Cookie Policy
This Cookie Policy explains how HyprVuln Labs ("we", "us", "our") uses cookies and similar technologies on our website and client console at hyprvuln.xyz, in compliance with the EU ePrivacy Directive (2002/58/EC) and the GDPR.
1. What Are Cookies
Cookies are small text files stored on your device (computer, tablet, or mobile) when you visit a website. They help the website recognize your device and remember certain information about your visit, such as your preferences or actions.
2. Our Approach
We take a minimal approach to cookies. Our public pages are primarily static; the authenticated console uses essential cookies for account security. We do not use advertising cookies, marketing trackers, or social media pixels. We do not track you across websites.
3. Cookies We Use
| Cookie | Type | Purpose | Duration |
|---|---|---|---|
| __Host-session | Strictly necessary | Keeps you signed in to the client console. In local development the cookie is named hv_session. | Up to 7 days, with a 12-hour idle limit |
| __Host-hv_oauth | Strictly necessary | Protects the temporary GitHub sign-in transaction. In local development the cookie is named hv_oauth_txn. | 10 minutes |
| Stripe | Strictly necessary | When you proceed to payment, Stripe may set cookies required for fraud detection and secure payment processing. | Per Stripe's policy |
We do not use:
- Analytics cookies (no Google Analytics, no Plausible, no Fathom)
- Advertising or retargeting cookies
- Social media tracking pixels
- Third-party marketing cookies
4. Third-Party Services
Our website links to third-party services that have their own cookie policies:
- Discord — When you click a Discord link, Discord's own cookies apply. See Discord's privacy policy.
- Stripe — When processing payments, Stripe uses cookies for security and fraud prevention. See Stripe's cookie policy.
- Google Fonts — The public landing page currently requests font files from Google. See Google's privacy policy.
5. Managing Cookies
Since we only use strictly necessary cookies, no consent banner is required under EU law. However, you can control cookies through your browser settings at any time:
Common browsers
- Chrome: Settings → Privacy and security → Cookies and other site data
- Firefox: Settings → Privacy & Security → Cookies and Site Data
- Safari: Preferences → Privacy → Manage Website Data
- Edge: Settings → Cookies and site permissions → Cookies and data stored
Please note that blocking all cookies may affect the functionality of certain website features, including payment processing.
6. Local Storage and Similar Technologies
In addition to cookies, websites can use other storage mechanisms such as localStorage and sessionStorage. The HyprVuln service uses local storage for UI preferences and an in-progress order draft.
The HyprVuln web app may additionally store in your browser a draft audit configuration (the plan and repository you are about to submit) and interface preferences such as your chosen language. Draft fields are sent to the service only when you submit the order; they can be cleared from your browser's site-data settings before then.
7. Do Not Track
We respect "Do Not Track" (DNT) browser signals. Since we do not use tracking cookies or analytics, your browsing on our site is not tracked regardless of your DNT settings.
8. Changes to This Policy
If we ever introduce new cookies (for example, analytics), we will update this policy and implement a cookie consent mechanism before doing so. Changes will be posted on this page with an updated revision date.
9. Contact
For any questions about our use of cookies, email contact@hyprvuln.xyz.
You also have the right to contact the French data protection authority (CNIL) at www.cnil.fr.
See also our Privacy Policy.