Privacy Policy
Last updated: August 2026
What we collect
When you sign in, we store your email, display name, and profile photo from your Google or GitHub account. We do not collect phone numbers, addresses, or payment card details directly. Payment processing is handled by our payment provider; we never see your card number.
How we use it
We use your account information to identify you, match you to submissions, and send transactional emails about your listings or reports. We do not sell your data or use it for advertising.
What we store
We keep the data needed to run the platform: your account details, bounty listings, private submissions, credit ledger entries, and locale preference. Sessions are stored in cookies to keep you signed in.
Private submissions
Bug reports and proof submitted by hunters are private. Only the founder who owns the listing can see them. We do not publish, share, or use submission content beyond delivering it to the intended recipient.
Sharing
We share data only with service providers necessary to run OopsBounty: our hosting infrastructure, payment processor, and analytics. These providers are contractually required to protect your data and may not use it for their own purposes.
Cookies
We use session cookies to keep you signed in. We also store your locale preference in your browser. We do not use third-party tracking cookies or cross-site cookies.
Data retention
We keep your account data as long as you have an account. If you delete your account, we remove your personal information within 30 days. Aggregated, anonymized data may be retained for analytics.
Your rights
You can request access to or deletion of your personal data by contacting us. We will respond within 30 days.
Changes
If we change this policy, we will update the date above and post the revised policy here. Continued use of OopsBounty after changes means you accept the updated policy.
Contact
Questions about this policy? Reach out atprivacy@oopsbounty.com