← Back

Privacy Policy

Last updated June 2026

This Privacy Policy explains how Cecuro, Inc. ("we," "us," or "our") collects, uses, and shares information when you use BountyHunt (the "Service"). BountyHunt is a public-information aggregator for bug-bounty and audit programs; most of what it displays is public third-party data, not personal information about you.

1. Information we collect

  • Account identity. When you sign in with Google or GitHub, we receive your email address, name, and basic profile information from that provider, plus the session needed to keep you signed in.
  • Things you create. API keys (stored only as a hash), webhook subscriptions (including the endpoint URL, any custom headers you add, and a signing secret), program watches, and similar configuration.
  • Billing information. If you purchase a paid plan, our payment processor (Stripe) collects and handles your payment details; we receive transaction identifiers, status, amounts, and invoice records (we do not store full card numbers).
  • Usage & operational data. Request and error logs (e.g. webhook delivery outcomes), and usage and analytics data about how you interact with the Service, used to run, secure, debug, and improve it.
  • Cookies & analytics. We use a session cookie to keep you signed in, and our product-analytics provider (PostHog) sets cookies and uses local storage to measure how the Service is used (such as pages visited and features clicked). These are used to operate and improve the Service, not for third-party advertising. We do not record your screen or capture the values you type. You can clear or block these cookies in your browser; the sign-in cookie is required to use an account.

2. How we use information

  • provide the Service: authenticate you, store your subscriptions, and deliver webhooks;
  • operate, secure, debug, and improve the Service and prevent abuse;
  • process payments and maintain billing records (for paid plans);
  • develop and improve the Service and its features (including AI/ML models) using platform-generated and aggregated interaction data (see Section 4);
  • send essential service-related communications;
  • comply with legal obligations and enforce our Terms.

3. Service providers (subprocessors)

We do not sell your personal information. We share information with the providers we use to run BountyHunt:

  • Cloudflare — hosting, the application database (D1), and infrastructure logs.
  • Google Cloud Platform — cloud storage and compute.
  • Microsoft Azure — cloud services, including Azure OpenAI for AI processing.
  • Google and GitHub — sign-in (OAuth) identity providers; we receive profile/email per your authorization.
  • PostHog — product analytics (how the Service is used).
  • Telegram — notification delivery (direct messages).
  • Stripe — payment processing.

Our payment processor handles sensitive financial data under its own policies and industry standards (e.g. PCI DSS). We may also disclose information when required by law or to protect our rights and safety, and in connection with a merger, acquisition, or asset sale (with notice where required).

4. AI processing & use of platform data

We use a third-party AI / large language model provider (Microsoft Azure OpenAI, and we may change providers over time) to parse and classify the public third-party listings we aggregate. Content sent to the provider is subject to that provider's own terms and privacy policy.

We may use data generated within the Service and aggregated or de-identified information about how users interact with it to operate, secure, improve, and develop the Service and its features, including AI/ML models. When we offer our own first-party programs or assets, we may use that content as our own. We do not sell your personal information.

5. Aggregated public data

The bug-bounty, program, and audit information shown in BountyHunt is collected from public sources. It primarily concerns organizations and projects rather than individuals; we are not the authoritative source for it. See the Terms for our no-affiliation and accuracy disclaimers.

6. Retention & security

We keep account and configuration data while your account is active and delete or anonymize it on request, subject to legitimate retention needs (e.g. abuse-prevention, legal). We use industry-standard safeguards including encryption in transit, but no method of transmission or storage is 100% secure.

7. Your rights & choices

Depending on where you live, you may have rights to access, correct, delete, or export your personal information, or to object to or restrict its processing. You can delete your account at any time. To exercise any right, contact privacy@cecuro.ai. Our Service is not directed to children under 13 (or under 16 in the EEA/UK), and we do not knowingly collect their information.

8. International transfers & changes

Your information may be processed in countries other than your own, with appropriate safeguards. We may update this Policy and will post the new version with a new "Last updated" date.

9. Contact

Privacy questions: privacy@cecuro.ai. Postal: Cecuro, Inc., 2261 Market Street STE 86548, San Francisco, CA 94114, USA.

Terms & Conditions Privacy Policy

We use cookies to improve your experience. You can opt out of analytics cookies. Find out more in our privacy policy.