Legal · Privacy

Privacy Policy

How VulnX collects, uses, and protects your data. We process the minimum data needed to operate the service.

2026Edition year
5Data categories
0Third-party trackers
1Contact channel

Section 01

What this platform does

VulnX is a self-hosted web vulnerability scanner. Registered users submit a target URL and the platform runs automated security checks against that single domain (no subdomain enumeration). We process the minimum data needed to operate the service.

Section 02

Information we collect

Account information

Username, email address, full name, country, and an optional company name, plus a password stored only as a salted ARGON2ID hash.

Scanner usage data

The target URLs you scan, scan status/progress, scanner findings, and HTTP request metadata (URL, status code, duration) generated by scans you run.

Logs

Server and application logs — timestamps, IP addresses, request paths — used for security monitoring, abuse prevention, and debugging.

Cookies & sessions

A session cookie (HttpOnly, SameSite=Lax) to keep you logged in, and a CSRF token per session. No third-party tracking cookies are set.

Contact submissions

When you use the contact form, we store your name, email, optional company, subject, message, and IP address so we can respond and prevent abuse.

Section 03

How we use information

Operate Your Account Provide and operate your account and scans. Display scan history and reports to you (and only you).
Prevent Abuse Rate limiting, brute-force protection, duplicate-account detection, and CSRF defense all rely on the data above.
Improve Reliability Aggregate, non-identifying statistics about platform usage. Respond to contact submissions promptly.

Section 04

What we do NOT collect

No plaintext passwords (only one-way hashes). No payment card numbers or billing details. No content of websites you scan (only the security metadata). No precise geolocation, browsing history, or device fingerprints.

Section 05

Data retention

Active accounts

Account records are kept while your account is active.

Scan records

Scans, findings, and logs are retained for operational and security purposes and may be purged automatically after a retention window (see the admin panel).

Deletion

You may delete individual scans at any time; account deletion is available on request.

Section 06

Sharing of information

We do not sell personal data. Data is shared only with:

Third-party security APIs
Public DNS, SSL/TLS, CVE-lookup — only the target hostname you authorized is sent, never your credentials.
Service providers
Infrastructure operators bound by confidentiality obligations.
Authorities
Where required by law or to prevent illegal activity.

Section 07

Security monitoring

We monitor the platform for abuse, brute-force attempts, and anomalous activity. IP addresses of failed authentication attempts and contact submissions are retained for this purpose.

Section 08

Your rights

Depending on your jurisdiction you may have rights to access, correct, export, or delete your personal data. Contact us using the contact page and we will respond to verified requests.

Section 09

Changes to this policy

We may update this policy as the platform evolves. Material changes will be announced on this page with an updated date.

Section 10

Contact

Privacy questions: use the contact page and we'll get back to you. Last updated: September 7, 2026.