Last updated: August 23, 2026

Privacy Policy

1. Introduction

HackAdvisor Labs ("we", "us", "our"), operated at labs.hackadvisor.io as part of the HackAdvisor ecosystem, is committed to protecting your privacy and personal data. This Privacy Policy explains what information we collect, how we use it, how we protect it, and what rights you have regarding your data. This policy applies to all users of the Platform, including individual users, organization members, and assessment candidates. By using the Platform, you acknowledge that you have read and understood this Privacy Policy. We process personal data in compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

2. Information We Collect

Account Information

When you register, we collect your username, email address, and password. Passwords are processed by Django's salted one-way password hasher and are never stored in plaintext. You may optionally provide profile information such as a bio, location, social media links, and avatar image.

Usage Data

We automatically collect information about your interactions with the Platform, including: challenges attempted and solved, time spent on challenges, hints requested, points earned, container start and stop events, flag submission attempts, and certificate generation events.

Technical Data

For security, abuse prevention, rate limiting, and service improvement, the Platform processes IP addresses, user-agent/browser information, referral paths, request timestamps, and request outcomes. Lab-traffic IP addresses are replaced with stable private HMAC pseudonyms before database storage. Security and organization audit records retain a source IP and user-agent for up to 90 days for incident investigation; after that window the IP is replaced with a purpose-scoped HMAC pseudonym and the user-agent and direct email/account labels are removed or pseudonymized. Optional website analytics is processed only after consent.

Assessment Candidate Data

If you participate in an organizational assessment, we collect your name (as provided by the inviting organization), challenge completion data, time taken, and hints used. This data is shared with the organization that invited you to the assessment. Assessment participation does not require full account registration.

B2B and commercial requests

If you request a demo or, as an organization owner, ask to renew or change a plan, we retain the company name, contact name, work email, team size, message, language, request source and type, requested plan, consent time, and consent-policy version. This information is used only to handle the B2B request.

3. Legal Basis for Processing (GDPR)

We process your personal data on the following legal bases under the GDPR:

  • Contract performance: Processing necessary to provide you with the Platform services you signed up for (account management, challenge access, leaderboard functionality, certificate issuance)

  • Consent: Processing based on your explicit consent, such as optional profile information, a B2B or organization commercial request, and marketing communications (you may withdraw consent at any time)

  • Legitimate interest: Processing necessary for our legitimate interests, such as Platform security, fraud prevention, service improvement, and aggregated analytics, where these interests are not overridden by your rights

  • Legal obligation: Processing necessary to comply with applicable laws, such as responding to lawful requests from authorities

4. How We Use Your Information

We use the information we collect for the following purposes:

  • Providing and maintaining the Platform, including account management, challenge delivery, and container orchestration

  • Displaying public achievement data (username, points, solve count, rank, and completed public challenges); active sessions and failed attempts are not shown publicly

  • Sending essential notifications about your account, security alerts, and important Platform updates

  • Preventing abuse, fraud, unauthorized access, and enforcing our Terms of Service

  • Improving the Platform, developing new features, and optimizing user experience based on aggregated usage patterns

  • Generating anonymized and aggregated analytics to understand Platform usage trends

  • Issuing and verifying certificates of achievement linked to your username and solved challenges

  • Handling the B2B demonstration you requested and contacting the supplied work email; request data is automatically deleted no later than 365 days after submission

5. Data Storage and Security

Primary application data is stored on the Platform's production host in Moscow, Russia. Encrypted disaster-recovery snapshots are also kept locally and with a separately controlled S3-compatible off-site provider. We use TLS/HTTPS in transit, encrypted Restic backups, AES-256-GCM for vulnerability reports, salted one-way password hashing, access controls, rate limiting, email verification, and security monitoring. No storage or transmission method is absolutely secure; provider and jurisdiction changes are reviewed before production configuration is changed.

6. Cookies and Tracking Technologies

We use a minimal set of cookies and similar technologies necessary for Platform operation:

Essential Cookies (Strictly Necessary)

Authentication uses an opaque Secure, HttpOnly, SameSite session cookie and a separate non-secret CSRF cookie. Local and OIDC credentials remain in the server-side session store; OIDC token material is additionally encrypted at rest and is not stored in browser local storage. Browser sessions expire after no more than seven days, are cleared on logout, and are not used to track you across other websites.

Cloudflare Turnstile

We use Cloudflare Turnstile on login, registration, and password reset pages to prevent automated attacks. Turnstile may store data needed for bot detection under Cloudflare's privacy policy. Only after you accept analytics in the cookie banner may we load Google Tag Manager and PostHog; declining analytics does not prevent use of the Platform. We do not intentionally use advertising cookies or social-media tracking pixels.

7. Challenge Container Data

Challenge containers run in isolated per-instance environments and are removed when the lab stops or expires. To improve and generate defensive training material, we retain HTTP method, path, status, timing, size, user-agent, referral path, a pseudonymous IP, and up to 8 KB of request-body text for no more than 30 days. Before database storage, automated filters remove known secret fields, authorization tokens, JWTs, flags, email addresses, control characters, referral origins, and query strings from referrers; response bodies are not collected. Filtering reduces risk but cannot recognize every possible identifier, so never enter real credentials or personal data into a training lab.

8. Third-Party Services

We share data with the following third-party service providers, each of which has their own privacy policy:

  • Cloudflare -- Turnstile CAPTCHA and DNS; CDN/DDoS proxying may also be enabled by the operator. Cloudflare processes browser and traffic data needed for the enabled security services.

  • SMTP Provider (smtp.mail.ru) -- Transactional email delivery for account verification, password resets, organization invites, and internal notification of a requested B2B demo. We share the email address and necessary message body for delivery purposes only.

  • SERV.HOST -- primary server hosting in Moscow, Russia. A separately encrypted off-site backup is stored with the S3-compatible provider approved in the production configuration; current provider and jurisdiction details are available from admin@hackadvisor.io.

  • Google Tag Manager and PostHog -- optional site analytics loaded only after your consent and excluded from sensitive invite, assessment, email-verification, and password-reset routes. PostHog receives explicitly emitted events and route paths without query strings; autocapture and session recording are disabled. The configured GTM container may load only tags approved by the Platform operator.

  • Anthropic and OpenAI -- AI-assisted lab generation, investigation/report review, and designated AI training labs. Content submitted to an AI-assisted feature, including an organization vulnerability report or incident report when that feature is requested, may be transmitted to the configured AI provider. Do not submit third-party personal data without authority.

  • Sentry (when configured) receives scrubbed error diagnostics without default PII. Telegram (when configured) receives feedback or operational notifications sent to administrators. These services may process data outside Russia.

  • Polygon blockchain (when enabled) -- certificate level and number are published to a global, public, irreversible ledger. Future mints do not include an account identifier. Historical transactions may contain the username that existed at mint time and cannot technically be altered or erased from the blockchain; contact admin@hackadvisor.io before account deletion if this affects you.

We do not sell, rent, or trade your personal information to any third party. We do not share your data with advertising networks or data brokers.

9. Organization Data

If you are a member of an organization on the Platform, your organization administrator can view your activity within the organization context, including challenges assigned, completion status, and performance metrics. Organization data is strictly isolated -- administrators of one organization cannot access data from another organization. Vulnerability reports uploaded by organizations are encrypted at rest using AES-256-GCM; detected PII values are not duplicated into plaintext metadata. Audit events are retained for the lifetime of the organization, while direct network identifiers and email/account target labels in those events are removed or pseudonymized after 90 days. If you leave an organization, your historical activity data within that organization (solves, assessment results) is retained for the organization's records, but your personal profile information is no longer accessible to the organization.

10. Assessment Candidate Data

If you participate in an assessment as a candidate, the organization that created it can access your attempts, completion status, time taken, hints, notes, and results. Assessment data is isolated to that organization and retained while needed for the assessment and the organization's legitimate records, subject to contractual and legal requirements. Candidates may request access, correction, or deletion by contacting the inviting organization or admin@hackadvisor.io.

11. Data Retention

Account and learning records are retained while the account is active. Self-service deletion removes the active account, profile, avatar, and personal solve/activity records immediately after ownership checks; public certificate records remain with the holder replaced by 'Deleted user', and narrowly scoped security/audit events may remain where legally necessary. Historical Polygon transactions cannot be erased; future mints contain no account identifier. Encrypted backup snapshots age out under a 14-daily, 8-weekly, and 12-monthly policy and are used only for disaster recovery. Pseudonymized lab-traffic records are deleted after 30 days. B2B demo requests and commercial requests from existing organizations are automatically deleted no later than 365 days after submission. Organization assessment and audit events are retained for the organization's legitimate, contractual, and legal needs, but raw audit IP, user-agent, email target labels, and account target labels are retained for no more than 90 days before removal or pseudonymization. Email verification values are stored only as keyed digests and expire after 30 minutes; password-reset links expire after 1 hour. Irreversibly aggregated data may be retained longer.

12. Your Rights Under GDPR

Under the General Data Protection Regulation (GDPR) and applicable data protection laws, you have the following rights regarding your personal data:

  • Right of Access -- You can view your personal data at any time through your profile page (/me). You may also request a complete copy of all data we hold about you.

  • Right to Rectification -- You can update and correct your personal information through your account settings (/me/settings) at any time.

  • Right to Erasure ("Right to be Forgotten") -- You can request deletion of your active account and associated personal data through account settings or admin@hackadvisor.io. Public certificate records are anonymized rather than removed, organization records may require a lawful retention decision, and historical Polygon entries cannot technically be altered. We process rights requests within 30 days.

  • Right to Data Portability -- You can export your personal data in a machine-readable format through your account settings. This includes your profile information, challenge history, and points.

  • Right to Restriction of Processing -- You can request that we restrict processing of your personal data in certain circumstances, such as while we verify the accuracy of your data.

  • Right to Object -- You can object to the processing of your personal data for certain purposes, such as direct marketing. We do not currently engage in direct marketing.

  • Right to Withdraw Consent -- Where processing is based on your consent, you may withdraw it at any time. This will not affect the lawfulness of processing based on consent before its withdrawal.

To exercise any of these rights, use the self-service tools available in your account settings or contact us at admin@hackadvisor.io. We will respond to all data rights requests within 30 days as required by the GDPR. If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.

13. International Data Transfers

Primary application storage is in Russia. Cloudflare, consent-based analytics, AI providers, Sentry, Telegram, email delivery, the configured encrypted off-site backup, and the global Polygon ledger may process or publish data in other countries. We limit the data sent to each service, encrypt backups before transfer, no longer include account identifiers in new Polygon mints, and require the operator to approve the provider, destination, and applicable legal safeguards before enabling a production integration.

14. Children's Privacy

The Platform is not intended for children under the age of 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at admin@hackadvisor.io, and we will take steps to delete such information promptly.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. Material changes will be communicated through a prominent notice on the Platform or by email at least 14 days before the changes take effect. We encourage you to review this policy periodically. The "Last updated" date at the top indicates when the policy was last revised.

16. Contact and Data Protection

For any privacy-related questions, concerns, data access requests, or to exercise your GDPR rights, please contact us at admin@hackadvisor.io

When contacting us about data rights, please include your username and the email address associated with your account so we can verify your identity and process your request efficiently. We aim to respond to all inquiries within 30 days.

Terms of Service