Legal
Privacy Policy
Last updated: January 1, 2025
This Privacy Policy explains how BugBounty (“we”, “us”, “our”) collects, uses, and protects your personal information when you use our platform. We are committed to handling your data responsibly.
1. Information We Collect
Account information: When you register, we collect your email address, chosen display name (nickname), and hashed password. Organization administrators additionally provide a company name.
Profile information: Hackers may submit identity verification information as part of the verification process. This information is used solely to confirm eligibility and is not shared publicly.
Report content: Vulnerability reports, comments, and any file attachments you upload are stored and associated with your account. Organization staff and platform administrators may view this content.
Usage data: We collect server logs including IP addresses, browser user-agent strings, and timestamps for security, rate-limiting, and audit purposes. This data is retained for 90 days.
2. How We Use Your Information
We use the information we collect to:
- Operate and improve the Platform
- Authenticate you and protect your account
- Send transactional emails (verification, password reset, report status changes)
- Investigate abuse, fraud, and security incidents
- Comply with legal obligations
We do not sell your personal data to third parties. We do not use your data for advertising purposes.
3. Sharing of Information
With organizations: When you submit a vulnerability report to a Program, the report content, your nickname, and reputation score are visible to the organization's administrators. Your email address is not shared.
With service providers: We use the following sub-processors to operate the Platform:
- Supabase — database and file storage (EU/US)
- Resend — transactional email delivery
- Upstash — rate-limiting (Redis-compatible, serverless)
- Vercel — hosting and edge functions
Each sub-processor is bound by a data processing agreement. We do not share your data with any other third parties without your explicit consent, except where required by law.
4. Data Retention
We retain your account data for as long as your account is active. If you request account deletion, we will delete your personal information within 30 days, except where we are required to retain it by law or for legitimate security audit purposes.
Vulnerability reports and audit logs may be retained beyond account deletion to preserve the integrity of the security record.
5. Security
We implement industry-standard security measures including:
- Passwords hashed with bcrypt (cost factor 12)
- Session tokens signed with HMAC-SHA256 and stored in httpOnly cookies
- All data in transit encrypted via TLS 1.2+
- File attachments stored in private, access-controlled buckets with signed URLs
- Rate limiting on authentication endpoints
No security system is infallible. If you discover a vulnerability in our own infrastructure, please report it through our Responsible Disclosure policy.
6. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, or delete your personal data, or to object to or restrict its processing. To exercise these rights, contact us through the Platform. We will respond within 30 days.
7. Cookies
We use a single session cookie (bb_session) to authenticate you. This cookie is httpOnly, SameSite=Lax, and Secure in production. We do not use third-party tracking cookies or analytics cookies.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes via email. Continued use of the Platform after changes are posted constitutes acceptance.