Privacy Policy
HyprVuln Labs ("we", "us", "our") is committed to protecting your personal data. This privacy policy explains how we collect, use, and safeguard your information when you use our website and security audit and bug hunting services, in compliance with the General Data Protection Regulation (GDPR - EU Regulation 2016/679) and applicable French data protection laws.
1. Data Controller
Data controller: Bastien Picard — Entrepreneur individuel (EI), operating under the HyprVuln Labs brand
Business address: 6 rue Jean-Jacques de Cambacérès, 13200 Arles, France
Contact: contact@hyprvuln.xyz
2. Data We Collect
We collect and process the following categories of personal data:
| Data category | Purpose | Legal basis |
|---|---|---|
| Client identity (name, email, workspace, approved communication handles) | Service delivery, account access, communication | Contract performance |
| Program scope (assets, repositories, test accounts, exclusions) | Operating the security audit service | Contract performance |
| Source code (cloned temporarily) | Authorized testing and triage | Contract performance |
| Payment information | Processing transactions via Stripe | Contract performance |
| Technical data (IP address, browser type) | Website functionality and security | Legitimate interest |
We do not collect data beyond what is strictly necessary for providing our services.
3. How We Use Your Data
Your personal data is used exclusively to:
- Deliver the security audit and bug hunting services you request
- Communicate findings, triage notes, monitoring alerts, and reports
- Process payments through our payment provider (Stripe)
- Ensure the security and proper functioning of our website
- Comply with legal obligations
4. Source Code and Program Handling
Source code is our most sensitive material. We follow strict protocols:
- Code is cloned into an isolated, ephemeral environment dedicated to authorized testing or triage
- Temporary source code copies are scheduled for deletion no later than seven days after delivery, failure, or cancellation of the assessment
- Code is protected in transit and while stored for the authorized workflow
- HyprVuln does not train its own models on your code. External model processing is described below; provider retention and use depend on the applicable service terms and settings
- Code is disclosed only to documented service providers needed for the authorized workflow
- A mutual NDA is available upon request
For invited beta source audits, automated analysis sends source excerpts, assessment context, tool results, and generated findings through our FCC model gateway and OpenRouter. Both the automated scan and expert review can use this model processing. The beta default is DeepSeek V4.1 Flash, hosted by NovitaAI. DeepSeek V4 Pro (0813), using the DeepSeek endpoint, is an alternative that requires separate scope acceptance before your source is sent to it. Automatic fallback to another model or provider is disabled. Isolation of the assessment runner does not mean source material stays on our server: model requests leave it through our controlled gateway.
As checked on September 9, 2026, OpenRouter's provider directory lists direct DeepSeek as retaining prompts and using them for training. This provider-level listing does not establish the policy of a particular endpoint or any account-specific agreement. The default NovitaAI route and any alternative require review of their applicable endpoint policies and our account settings before private-code acceptance; our own source deletion schedule does not delete provider copies.
Before private source is accepted, we review the processing chain, provider terms, retention, account settings, and any project-specific restrictions as part of scope acceptance. We do not promise zero retention or EU-only model processing. Ask us about processing restrictions before uploading source or granting repository access.
5. Data Sharing
We do not sell, rent, or trade your personal data. We share data only with:
- GitHub — account connection and retrieval of the repository revision authorized for an assessment.
- OpenRouter and NovitaAI (or the separately accepted alternative provider) — routing and processing model requests for beta source audits, including the source material and assessment context described above. See OpenRouter's data collection documentation and provider handling policies. Provider terms and account settings require separate review; our local deletion schedule does not establish their retention period.
- Stripe — for payment processing (see Stripe's privacy policy)
- Resend — for account recovery email when enabled. Messages contain a one-time recovery link, not source code or audit findings.
- Approved communication platforms such as Slack or Discord when configured by the client
- OVH — for website hosting in France (see OVH's privacy policy)
We review processor safeguards and contractual terms before placing customer data in scope.
6. Data Retention
- Temporary source code and context copies: Scheduled for deletion seven days after delivery, failure, or cancellation. Original ZIP uploads expire after 24 hours. Code excerpts needed to understand a finding are retained with the report.
- Pentest credentials: Encrypted handoff credentials expire seven days after submission and are also removed during assessment cleanup. A new handoff may be needed for longer engagements.
- One-time assessments: Reports, findings, and associated assessment records are retained for twelve calendar months after delivery. Failed or cancelled assessments are retained for twelve months after that terminal event.
- Assessments with monitoring: Reports and findings remain available during the subscription. Their deletion is scheduled thirty days after cancellation takes effect, rather than when cancellation is first requested. Active testing must finish or be stopped before the assessment can be deleted.
- Account recovery links: Valid for one hour by default, usable once, and stored only as hashes. Expired token records are removed by regular cleanup.
- Payment records: Accounting records follow applicable French accounting retention requirements. Source handoff data and customer briefs are removed separately and are not retained as accounting documents.
- External communication messages: Subject to the configured platform's own retention policies
These periods apply to the application stores we operate. Cleanup runs regularly; a failed deletion is retried and is not recorded as successful. Earlier deletion of eligible assessment data can be requested. Backup and external-provider retention must be assessed separately; these periods do not assert immediate erasure of every infrastructure copy.
You may request deletion of eligible data at any time by emailing contact@hyprvuln.xyz.
7. Your Rights (GDPR)
Under the GDPR, you have the following rights:
- Right of access — Obtain a copy of all personal data we hold about you
- Right to rectification — Request correction of inaccurate data
- Right to erasure — Request deletion of your personal data
- Right to restriction — Request limitation of processing
- Right to data portability — Receive your data in a structured, machine-readable format
- Right to object — Object to processing based on legitimate interest
- Right to withdraw consent — Where processing is based on consent, withdraw it at any time
To exercise any of these rights, email contact@hyprvuln.xyz. We will respond within 30 days.
You also have the right to lodge a complaint with the French data protection authority: CNIL (Commission Nationale de l'Informatique et des Libertes) — www.cnil.fr.
8. International Transfers
Hosting in France does not mean all processing takes place in France or the European Union. GitHub, payment and communication services, and the OpenRouter/NovitaAI model-processing chain or a separately accepted alternative may involve processing outside the EU. Applicable processing locations and transfer safeguards must be established for the accepted project before private source is submitted. Contact us for the arrangements applicable to your assessment; this policy does not assert that a particular transfer agreement has already been verified for every provider.
9. Security Measures
We use technical and organizational measures to protect your data:
- Encrypted transport for the authenticated service
- Access controls for stored customer material
- Isolated, ephemeral environments for code analysis and report reproduction
- Access restricted to authorized HyprVuln operators and vetted researchers as required by the approved program scope
- No persistent storage of source code beyond the approved program workflow
10. Cookies
For information about how we use cookies, please see our Cookie Policy.
11. Changes to This Policy
We may update this privacy policy from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review this policy periodically.