VulnSea

Privacy Policy

Effective September 14, 2026 · Applies to https://beta.vulnsea.com (beta.vulnsea.com redirects here).

VulnSea aggregates public CVE and vulnerability intelligence and serves it to humans and automated agents. This policy explains what we collect, why, and the choices you have. We collect the minimum needed to run the service and we do not sell your data.

1. Who we are

VulnSea ("we", "us") is the operator of this service and the data controller for the personal data described below. Contact: [email protected].

2. What we collect

Account data (via OAuth). When you sign in with GitHub or Google, we receive and store your name, email address, profile image URL, and the provider account identifier. We also store OAuth tokens (access, refresh, id) and granted scopes so the sign-in works. We do not receive your provider password.

Service data you create. Your role, saved searches, watchlist entries, API keys, and any PoC requests you submit (including the optional note you attach). API keys are stored only as a SHA-256 hash plus a short display prefix — we cannot recover the full key after it is shown to you once.

Alerts & notifications. If you turn on alerts we store your minimum severity and, if you set one, the Slack / Discord / webhook URL you gave us, and we send matching CVE alerts to that URL. In-app notifications (saved-search matches, account events) are stored until you dismiss them.

PoC requests. A request is stored with your account id and email, the CVE id and your optional note. To act on it, the request (including your email) is also posted to our own operations channel (Slack / Discord, via a webhook we control). Requests are visible on the CVE page as a status only, never with your identity.

Lookups that leave the site. Asking for a CVE or GHSA id that is not in the corpus makes us fetch it from CVE.org, NVD or GitHub. Only the id travels — nothing about you. Similarly, community "trending" counts come from public Bluesky and Hacker News posts; we store counts per CVE, not the posts or their authors.

Operational logs. Request and error logs (structured JSON) with secrets and API keys redacted; an admin audit trail of moderation actions (ban, unban, delete, key revocation); and ingest/monitoring events. To rate-limit and protect the service, our edge (Cloudflare) and the app process your IP address transiently.

Error tracking (optional). If enabled, we forward exception data to Sentry to debug crashes.

Advertising. VulnSea is ad-supported. Pages may display third-party ads, and the ad network may set cookies or use device identifiers to serve and measure them under its own policy. Ads are served by Google AdSense — see how Google uses data in advertising and Google Ads Settings to opt out of personalised ads. Where required (EEA/UK/Switzerland) Google's consent prompt is shown before any personalised ad loads, and the browser Topics API is switched off for the whole site (Permissions-Policy: browsing-topics=()). Ads never appear on the API, the markdown records, the feeds or the MCP endpoint. Apart from the ad network's cookies, we set only the cookies required for authentication (session and CSRF).

Analytics. We may count page views with a cookieless, privacy-friendly analytics service (Plausible or Umami). It sets no cookies, stores no personal data, and does not track you across sites; it produces aggregate page counts only.

Sponsorship. Some pages may carry a clearly labeled sponsor line — a plain link with rel="sponsored", no scripts, no tracking. Sponsors have no influence over content. See /sponsor.

3. How we use it

  • Authenticate you and keep you signed in.
  • Provide the features you use (API access, saved searches, watchlist, alerts).
  • Operate, secure, rate-limit, and debug the service.
  • Enforce our Terms — including banning abusive accounts.

Legal bases (where GDPR applies): performance of our agreement with you (providing the service), and our legitimate interests in keeping the service secure and operational.

4. Sharing & processors

We do not sell personal data. We share data only with infrastructure providers that process it on our behalf:

  • Cloudflare — edge network, tunnel, and rate-limiting/WAF.
  • GitHub & Google — OAuth sign-in (only when you choose them).
  • Ad network — serves and measures the ads shown on the site (see Advertising above).
  • Sentry — error tracking, if enabled.
  • Hosting provider — the server (or VPS) the app runs on.
  • Backup storage — encrypted-in-transit copies of the database (which includes account data) are kept off-site with an object-storage provider (Backblaze B2 or Cloudflare R2).
  • Bluesky — we post CVE ids and titles to our own account; no user data is involved.
  • CVE.org, NVD, GitHub, FIRST.org, CISA — data sources we query; requests carry CVE ids, never your identity.

We may also disclose data if required by law.

5. Retention

We keep account data while your account is active. Operational logs are retained for a limited window. Local backups are kept for about two weeks and off-site copies for about five weeks. Audit-log entries are append-only and retained for security and accountability, and may persist after an account is deleted.

6. Your rights & choices

You can view and manage your API keys and saved searches from your account page, and revoke keys at any time. Depending on your location you may have rights to access, correct, export, or delete your personal data, and to object to certain processing.

You can delete your account yourself from the bottom of your account page ("Delete account"). Deletion removes your account record and cascades to your sessions, OAuth links, API keys, saved searches, and watchlist; append-only audit entries recording prior moderation actions are retained. To exercise any other right, email [email protected].

7. Security

Traffic is served over HTTPS through Cloudflare. API keys are hashed at rest, secrets are redacted from logs, and admin actions are audited. No system is perfectly secure, but we aim to apply reasonable safeguards.

8. Children

VulnSea is not directed to children under 16 and we do not knowingly collect their data.

9. International transfers

Our providers may process data in countries other than yours. Where required, transfers rely on appropriate safeguards offered by those providers.

10. Changes

We may update this policy as the service evolves. Material changes will be reflected by a new effective date at the top of this page.

11. Contact

Questions or requests: [email protected].

See also our Terms of Service.