Data Protection & Privacy

Privacy Policy

Last updated: September 2026

1. Core Principle: Zero Tool Telemetry

All 20 utilities in the Hackerrecon Toolkit (including JWT decoding, CIDR calculation, Regex evaluation, Password generation, and Hash Identification) execute entirely within your browser's local sandbox. Target URLs, sensitive tokens, hashes, and network blocks are never uploaded, logged, or monitored by our infrastructure.

2. Account Information & Authentication

When you create an account to unlock access, we collect your email address and an encrypted password hash. This data is stored using Supabase Authentication to bind your digital license and authenticate sessions across devices.

3. Payment Processing via DodoPayments

Financial transactions are handled by DodoPayments. Hackerrecon does not store, process, or transmit your credit card, debit card, or UPI credentials. We only receive a verified webhook event confirming payment completion (`payment.succeeded`) containing the payment ID and transaction currency.

4. Optional Mission Reports & R2 Storage

In Hacker Terminal, if you choose to export or sync simulation mission completion reports to Cloudflare R2, reports are stored under your unique user namespace. No external third parties have access to these files.

5. Account Deletion & Rights

You have the right to request deletion of your account and associated transaction records at any time. Email hackerrecon@protonmail.com to request full data purge.