// legal
Privacy Policy
Last updated July 29, 2026
What we collect
- Account data: username, email address, password (stored only as a bcrypt hash).
- Profile data you choose to add: name, bio, location, website, social links, photo.
- Learning data: rooms completed, flags solved, points, badges, activity dates.
- Payment data: plan, amount, method, and a transaction reference. We never see or store your card details — PayPal handles that. For UPI we store only the reference you provide so we can verify the transfer.
- Technical data: IP address and timestamps for rate limiting and abuse prevention.
- Google sign-in (optional): your Google ID, email, name and profile picture.
Why we use it
To run your account and track progress, process payments, send service email (verification, password reset, pass expiry), prevent abuse, and improve the platform. We do not sell your data or share it with advertisers.
Cookies
We use a session cookie to keep you logged in, and a referral cookie (30 days) if you arrive via a partner link. We do not use advertising or cross-site tracking cookies.
Who we share with
Only the providers needed to operate: our hosting provider, PayPal (payments), Google (only if you use Google sign-in), and our email provider. Each processes data on our behalf.
How long we keep it
Account and learning data for as long as your account exists. Payment records are kept as long as tax and accounting law requires. Rate-limit logs are short-lived.
Your rights
You can view and edit your data any time under Account, and delete your account permanently from the same page — this erases your profile, progress and personal data (anonymised payment records are retained where law requires). You may also request a copy of your data by emailing support@asecurity-global.com.
If you are in the EU/UK, you have rights of access, rectification, erasure, restriction, portability and objection under the GDPR, and may complain to your local data protection authority.
Security
Passwords are hashed with bcrypt, traffic is served over HTTPS, sessions are hardened, optional two-factor authentication is available, and uploads cannot execute code. No system is perfect, but we take this seriously — see our contact page to report a vulnerability responsibly.
Children
This platform is not intended for children under 16. If you believe a child has created an account, contact us and we will remove it.