Bad Bounties is a PhantomBugz project. This notice describes information used to operate the site, review submissions, publish community contributions, and prevent abuse. For questions or requests about your information, use our Contact page.
Accounts and sign-in
Account records include your username, email address, display and profile information, password hash, email-verification state, and account-security settings. Two-factor authentication can involve authenticator configuration, hashed backup codes, and optional security-key registrations. Sign-in and session records can contain your IP address, browser information, and timestamps. Your email address is not displayed publicly as part of your profile.
Contributions and publication
We store company listings, review scores and text, case summaries, private context, replies, event submissions, organizer preferences, and staff-interest records. Submission status, revisions, staff decisions, moderation records, and audit records support these workflows.
Your public profile image and display information, published replies, approved reviews and case summaries, and approved event details are public. Approved, eligible sponsorship banners can also be displayed publicly. Others can view, copy, or share public material. A directory listing can appear before it has an approved review. An existing approved review remains public while an edited revision awaits approval.
Private context is not copied into the public case discussion. Pending submissions and staff notes are available to authorized people handling the relevant workflow. Site administrators and service providers have operational access to the systems they run. Private intake is not end-to-end encrypted or anonymous merely because it is excluded from public pages.
Hosting, email, security, and editing services
We use Namecheap for hosting and SMTP email delivery. Hosting systems can record requests, errors, and network addresses. Email services process recipient addresses and message contents, including account setup and security links. Email sent to our contact address is also handled by the email service.
Cloudflare provides network protection and Turnstile checks on protected forms. The browser supplies device and network signals to Cloudflare; server-side Turnstile validation sends the challenge token and raw visitor IP address. When network screening is enabled, we send the raw visitor IP address to ipapi.is to check network characteristics associated with abusive or automated traffic.
Some review-eligibility and rate-limit records use keyed network identifiers. That does not mean every IP address is anonymous or absent from the site: forum replies, sessions, hosting logs, and security services can contain raw addresses.
Installed AI editing tools may send selected content to OpenAI when an operator uses those tools. This notice does not promise that private intake will never be selected for AI-assisted processing. Keep submissions limited to the information needed to explain the matter.
Browser storage and external links
WordPress uses cookies for sign-in and account security. The theme stores your motion preference in your browser. Clearing browser storage does not delete your account or contributions. External company, event, sponsor, and project links lead to services with their own practices.
Optional payment records
When payment features are enabled and used, account-linked orders can contain product and price details, transaction references, verification status, membership or campaign dates, and payment-issue messages. Payment verification may involve configured chain-data or payment providers. Cryptocurrency transactions are public on their blockchain, and an order can link your site account to a transaction. Bad Bounties cannot erase information from a public blockchain. Never send wallet secrets or seed phrases. A description of payment records is not an invitation to pay while checkout is closed.
Retention, correction, and removal
Most account, contribution, private-submission, audit, moderation, staff-interest, and payment records have no automatic deletion schedule. A rejection, ban, closed interest record, expired membership, or withdrawn publication does not automatically erase its underlying records.
Request a copy, correction, withdrawal, or deletion through Contact, identifying only the relevant account or record. Requests require review and may require verification of your authority without authentication secrets. There is no automatic account-wide erasure tool for custom Bad Bounties records. Sending a request does not immediately delete a record.
Removal from a public page, deletion from active storage, and removal from backups are separate operations. Removing or replacing a profile image removes its current site file when the operation succeeds; backup copies and copies made by others are separate. No instant deletion from all systems or fixed deletion deadline is promised.
Keep unnecessary private information out
Do not submit passwords, authenticator secrets, backup codes, verification links, wallet secrets, government IDs, or unnecessary private third-party information. Reviews, cases, replies, and staff-interest forms do not accept attachments. PoCs, exploit code, reproduction instructions, technical vulnerability details, and technical-proof links are outside this community’s intake. Read the Rules before contributing.