Privacy Policy
Last updated: 2026-06-11
Draft notice: This document is a starting draft and is pending review by legal counsel. It describes our current intended practices but is not yet final.
This Privacy Policy explains what information hacktool.io (“HackTool”, “we”, “us”) collects when you use our website and desktop application, why we collect it, and the choices you have. HackTool is a local-first security testing platform: scans run on your own machine, and we deliberately keep the data we hold to a minimum.
1. Information We Collect
- Account information (via Clerk). When you create an account we use Clerk for authentication. This includes your email address, name (if provided), and authentication identifiers. Passwords and login credentials are managed by Clerk; we never see or store your password.
- Payment information (via Stripe). Subscriptions are processed by Stripe. Your card number and full payment details are submitted directly to Stripe; we never receive or store your card data. We retain only Stripe’s subscription status, customer/subscription identifiers, and billing metadata needed to manage your plan.
- Application and license data (in Convex). We store license state, plan/entitlements, device activation for the single-device license, and limited account metadata in Convex, our serverless database. The desktop scanner runs locally, and scan targets and findings are not uploaded to us unless you explicitly export or share them. They do not necessarily stay on your device, however: if you enable the AI Operator, scan data is sent to the AI provider you choose. See section 2.
- Transactional email (via Resend). We use Resend to send account, billing, and support emails to the address associated with your account.
- Operational data (via Vercel and Cloudflare). Our website is served through Vercel and Cloudflare, which process standard request logs (IP address, user agent, timestamps) for hosting, security, and abuse prevention.
- Analytics and advertising (via Google). On our marketing website we use Google Analytics 4 to understand how visitors find and use the site, and Google Ads to measure the performance of our advertising campaigns. Where consent is required, these load only after you opt in, and we use Google Consent Mode so no analytics or advertising cookies are set until then. This applies to the website only; the desktop application contains no analytics or advertising trackers.
2. Data the Desktop Application Sends
The scanner itself runs entirely on your machine. The desktop application does make four kinds of outbound connection, and because you may be testing on behalf of a client, we set them out in full here rather than in general terms.
- AI Operator (your own API key). The Operator is off unless you turn it on and supply your own API key. When it runs, it sends the data it is reasoning about — target URLs, HTTP requests and responses, and finding evidence — to the AI provider you have configured: Anthropic, OpenAI, Google, or any OpenAI-compatible endpoint whose address you enter yourself. That data goes directly from your machine to that provider and does not pass through us. Your relationship for it is with that provider, under their terms and their retention policy. If you are testing a client’s systems, their data will leave your machine when you use this feature. We recommend confirming that your engagement permits it.
- Vulnerability (CVE) lookup. If you enable online CVE lookup, the application queries our CVE service to enrich findings. This is opt-in and you are asked on first run. It sends the software fingerprints being looked up, not your scan results.
- In-app feedback. If you submit feedback from inside the application, we receive what you wrote, the category you picked, your application version, your operating system and processor architecture, and your license token so we can identify the account. Only sent when you press send.
- Update checks. The application periodically checks for new versions. This contacts our update endpoint and GitHub, which hosts the installer files. Both see your IP address and the version you are running, as any download does. No scan data is involved.
Everything else — your targets, your findings, your reports — stays on your machine unless you export or share it deliberately.
3. Cookies and Tracking
Our website uses a few categories of cookies and similar storage:
- Essential. Required to run the site: keeping you signed in (Clerk session cookies) and remembering preferences such as your theme. These are always on.
- Analytics. Google Analytics 4, to measure traffic and understand how the site is used.
- Advertising. Google Ads, to measure conversions from our advertising and, where applicable, show relevant ads.
Analytics and advertising cookies are set only with your consent where consent is required (for example in the EU/EEA and UK). We use Google Consent Mode, which keeps these categories off until you opt in. You can opt out of Google Analytics with Google’s opt-out browser add-on and manage ad personalization in Google Ad Settings. You can change or withdraw your choice anytime using the Cookie preferences link in our footer. The desktop application sets no analytics or advertising cookies.
4. How We Use Your Data
- To create and authenticate your account.
- To process your subscription and manage billing.
- To validate and activate your single-device desktop license.
- To send essential account, billing, and support communications.
- To secure the service and prevent abuse.
We do not sell your personal data. We use Google Analytics and Google Ads to measure traffic and advertising performance, which can involve sharing limited online identifiers (such as cookie IDs) with Google for those purposes, subject to your consent. We do not otherwise share your personal data for third-party advertising.
5. Data Retention
We retain account and license data for as long as your account is active. If you cancel and request deletion, we delete personal account data within 30 days, except where we are required to retain limited billing records for tax and accounting purposes (typically retained by Stripe for the period required by law). Local scan data lives on your device and is removed when you delete it there.
6. Your Rights (GDPR / CCPA)
Depending on your location, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Under the CCPA, you have the right to know what we collect and to request deletion; we do not sell personal information, so there is no “opt out of sale” to exercise.
To exercise any of these rights, email support@hacktool.io. We will verify your request and respond within the timeframe required by applicable law.
7. Sub-processors
We rely on the following service providers to operate HackTool. Each processes data only as needed to provide its service:
| Provider | Purpose |
|---|---|
| Clerk | Authentication and account management |
| Stripe | Subscription and payment processing |
| Convex | Serverless database (license & account data) |
| Resend | Transactional email delivery |
| Vercel | Website hosting and edge delivery |
| Cloudflare | CDN, DNS, and DDoS protection |
| GitHub | Desktop application update feed and installer downloads |
| Website analytics (GA4) and advertising measurement (Google Ads) |
8. Changes to This Policy
We may update this policy as the product evolves. Material changes will be reflected by updating the “Last updated” date above, and where appropriate we will notify you by email.
9. Contact
Questions about this policy or your data? Email support@hacktool.io.