a limited set of cookies and similar technologies:

CategoryPurposeTypical lifespanCan you turn it off?
Strictly necessaryPage delivery, form submission, security, and load balancingSessionNo — the Site will not function properly without these
Marketing platform analyticsRecognizing returning visitors so form submissions and email activity connect to the right record, and aggregate measurement of Site trafficUp to 6 monthsYes
Session measurementCounting a single visit as one session30 minutes of inactivityYes

We do not use Google Analytics or any third-party analytics service. We do not use advertising cookies, retargeting pixels, or social media tracking pixels. The only cookies on the Site are those required to serve the pages and those set by the customer relationship management platform that hosts our forms.

Your choices:

  • Browser controls. Most browsers let you block or delete cookies. Blocking strictly necessary cookies may break parts of the Site.
  • Global Privacy Control (GPC). We honor the Global Privacy Control signal. If your browser or extension transmits a GPC signal, we treat it as a valid opt-out of any sale or sharing of personal information, consistent with California law.
  • Do Not Track (DNT). There is still no common industry standard for interpreting DNT browser signals. Because we do not sell personal information or serve targeted advertising, we do not alter our practices in response to DNT signals. We do honor GPC as described above.
  • Cookie banner. Where our Site presents a cookie preference banner, declining non-essential cookies stops the marketing platform from setting its tracking and identity cookies for your visit.

6. How We Share Information

In short

We do not sell your personal information. We do not rent, trade, or share it for anyone else’s marketing.

We share personal information only in the following limited circumstances:

Service providers. We use a small number of vendors to operate our business. They may process personal information on our behalf, under contract, and only for the purpose we specify. They are not permitted to use it for their own purposes.

Type of providerWhat it handles
Customer relationship management and forms platformContact records, form submissions, assessment responses and scores, email delivery, and aggregate Site usage measurement
Website hosting and content deliverySite delivery and server logs
SchedulingConsultation appointment booking, where used
Payment processingBilling for paid services, where applicable

(A current list of named providers is available on request using the contact details in Section 16.)

Professional advisors. We may share information with our accountants, attorneys, or insurers where necessary and subject to confidentiality obligations.

Legal requirements. We may disclose information if required by law, subpoena, court order, or other valid legal process, or where we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others, or to investigate fraud or a security incident.

Business transfer. If SafeCyber Living is involved in a merger, acquisition, or sale of assets, personal information may be transferred as part of that transaction. We will notify you before your information becomes subject to a materially different privacy policy.

With your direction. We will share information with a third party — for example, a family member, IT provider, or employer — only when you ask us to.

7. Data Retention

We keep personal information only as long as we have a reason to, then delete or de-identify it.

CategoryTarget retention periodCriteria we use
Contact and consultation inquiries24 months after our last substantive contact with youLong enough to remember prior conversations and follow up meaningfully
Risk assessment responses, scores, and notes36 months, or until you request deletionLong enough to measure progress across repeat assessments
Newsletter subscription recordsUntil you unsubscribe, plus 12 monthsProof of consent and suppression-list integrity so we do not re-add you
Client engagement records and invoices7 yearsTax, accounting, and professional recordkeeping requirements
Site usage data and tracking cookiesUp to 6 monthsCookie lifespan set by our marketing platform; we do not extend it and we add no third-party analytics
Security and server logsApproximately 30 daysSet by our hosting provider, not by us. We run no servers of our own, so we cannot extend or shorten this period

When a retention period ends, we delete the information or de-identify it so it can no longer reasonably be linked to you. Information in encrypted backups may persist for a limited additional period until those backups rotate out of retention.

How we enforce these periods. We review and purge records on a quarterly cycle, so deletion may occur up to three months after the target period ends. We state this plainly rather than implying same-day deletion we do not perform.

8. How We Protect Your Information

We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the information we hold, including:

  • Encryption in transit. The Site is served over HTTPS/TLS. Form submissions are encrypted in transit.
  • Encryption at rest. Client records and assessment results are stored in systems that encrypt data at rest.
  • Access control. Access is limited to those who need it to do their work, on a least-privilege basis.
  • Strong authentication. Multi-factor authentication is enabled on the accounts and platforms we use to store client information.
  • Vendor diligence. We evaluate the security posture of the providers we rely on before entrusting them with information.
  • Data minimization. We do not collect information we do not need, and we delete it on the schedule in Section 7.
  • Device hardening. Company devices use full-disk encryption, current patch levels, and automatic screen locking.
An honest limitation

No system is perfectly secure, and no one who tells you otherwise should be trusted. We cannot guarantee absolute security of information transmitted over the internet. Please do not send us passwords, account credentials, or full financial account numbers by email or through a web form. If you believe your interaction with us has been compromised, or if you discover a vulnerability in the Site, contact us immediately at security@safecyberliving.com.

Breach notification. If we become aware of a security incident affecting your personal information, we will notify you and any applicable regulators as required by law, without unreasonable delay.

9. Confidentiality of Your Risk Assessment

Your risk assessment results deserve specific commitments, so here they are:

  • Your individual responses, scores, and risk tier are confidential. We do not publish them, and we do not disclose them to any third party except as described in Section 6.
  • We do not use your results to market third-party products to you, and we do not receive commissions for referring you to any vendor.
  • The free consultation and the assessment carry no obligation to purchase anything.
  • We may use aggregated, de-identified data — for example, “38% of respondents were unaware of SIM-swap fraud” — in educational content and general reporting. Aggregate figures never identify you and are constructed so that individuals cannot reasonably be re-identified.
  • You may ask us to delete your assessment results at any time. See Section 10.

10. Your Privacy Rights

10.1 Rights Available to Everyone

Regardless of where you live, you may ask us to:

  • Access — tell you what personal information we hold about you;
  • Correct — fix information that is inaccurate;
  • Delete — erase your information, subject to legal retention obligations;
  • Opt out of marketing — stop sending you newsletters or promotional email; and
  • Obtain a copy — receive your information in a portable format.

To unsubscribe from email, use the unsubscribe link at the bottom of any message, or contact us directly.

10.2 California Residents (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you the following rights:

  • Right to know the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the categories of third parties to whom we disclose it.
  • Right to delete personal information we collected from you, subject to statutory exceptions.
  • Right to correct inaccurate personal information.
  • Right to opt out of sale or sharing of personal information for cross-context behavioral advertising. We do not sell or share personal information, so there is nothing to opt out of — but you may still submit a request and we will confirm this in writing.
  • Right to limit use of sensitive personal information. We do not use or disclose sensitive personal information for purposes that trigger this right.
  • Right to non-discrimination. We will not deny you services, charge you a different price, or provide you a different level of service because you exercised a privacy right.
  • Right to no retaliation if you are an employee, applicant, or contractor.

We do not offer financial incentives in exchange for personal information.

A note on applicability, in the interest of transparency

The CCPA’s obligations apply to businesses that meet statutory thresholds relating to revenue and the volume of consumer data handled. SafeCyber Living is a small business and may fall below those thresholds. We extend the rights described above to our clients and Site visitors as a matter of policy, whether or not we are legally required to.

10.3 Residents of Other U.S. States

A growing number of states — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island — have enacted comprehensive consumer privacy laws granting rights to access, correct, delete, and port personal information, to opt out of targeted advertising and sale, and to be free from discrimination for exercising those rights.

Rather than distinguish among them, we extend the rights in Sections 10.1 and 10.2 to all Site visitors and clients, regardless of state. Some states also provide a right to appeal a denied request; if we deny your request, we will explain why and tell you how to appeal.

10.4 How to Exercise Your Rights

Submit a request by:

  • Email: security@safecyberliving.com
  • Phone: 253-341-5125

If you would prefer to correspond by postal mail, email or call us and we will provide a mailing address for your request.

Verification. To protect you, we must verify your identity before acting on a request to know, delete, or correct. We will typically ask you to confirm information already in our records — for example, the email address you used to contact us. We will not create new accounts or collect additional sensitive information solely for verification. If we cannot verify you, we will explain why and, where possible, tell you what else we need.

Authorized agents. You may designate an authorized agent to submit a request on your behalf. We will ask the agent for written proof of authorization and may ask you to verify your identity directly.

Timing. We will confirm receipt within 10 business days and respond substantively within 45 calendar days. If we need more time, we will tell you and may extend by up to an additional 45 days. There is no charge for a reasonable request.

No account required. You do not need to create an account with us to exercise any right.

11. Children’s Privacy

The Site and our services are intended for adults. We do not knowingly collect personal information from children under 13, and we do not knowingly sell or share the personal information of consumers under 16.

If you are a parent or guardian and believe your child has provided us with personal information, contact us at security@safecyberliving.com and we will delete it promptly.

Where we provide family or household cybersecurity guidance, we work with the parent or guardian — not directly with the child — and we do not ask for information about children beyond what is necessary to give useful advice.

12. Third-Party Links and Resources

Our Site and educational materials may link to third-party tools, articles, and vendors that we believe are useful — for example, password managers, credit-freeze portals, or government fraud-reporting sites. We do not control those sites and are not responsible for their privacy practices. Review their privacy policies before providing information. A link is not an endorsement of their data practices, and we receive no compensation for these referrals unless we expressly disclose otherwise.

13. International Visitors

SafeCyber Living operates in the United States, and the information we collect is stored and processed in the United States. Privacy laws in the U.S. may differ from those in your country. If you access the Site from outside the United States, you understand that your information will be transferred to and processed in the United States.

We do not target our services to individuals in the European Economic Area, the United Kingdom, or Switzerland. If you are located in one of those jurisdictions and wish to exercise rights under applicable law, contact us at security@safecyberliving.com and we will work with you in good faith.

14. Changes to This Policy

We may update this policy to reflect changes in our practices, our technology, or the law. When we do, we will revise the “Last Updated” date at the top of this page.

If we make a material change — for example, collecting a new category of personal information or using it for a substantially new purpose — we will provide prominent notice on the Site and, where we have your email address and the change affects you, by email. Material changes will not be applied retroactively to information already collected without your consent where consent is required.

We encourage you to review this page periodically.

15. Accessibility and Other Formats

We aim to make this policy readable and accessible, including to visitors using assistive technology. If you need this policy in an alternative format, contact us at security@safecyberliving.com and we will provide one.

16. Contact Us

Questions, concerns, or requests about privacy:

Anthony Higgins d/b/a SafeCyber Living
Tacoma, Washington
Serving Tacoma and the greater Puget Sound region

Privacy inquiries: security@safecyberliving.com
Security and vulnerability reports: security@safecyberliving.com
Phone: 253-341-5125
Web: safecyberliving.com

We take privacy questions seriously and aim to respond to every inquiry. If you are not satisfied with our response, you may contact the California Privacy Protection Agency or your state attorney general’s office.

↑ Back to top