Privacy Policy
BadgerQuest is a gamified security-awareness training service operated by CyberBadger, a company registered in Ontario, Canada. This policy explains what personal information we collect, why, how long we keep it, and what rights you have. It covers the service at badgerquest.ca and our sales and marketing contacts.
Questions or requests: privacy@cyberbadger.ca.
In short
- We do not sell your personal information, and we never use it for advertising. Every cookie we set is strictly necessary to run the service. There are no advertising or third-party analytics cookies, and no tracking pixels.
- If your employer gave you an account, its administrators can see your training activity, your completion, and a computed risk score. They cannot see your individual quiz answers.
- You can export everything we hold about you, and delete your account, yourself, from Settings, immediately, without asking us or anyone else.
- We never receive biometric data. Passkey sign-in verifies your fingerprint, face or PIN entirely on your own device.
- Your data is hosted in the United States (Railway) and payments are processed in Canada (Helcim). Those two, plus our email provider, are the only third parties involved.
The rest of this policy covers all of that in full, including the parts that are less obvious, such as what happens if your employer claims your work email domain.
1. Who is responsible for your information
CyberBadger operates BadgerQuest. Depending on how you came to use it, either your organisation or CyberBadger is the party legally responsible for your personal information.
- If an employer, school or other organisation gave you an account, including through single sign-on, an invitation, or by claiming your email domain (section 8), that organisation is the controller of your training data and CyberBadger is its processor: we act on that organisation's instructions, under its agreement with us. To access or correct your training data, your administrator is usually the fastest route, because they can act on it directly. You can also come to us and we will help or pass the request on.
- If you signed up yourself, with no employer involved, CyberBadger is the controller.
- If you are a business contact in our sales pipeline (section 9), CyberBadger is the controller of that information.
A Data Processing Agreement covering the processor relationship is available to organisation customers on request.
2. What we collect
| Category | Examples | Why |
|---|---|---|
| Account | Email (required), name (optional), password hash (bcrypt; absent entirely for passkey-only and SSO accounts), avatar and cosmetic choices | Create, identify and secure your account |
| Organisation membership | Which organisation you belong to, your role, department, country | Run your organisation's training and keep organisations separate |
| Training activity | Quest runs, individual quiz attempts, phishing practice outcomes (caught, missed, reported, false alarm), XP, streaks, ranks, badges, league standings, story progress | Run the game, track your progress, produce readiness reporting |
| Passkeys | A public key, credential ID, signature counter, transports, device type, whether the credential is backed up, an optional label you choose | Let you sign in without a password. See section 6: no biometric data ever reaches us |
| Sessions | A signed token in a browser cookie | Keep you signed in |
| Referrals and preferences | Your referral code, who referred you, your email preferences | Run referrals and respect your choices |
| Certificates | Holder name, training name, organisation name, score, a unique serial | Issue proof of completion that anyone can verify |
| Support and bug reports | What you typed, plus technical detail (error, page address, browser user agent) and your identity if you were signed in | Investigate and fix what you reported |
| Security records | Rate-limiting records containing your IP address, single-use tokens for email verification and password reset, and an audit log of privileged actions | Protect accounts and keep administrators accountable |
| Email delivery records | Your address, the category of message, our provider's message ID, delivery status | Send email reliably and diagnose delivery failures |
| Notification reminders | If you turn reminders on, the address your browser gives us for that device, the keys needed to encrypt a message to it, a short label for the device, and the language you are using | Send the reminders you asked for, and nothing else |
| Usage analytics | First-party events, stored in our own database | Understand how the product is used |
Every analytics event stays in our own database. Nothing is sent to an outside analytics company.
3. What we deliberately do not collect
- No biometric data. Passkeys use your fingerprint, face or device PIN, and all of that verification happens on your device, by your device's own operating system. We receive a public key and some technical metadata about the credential, nothing else. Your biometrics never reach us in any form, and there is nothing on our side to leak.
- No third-party tracking. No advertising cookies, no tracking pixels, no third-party analytics, no ad technology of any kind.
- No third-party error tracking. When something breaks, the report goes into our own database, not to an outside monitoring vendor.
- No AI or large-language-model provider. Simulated scams are produced by a deterministic generator we wrote and run ourselves. Your data is never sent to an AI provider.
- No external fonts or content delivery networks. Assets are self-hosted at build time, so loading the app does not call out to anyone.
4. Cookies and local storage
Every cookie we set is strictly necessary. None are used for advertising, tracking or analytics, and we set no third-party cookies at all, which is why you are not asked to consent to any.
| Cookie | Purpose | Lifetime |
|---|---|---|
authjs.session-token | Keeps you signed in | 7 days |
bq_wac | Holds a passkey challenge while you sign in | 5 minutes |
bq_sso | Holds single sign-on state, nonce and PKCE values during login | 10 minutes |
bq_sso_ticket | A single-use token that completes an SSO login | 2 minutes |
bq_imp | Signed marker used only when CyberBadger staff view an account for support | 30 minutes |
bq_su | Ties a signup in progress to the browser that started it | 24 hours |
The session cookie is HTTP-only, same-site, and marked secure in production, so page scripts cannot read it and it travels only over HTTPS.
We also use browser local storage for three preferences that never leave your device: your theme (bq-theme), whether sounds are muted (bq-muted), and whether you dismissed an invite prompt (bq-invite-nudge-dismissed).
5. What your organisation's administrators can see
If you belong to an organisation, its owners and administrators can see, for each member: name, email, role, department, XP, streak, quest counts and accuracy, phishing practice outcomes (encounters, caught, missed, false alarms), last active date, last login date, join date, and an individual Human Risk Score with a letter grade (section 7).
They cannot see your individual quiz answers. Only you can, through your own data export (section 12).
Everything they see is counted from the day you joined that organisation, not from your first ever day on BadgerQuest. If you used BadgerQuest before you worked there, or before they had an account at all, that earlier practice stays yours: it is not in their roster, their reporting, or your score as they see it. Your own view of your history is unaffected and still shows everything.
An administrator can exclude specific members from the organisation's aggregate statistics. When that happens, the number of people excluded is reported alongside the score, so the figures stay honest about their own denominator.
Programmatic access to your score
On plans that include API access, your organisation can also pull your Human Risk Score and related events programmatically and feed them into its own systems, such as a security monitoring or HR platform. This is the same information an administrator can already see in the product; the API only makes it automatic. What your organisation does with it, including any decision it makes as a result, is your organisation's responsibility, not ours. Our terms require organisations not to use the score as the sole basis for an automated decision that significantly affects someone.
6. Passkeys
We store a public key and technical metadata: credential ID, signature counter, transports, device type, whether the credential is backed up, and any label you give it. We deliberately request no device attestation, so we do not collect information that could be used to fingerprint your particular device. Verification of your fingerprint, face or PIN happens on your device and is never transmitted to us.
7. Your Human Risk Score, and automated processing
We calculate a Human Risk Score for each person, shown as a percentage and a letter grade. It blends three things: how often you report the phishing simulations you meet, your quiz accuracy, and how often what you report turns out to be an actual simulation rather than a false alarm. Attendance is deliberately excluded, because turning up is not competence, and a score you can raise by logging in would not mean anything.
The score does two things by itself:
- It is shown to you, and to your organisation's administrators if you belong to one.
- It automatically adjusts the difficulty of the practice you are served next.
It does not automatically discipline you, restrict your access, or report you to anyone. Any consequence beyond the difficulty of your next scam is a decision made by a person at your organisation, using the score as one input among others. An algorithm produces the number; no algorithm acts on it.
If you think your score is wrong or unfair, email privacy@cyberbadger.ca, or ask your administrator. A person will review it. We will tell you what the score was calculated from, and correct it if the underlying records are wrong. Where a decision based on automated processing has a legal or similarly significant effect on you, you have the right to contest it and to ask for human intervention.
8. Domain claiming, and how an employer gains visibility of an existing account
If a company proves it controls an email domain, by publishing a DNS record we verify, we move existing accounts on that domain into that company. From that point, that person's training is visible to the company's administrators in the same way as any other member's.
What that company sees starts on the day the account moved. Practice you did before then, including anything from before that company had a BadgerQuest account, is not shown to them and is not counted in their reporting or in the score they see for you. It stays in your own record. This is the same rule that governs every other member (section 5), and it is deliberate: a company proving control of its domain is a good reason to administer the account from that point on, and not a reason to be handed a history it had no part in.
This happens without asking the individual first, because the company is asserting control of its own domain. We think that is the expected outcome for a work email address, and it is how most workplace tools treat a verified domain, but we would rather state it plainly than leave you to discover it.
Three kinds of account are never moved:
- Someone who already belongs to a different organisation.
- A CyberBadger staff account.
- Anyone paying for their own personal subscription.
Everyone who is moved is emailed to tell them it happened. Nobody is moved silently. If you believe your account was moved in error, email privacy@cyberbadger.ca and we will look at it.
9. Business contacts and our sales pipeline
Separately from the product, we keep records about business contacts at organisations we think may want BadgerQuest, who have not signed up. This can include a name, work email address, job title, phone number, and notes we make.
We rely on either express consent or one of the implied consent bases recognised by Canada's Anti-Spam Legislation, such as a business email address published without a statement refusing such messages. Where the basis is implied, it expires, and we record and respect that expiry. Outreach is written and sent by a person, not by an automated campaign tool.
This pipeline has its own suppression list, deliberately separate from the product's, so asking us to stop contacting you is honoured regardless of anything else. Records that never become a customer are deleted after 730 days.
To see what we hold about you, or to be removed, email privacy@cyberbadger.ca.
10. How we use your information
- To run the game and track your progress.
- To give your organisation's administrators the reporting in section 5, strictly limited to their own organisation.
- To send account, billing and, where your employer requires training, reminder email (section 11).
- To operate referrals, leagues, certificates and the other features you use.
- To secure the service: rate limiting, abuse investigation, and audit logging.
- To answer support requests and fix the bugs you report.
- To meet our legal and tax obligations.
- To run the sales pipeline in section 9.
We do not use your personal information for anything incompatible with these purposes.
11. Email, and what you can turn off
- Account and billing email (verification, password reset, receipts, payment failures) cannot be turned off while your account is open. Without it we cannot run your account.
- Employer-required training email (assignment reminders and overdue escalations) can be reduced to final escalations only, but not silenced. Your employer required the training; that is not ours to override on your behalf.
- Engagement email (weekly nudges, monthly summaries, and a win-back note if you go quiet) is genuinely optional and one click turns it off completely.
- Reminders on your device (the Friday beacon reminder, and the Daily Raven reminder if you ask for it) are off until you switch them on, one device at a time, and switching them off deletes that device's address immediately.
Every email outside the account and billing tier carries a one-click unsubscribe built to the RFC 8058 standard, so your mail provider can offer the unsubscribe directly in its own interface. Our suppression list only ever gets stronger: once you have opted out at a level, nothing starts sending you more than that again.
We also cap scheduled mail at two messages in any seven days and four in any thirty, with account and billing email exempt because it is transactional.
12. Your rights, and how to use them
If you have an account, you can do both of these yourself, from Settings, without asking anyone:
- Export your data. A single JSON file containing everything we hold about you, including your own quiz answers.
- Delete your account. Immediate, and it cascades: training history, memberships, certificates, badges, sessions and passkeys are removed. Any active billing is stopped first.
Three things about deletion are worth knowing:
- Content you authored (if you wrote training material for your organisation) survives, with the link to you as author removed, so it is no longer personal information.
- If you unsubscribed from email, that record survives deletion. An unsubscribe has to outlive the account, or deleting your account could quietly re-permit email to you later.
- Deletion is blocked in exactly one case: you are the last owner of an organisation that still has members. Transfer ownership first, so the organisation is not orphaned.
You also have the right to ask us what we hold and why, to have inaccurate information corrected, and to know who we have disclosed it to. Email privacy@cyberbadger.ca. If your account came from an employer, we will usually direct you to your administrator first, because they control that data, but we will help either way.
13. How long we keep things
| Record | Kept for |
|---|---|
| Rate-limiting records containing an IP address | 24 hours |
| Expired sign-in challenges and single-use tickets | Deleted once expired |
| Spent or expired email verification, password reset and signup tokens | 7 days |
| Error and bug reports | 12 months |
| Email delivery log | 13 months |
| Record of the reminders we sent to a device | 13 months |
| A device's notification address | Deleted when you turn reminders off, or when the push service tells us the device is gone |
| Audit log of privileged actions | 24 months |
| Sales pipeline records that never convert | 730 days |
| Your account and training data | For the life of your account, then as described in section 12 |
These are enforced by a scheduled job, not by intention: the periods above are read directly from the code that does the deleting, so this table cannot drift away from what actually happens.
Certificates are the deliberate exception. They stay verifiable so that a certificate presented years later can still be checked, unless your account is deleted, in which case they are removed with it.
14. Where your information is processed
We host the application and database with Railway, in the United States, and process payments with Helcim, in Canada. Personal information about Canadian users is therefore processed outside Canada, in a country whose courts, law enforcement and national security authorities may be able to compel access to it under their own law. Canadian privacy law requires us to say that plainly, so: if you are in Canada, some of your personal information leaves the country.
15. Who else touches your data
| Subprocessor | What they do | Where | What they see |
|---|---|---|---|
| Railway | Hosts the application and the database | United States | Everything stored in the service |
| Resend | Sends our email | United States | Your email address and the contents of messages we send you |
| Helcim | Processes card payments | Canada | Billing contact details, a customer code, and charge records. Card numbers are entered into a form Helcim hosts and never reach our servers or storage |
That is the complete list. If it changes, this table changes, and organisation customers with a Data Processing Agreement are notified as that agreement requires.
16. Security
- TLS in transit, with HTTP Strict Transport Security preloaded.
- A strict same-origin Content Security Policy with a fresh cryptographic nonce on every request.
- Passwords hashed with bcrypt at cost 12.
- Every other bearer token (API keys, invitations, verification links) stored only as a SHA-256 hash, never in a form we could read back.
- Everything we store, the database included, additionally encrypted at rest at the storage layer by our hosting provider (section 15).
- Two-factor secrets, single sign-on client secrets, webhook signing secrets and payment provider credentials encrypted by the application itself with AES-256-GCM before they are stored. Two-factor backup codes stored only as hashes.
- Per-organisation isolation enforced on the server for every read, not merely by hiding things in the interface.
- An audit log of privileged actions.
- Protection against server-side request forgery on every outbound request to an address a customer configured.
- Database-backed rate limiting on sign-in, registration, password reset, two-factor and passkey endpoints, so a deploy cannot reset an attacker's budget.
- Multi-factor authentication, passkeys or single sign-on, enforceable across an organisation at its option.
- Periodic internal adversarial review of our own code.
We do not hold SOC 2, ISO 27001 or any other third-party security certification, and we have not had a third-party penetration test. If either becomes true we will say so here. Until then, please do not read the list above as implying either.
17. If something goes wrong
If we suffer a breach of security safeguards that creates a real risk of significant harm to you, we will notify the Privacy Commissioner of Canada and affected individuals, as Canadian law requires, and keep the records of it that the law requires us to keep. If you hold an account through an organisation, we will notify that organisation without undue delay so it can meet its own obligations.
Beyond what the law strictly requires, we commit to telling affected organisations and individuals what we know as soon as we know it, without waiting for an investigation to conclude, and to telling them again when we know more.
18. Age
BadgerQuest is built for workplace training. Individual accounts require you to be at least 16. We do not knowingly collect personal information from anyone under 16, and we will delete it if we learn we have. If you believe a child has given us personal information, write to privacy@cyberbadger.ca.
19. Quebec residents
Quebec's Act respecting the protection of personal information in the private sector applies to you in addition to the rights above. That includes the right to be told when a decision is based exclusively on automated processing (section 7 explains that no consequence beyond the difficulty of your next practice scam is automated), and the right to receive the information you provided us in a portable form, which our data export gives you directly. Requests go to privacy@cyberbadger.ca.
20. California residents
The California Consumer Privacy Act, as amended, gives California residents specific rights, and requires this disclosure in this form.
Categories we collect: identifiers (name, email, IP address), account and authentication information, employment information (organisation, role, department), internet and network activity (training activity and usage events), and the contents of your communications if you contact support. Section 2 has the detail.
Sources: you, your organisation if it enrolled you, and automatically as you use the service.
Purposes: as set out in section 10.
Sale or sharing: we do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done either in the preceding twelve months and do not intend to.
Your rights: to know, to delete, to correct, and not to be treated differently for exercising any of them. You can do the first two yourself (section 12) or ask us. An authorised agent may act for you; we will ask for proof of their authority.
21. Europe and the United Kingdom
BadgerQuest is not offered into the European Economic Area or the United Kingdom, and we make no claim of compliance with the EU or UK General Data Protection Regulation. That is a business position rather than a technical block: nothing currently stops an organisation based there from signing up.
If you are an organisation in the EEA or UK and want to enrol staff, contact legal@cyberbadger.ca before you do. We would need a Data Processing Agreement incorporating Standard Contractual Clauses in place first.
22. Changes
We may update this policy as the product or the law changes, and will post the new version here with a new effective date. If a change is material, we will take reasonable steps to tell you, by email or in the product, before it takes effect.
23. Contact
Questions, requests or complaints: privacy@cyberbadger.ca. Other legal questions: legal@cyberbadger.ca. If you are in Canada and are not satisfied with our answer, you can contact the Office of the Privacy Commissioner of Canada, and if you are in Quebec, the Commission d'accès à l'information.
See also our Terms of Service.