Security & Breach Response Policy

Last Updated: September 7, 2026

This Security & Breach Response Policy (“Policy”) explains how Cry-Fi (“Cry-Fi”, “Platform”, “we”, “our”, or “us”) approaches Platform security, security incidents, and personal-data breach response.

Cry-Fi uses reasonable technical and organizational measures designed to protect the Platform and information processed through it. However, no internet-based service, system, or method of electronic transmission can guarantee absolute security.


1. Purpose

This Policy outlines Cry-Fi’s general approach to:

  • Platform security

  • Account protection

  • Security incident response

  • Personal-data breach response

  • User security responsibilities

  • Vulnerability reporting

This Policy describes general security practices and response principles and does not create a guarantee that any particular security control will always be available or effective.


2. Security Measures

Cry-Fi may implement reasonable technical, organizational, and administrative safeguards appropriate to the nature and risks of the Platform.

Depending on the circumstances, these measures may include:

  • Secure hosting and infrastructure practices

  • Access controls

  • Authentication and account-protection measures

  • Encryption or encrypted transmission where applicable

  • Security updates and maintenance

  • Technical logging and monitoring where appropriate

  • Fraud and abuse detection

  • Administrative and organizational security controls

  • Backup or recovery measures where appropriate

Cry-Fi may modify, replace, or improve its security measures as the Platform develops, technology changes, and security risks evolve.


3. User Security Responsibilities

Users and Listeners are responsible for taking reasonable steps to protect their accounts, devices, and access credentials.

This includes:

  • Keeping login credentials confidential

  • Using reasonably strong and unique passwords

  • Not sharing account credentials

  • Protecting personal devices from unauthorized access

  • Keeping devices and relevant software reasonably updated

  • Using only legitimate Cry-Fi access methods

  • Reporting suspected unauthorized account access

  • Keeping account and contact information reasonably accurate

Users should promptly notify Cry-Fi if they reasonably believe that their account has been compromised or used without authorization.

Cry-Fi may take reasonable steps to secure or restrict an account where unauthorized access is suspected.


4. Security Incidents

A security incident may include an actual or suspected event that could affect the confidentiality, integrity, or availability of Cry-Fi systems or information, including:

  • Unauthorized account access

  • Credential compromise

  • Unauthorized data access

  • Accidental data exposure

  • Malware or malicious activity

  • Website or Platform tampering

  • Unauthorized system changes

  • Service disruption

  • Exploitation of a security vulnerability

  • Other events that may materially affect Platform security

Cry-Fi may assess incidents based on their nature, scope, severity, credibility, and potential impact.

Not every technical issue, service interruption, or unsuccessful attack attempt will constitute a personal-data breach.


5. Third-Party Services

Cry-Fi may use third-party providers for services such as:

  • Hosting

  • Payment processing

  • Email delivery

  • Analytics

  • Advertising

  • Security

  • Authentication

  • Video or communication infrastructure

  • Other technology or operational services

These providers may maintain their own security controls, privacy practices, terms, and incident-response procedures.

Where a security incident involves a third-party provider, Cry-Fi may coordinate with that provider and take reasonable steps within its control to assess, contain, mitigate, or otherwise address the issue.

Third-party security incidents may be subject to the provider’s own notification and response obligations.


6. Security Incident Response

When Cry-Fi becomes aware of a potentially significant security incident, Cry-Fi may take reasonable steps, as appropriate to the circumstances, to:

  1. Identify and assess the incident;

  2. Determine potentially affected systems, accounts, or information;

  3. Restrict affected systems or accounts where appropriate;

  4. Contain or prevent unauthorized access;

  5. Secure or restore affected systems;

  6. Investigate the nature and potential scope of the incident;

  7. Preserve relevant technical records;

  8. Coordinate with relevant service providers or security specialists;

  9. Take corrective or preventive measures; and

  10. Notify affected individuals, authorities, or other parties where required or appropriate under applicable law.

The specific response will depend on the nature, severity, scope, and circumstances of the incident.


7. Personal-Data Breach Response

Where Cry-Fi determines that a security incident may constitute a personal-data breach, Cry-Fi may assess:

  • What information was affected;

  • Which individuals may be affected;

  • Whether the information was accessed, disclosed, altered, lost, or otherwise compromised;

  • The nature and severity of potential risks;

  • Whether containment or mitigation measures are necessary;

  • Whether notification is legally required;

  • Which authorities or other parties may need to be notified; and

  • What remedial or protective measures may be appropriate.

Cry-Fi will take actions required by applicable law and may take additional reasonable measures where appropriate.


8. User Notification

Where notification is required by applicable law, or where Cry-Fi reasonably determines that notification is appropriate, affected users may be notified through reasonable communication methods, including:

  • Email

  • Account notifications

  • Platform notices

  • Other appropriate communication channels

The timing, method, and content of any notification may depend on:

  • The nature of the incident;

  • The information affected;

  • Potential risks to individuals;

  • Applicable legal requirements; and

  • Whether notification could interfere with a legitimate investigation or security response.

Cry-Fi cannot guarantee that every security incident will result in individual notification where notification is not legally required or reasonably appropriate.


9. Law Enforcement & Regulatory Cooperation

Cry-Fi may cooperate with:

  • Law enforcement agencies

  • Government authorities

  • Regulatory bodies

  • Courts

  • Cybersecurity investigators

  • Other competent authorities

where required or legally permitted.

Cry-Fi may preserve or disclose relevant information where legally required or otherwise permitted under applicable law.


10. Security Logs & Evidence Preservation

Cry-Fi may retain relevant technical records, logs, account information, and other information relating to:

  • Security incidents

  • Unauthorized access

  • Fraud

  • Account compromise

  • Abuse or misconduct investigations

  • Platform security

  • Disputes

  • Legal or regulatory requirements

Retention will be handled in accordance with Cry-Fi’s Privacy Policy and Data Retention & Deletion Policy, subject to applicable law.

Preservation of information for security or legal purposes does not necessarily mean that the information will be retained indefinitely.


11. Responsible Vulnerability Disclosure

If you identify a potential security vulnerability affecting Cry-Fi, you should report it responsibly rather than publicly exploiting, selling, or disclosing the vulnerability before Cry-Fi has had a reasonable opportunity to assess it.

Reports should include, where reasonably possible:

  • A description of the suspected vulnerability;

  • The affected feature, endpoint, or system;

  • Steps necessary to reproduce the issue;

  • Relevant technical information; and

  • The potential security or privacy impact.

Reports should contain only the minimum information reasonably necessary to demonstrate the issue.

Cry-Fi may investigate legitimate security reports and take appropriate action.

You must not:

  • Access accounts or information belonging to other users;

  • Extract, copy, modify, or disclose personal information;

  • Disrupt Platform availability;

  • Deploy malware or other harmful code;

  • Conduct destructive testing;

  • Circumvent security controls for purposes unrelated to demonstrating the vulnerability; or

  • Continue testing after being asked to stop.

Unauthorized access, exploitation, disruption, data extraction, or security testing against Cry-Fi systems or third-party systems without appropriate authorization is prohibited.

If you unintentionally access information that does not belong to you while investigating a suspected vulnerability, stop further access, do not copy or disclose the information, and report the issue responsibly.


12. No Guarantee of Absolute Security

Cry-Fi takes reasonable security measures but cannot guarantee that:

  • The Platform will never be attacked;

  • Unauthorized access will never occur;

  • All vulnerabilities will be detected;

  • All security incidents will be prevented;

  • Third-party systems will always remain secure;

  • User devices or credentials will remain secure; or

  • Information transmitted over the internet will be completely risk-free.

Users should understand that internet-based services carry inherent security and privacy risks.


13. Limitation of Responsibility

To the fullest extent permitted by applicable law, Cry-Fi is not responsible for security incidents arising solely from circumstances outside its reasonable control, including certain criminal attacks, compromised user devices or credentials, or failures within independent third-party systems.

Cry-Fi will nevertheless make reasonable efforts, within its control and subject to applicable law, to respond to significant security incidents and mitigate their effects.

Nothing in this Policy excludes or limits liability that cannot legally be excluded or limited.


14. Security Improvements

Cry-Fi may periodically review and improve its:

  • Security controls

  • Authentication systems

  • Access controls

  • Monitoring mechanisms

  • Infrastructure

  • Fraud and abuse prevention measures

  • Incident-response procedures

  • Data-protection practices

Security practices may change as the Platform, technology, and threat landscape evolve.

Cry-Fi does not guarantee that any particular security feature or control will remain available indefinitely.


15. Relationship With Other Policies

This Policy should be read together with Cry-Fi’s other applicable policies, including:

  • Terms & Conditions

  • Privacy Policy

  • Data Retention & Deletion Policy

  • Safety & Reporting Policy

  • Content Moderation Policy

  • Code of Conduct

  • Community Guidelines

  • Listener Agreement

  • Listener Vetting & Verification Policy

  • Registration Terms

  • Booking Terms

  • Refund & Cancellation Policy

Personal-information handling, retention, deletion, and user privacy rights are further governed by Cry-Fi’s Privacy Policy and Data Retention & Deletion Policy.


16. Policy Changes

Cry-Fi may update this Policy from time to time to reflect changes in the Platform, security practices, technology, threat environment, or applicable legal requirements.

Updated versions become effective upon publication unless otherwise stated.


17. Contact

General matters:

hello@cry-fi.com

Support:

support@cry-fi.com

Security or technical concerns:

safety@cry-fi.com

Sign In

Register

Reset Password

Please enter your username or email address, you will receive a link to create a new password via email.