Privacy Policy

Last updated: August 2026

What we collect

When you sign in, we store your email, display name, and profile photo from your Google or GitHub account. We do not collect phone numbers, addresses, or payment card details directly. Payment processing is handled by our payment provider; we never see your card number.

How we use it

We use your account information to identify you, match you to submissions, and send transactional emails about your listings or reports. We do not sell your data or use it for advertising.

What we store

We keep the data needed to run the platform: your account details, bounty listings, private submissions, credit ledger entries, and locale preference. Sessions are stored in cookies to keep you signed in.

Private submissions

Bug reports and proof submitted by hunters are private. Only the founder who owns the listing can see them. We do not publish, share, or use submission content beyond delivering it to the intended recipient.

Sharing

We share data only with service providers necessary to run OopsBounty: our hosting infrastructure, payment processor, and analytics. These providers are contractually required to protect your data and may not use it for their own purposes.

Cookies

We use session cookies to keep you signed in. We also store your locale preference in your browser. We do not use third-party tracking cookies or cross-site cookies.

Data retention

We keep your account data as long as you have an account. If you delete your account, we remove your personal information within 30 days. Aggregated, anonymized data may be retained for analytics.

Your rights

You can request access to or deletion of your personal data by contacting us. We will respond within 30 days.

Changes

If we change this policy, we will update the date above and post the revised policy here. Continued use of OopsBounty after changes means you accept the updated policy.

Contact

Questions about this policy? Reach out atprivacy@oopsbounty.com