TraceX - Private Skill-based Bug Bounty & Managed Disclosure PlatformLearn More
Legal

Privacy Policy

This Privacy Policy explains how BugsTrace, Inc. ("BugsTrace," "we," "us," or "our") collects, uses, shares, and protects personal information when you use our websites, platforms, products, APIs, dashboards, communities, training services, security tools, and related services.

Last updated: June 4, 2026
01

Scope

This Privacy Policy applies to BugsTrace services, including BugsTrace Platform, BugsTrace Academy, BugsTrace Trigger, BugsTrace Agent, BugsTrace Copilot, BugsTrace Intel, BugsTrace Radar, managed disclosure services, private bug bounty programs, APIs, integrations, support channels, and related websites.

This Privacy Policy does not apply to third-party websites, services, or tools that we do not control.

02

Information We Collect

We may collect the following categories of information.

Account and Identity Information — this may include name, email address, username, password credentials, company name, job title, country, profile photo, account role, researcher profile, skill level, verification status, certification status, and account preferences.

Company and Program Information — for customers, we may collect company details, billing information, authorised users, security contacts, program scope, target assets, domains, IP ranges, application details, cloud environment information, bounty rules, disclosure preferences, and remediation workflow information.

Researcher and Academy Information — for researchers and learners, we may collect skill assessments, CTF performance, certifications, submitted reports, reputation data, program invitations, assignment history, payout details, learning progress, and profile tags such as web, API, mobile, cloud, infrastructure, binary, or other security categories.

Vulnerability Reports and Security Content — we may collect vulnerability reports, proof-of-concepts, screenshots, logs, affected URLs, code snippets, reproduction steps, severity assessments, business impact descriptions, remediation notes, comments, attachments, and triage decisions. You should avoid submitting unnecessary personal data, secrets, credentials, customer data, production data, or sensitive information unless required and authorised for a valid security report.

Payment and Billing Information — we may collect billing name, billing address, tax information, invoice records, subscription details, payment status, payout records, and limited payment metadata. Full payment card or banking details may be processed by third-party payment providers.

Device, Usage, and Log Information — we may collect IP address, browser type, device type, operating system, pages viewed, actions taken, session data, API usage, login events, error logs, security logs, referral URLs, approximate location, timestamps, and diagnostic data.

Cookies and Similar Technologies — we may use cookies, pixels, SDKs, local storage, and similar technologies to operate the website, keep users signed in, remember preferences, secure accounts, measure usage, improve performance, and support marketing where allowed.

Communications — we may collect messages, emails, support tickets, chat messages, community posts, feedback, survey responses, sales communications, and call or meeting notes.

Integration Data — if you connect third-party tools, we may process information from integrations such as code repositories, issue trackers, cloud services, SIEM tools, communication platforms, identity providers, ticketing systems, or payment processors.

03

How We Use Information

We use information to:

  • Provide, operate, maintain, and improve BugsTrace services.
  • Create and manage accounts.
  • Run private bug bounty and managed disclosure programs.
  • Match researchers with appropriate programs.
  • Process vulnerability reports and triage decisions.
  • Provide AI-assisted scoring, duplicate detection, report quality checks, severity recommendations, and remediation suggestions.
  • Deliver CTF training, certifications, and researcher assessments.
  • Monitor attack surfaces and security exposure.
  • Provide vulnerability intelligence, analytics, dashboards, and reports.
  • Process subscriptions, invoices, bounties, and payouts.
  • Detect fraud, abuse, unauthorised access, and platform misuse.
  • Secure BugsTrace systems, users, customers, and researchers.
  • Provide support and respond to inquiries.
  • Send service updates, security notices, product messages, and marketing communications where allowed.
  • Comply with law, legal process, sanctions, tax, accounting, and regulatory obligations.
  • Enforce our Terms of Use and program rules.
04

AI and Automated Processing

BugsTrace products may use AI, machine learning, automation, and scoring systems to analyse reports, assess severity, detect duplicates, validate scope, recommend bounties, identify attack surface risks, review code patterns, generate summaries, and support security workflows.

AI outputs are used to assist users and BugsTrace reviewers. We may use submitted reports, triage outcomes, feedback, and usage patterns to improve our systems, subject to customer agreements, confidentiality obligations, and applicable law.

Where required, we allow human review of important decisions involving reports, payouts, account restrictions, or program outcomes.

05

How We Share Information

We may share information with the following parties.

Customers and Program Owners — researcher reports, comments, proof-of-concepts, triage outputs, and related information may be shared with the customer or program owner responsible for the relevant asset or program.

Researchers — customers may share program scopes, rules, targets, feedback, acceptance decisions, payout decisions, and remediation status with authorised researchers.

Service Providers — we may share information with vendors that help us provide hosting, cloud infrastructure, analytics, security monitoring, customer support, payment processing, identity verification, email delivery, communications, logging, AI infrastructure, and business operations.

Business and Enterprise Integrations — where a customer connects BugsTrace to third-party systems, we may share relevant information with those systems, such as Jira, GitHub, GitLab, Slack, ServiceNow, SIEM platforms, cloud providers, or identity providers.

Legal, Safety, and Compliance — we may disclose information where we believe it is necessary to comply with law, enforce agreements, protect rights, investigate abuse, prevent fraud, respond to legal process, protect security, or prevent harm.

Business Transfers — if BugsTrace is involved in a merger, acquisition, financing, restructuring, asset sale, or similar transaction, information may be transferred as part of that transaction.

Aggregated or De-Identified Information — we may share aggregated, anonymised, or de-identified information that does not reasonably identify a person or customer, including security trends, benchmark data, vulnerability statistics, and platform performance insights.

06

Selling or Sharing Personal Information

BugsTrace does not sell personal information in the traditional sense. We do not sell researcher or customer personal information to data brokers.

If we use advertising or analytics technologies that are considered "sharing," "targeted advertising," or "sale" under certain privacy laws, we will provide required opt-out controls where applicable.

07

Legal Bases for Processing

Where required, we process personal information based on one or more legal bases, including:

  • Contract: to provide services you requested.
  • Legitimate interests: to secure, operate, improve, and protect BugsTrace services.
  • Consent: for certain cookies, marketing, or optional features.
  • Legal obligations: for tax, accounting, compliance, sanctions, and legal requests.
  • Vital or public interest: where necessary to prevent serious harm or respond to security incidents.
08

Data Retention

We retain personal information for as long as necessary to provide services, comply with legal obligations, resolve disputes, enforce agreements, maintain security, prevent abuse, and keep business records.

Vulnerability reports, audit logs, security logs, payout records, and compliance records may be retained for longer periods where needed for security, legal, accounting, or program integrity reasons.

When information is no longer needed, we delete, anonymise, or securely retain it according to our policies and legal obligations.

09

Security

We use administrative, technical, and organisational safeguards designed to protect information. These may include access controls, encryption, logging, monitoring, authentication, least-privilege permissions, secure development practices, vulnerability management, and incident response processes.

No system is perfectly secure. You are responsible for protecting your account credentials, using strong passwords, enabling available security features, and notifying us of suspected unauthorised access.

10

International Data Transfers

BugsTrace is based in the United States. Your information may be processed in the United States and other countries where BugsTrace, its affiliates, or service providers operate.

Where required, we use appropriate safeguards for international transfers, such as contractual protections or other lawful transfer mechanisms.

11

Your Privacy Rights

Depending on your location, you may have rights to:

  • Access personal information we hold about you.
  • Correct inaccurate information.
  • Delete personal information.
  • Port your information.
  • Restrict or object to certain processing.
  • Withdraw consent where processing is based on consent.
  • Opt out of marketing communications.
  • Opt out of certain targeted advertising, sale, or sharing where applicable.
  • Appeal a privacy-rights decision where required by law.

To exercise rights, contact privacy@bugstrace.com. We may need to verify your identity before responding.

12

California and Other US State Privacy Rights

Residents of California, Delaware, and other US states may have additional privacy rights under applicable laws.

Where required, we provide the right to know, access, correct, delete, opt out of certain data uses, and appeal certain decisions. We will not discriminate against you for exercising privacy rights.

13

Marketing Communications

You may unsubscribe from marketing emails by using the unsubscribe link in the email or contacting us. We may still send non-marketing messages, such as security alerts, account notices, billing notices, legal notices, and service updates.

14

Children's Privacy

BugsTrace services are not intended for children under 13. We do not knowingly collect personal information from children under 13.

Some Academy or university programs may involve students. Where required, such programs must be operated with appropriate institutional, parental, or legal permissions.

15

Third-Party Links and Services

BugsTrace may link to or integrate with third-party services. We are not responsible for the privacy practices of third parties. Review their privacy policies before using them.

16

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will update the effective date when changes are made. Material changes may be notified through the website, dashboard, email, or other reasonable method.

17

Contact

For privacy questions or requests, contact: privacy@bugstrace.com