Privacy Policy

Last updated August 20, 2026

This Privacy Policy explains how KPWN IT-Services ("we," "us," "our"), the data controller for CVE Crowd, processes personal data when you use https://cvecrowd.com and https://api.cvecrowd.com (together, the "Services"). It is meant to be read together with our Terms of Service, which describes what the Services do. Company details are listed in our Impressum; you can reach us with any privacy question at support [at] cvecrowd (dot) com.

TABLE OF CONTENTS

  1. What Personal Data We Collect
  2. Why We Process It, and on What Legal Basis
  3. Who We Share It With
  4. International Transfers
  5. How Long We Keep It
  6. How We Secure It
  7. Minors
  8. Your Rights
  9. Changes to This Policy
  10. Contact Us

1. What Personal Data We Collect

Account data

Payment data

If you subscribe to a paid plan, billing is handled entirely by our payment processor, Stripe, Inc. We do not receive or store your full card number or other sensitive payment instrument details; we only receive confirmation of your subscription status and the identifiers Stripe uses to bill you (customer ID, subscription ID). See Stripe's privacy notice at https://stripe.com/privacy.

Usage and technical data

Like most websites, our servers automatically log technical information for every request, such as your IP address, browser type, and the page or endpoint accessed, retained for a limited period for security and troubleshooting purposes. If you have API access, we also log which API endpoints you call and when, so we can enforce your plan's quota. Search terms entered into our search function are logged to a table that is not linked to your account or IP address, so we can see which terms are searched in aggregate.

Content shown through the Services

The Fediverse and Bluesky posts we display may contain personal data of their public authors (such as a username, display name, or avatar). We do not collect this beyond what is needed to display it, and we only source it from accounts configured as publicly discoverable. See our Terms of Service for how we handle this content.

What we do not do

We do not process special categories of personal data (e.g. health, biometric, or political data). We do not use advertising or analytics trackers, and we do not buy personal data about you from third parties.

Under the GDPR, we need a valid legal basis for every purpose we process personal data for:

3. Who We Share It With

We do not sell your personal data, and we do not share it for advertising purposes. We share personal data only with the following categories of recipients, each acting as our processor or, where noted, as an independent controller for their own purposes:

4. International Transfers

Our servers and database are located in Germany. Stripe and AWS are headquartered in the United States; where processing your data through these providers involves a transfer outside the EU/EEA, they offer appropriate safeguards recognized under the GDPR, such as the EU Standard Contractual Clauses. You can find details in the providers' own privacy notices linked above.

5. How Long We Keep It

We keep account data for as long as your account is active. When you delete your account, we deactivate it immediately and delete or anonymize the associated personal data within three months, except where we must retain specific records for longer to comply with a legal obligation (e.g. billing records for tax purposes) or to resolve an ongoing dispute or investigation. Technical server logs are kept only for a limited period needed for security and troubleshooting purposes, and are then deleted.

6. How We Secure It

We use technical and organizational measures appropriate to the risk, including hashing passwords with salted pbkdf2_sha256 (we never store passwords in plain text) and encrypting all connections to the Services with TLS. No method of transmission or storage is completely secure, so while we work to protect your information, we cannot guarantee absolute security.

7. Minors

The Services are intended for users who are at least 18 years old, and we do not knowingly collect personal data from anyone younger. If we become aware that we hold data from a user under 18, we will deactivate the account and delete the associated data. If you believe a minor has provided us with personal data, contact us at support [at] cvecrowd (dot) com.

8. Your Rights

Depending on where you live, data protection law may give you the right to:

You can exercise most of these rights directly: update your account details or delete your account from your account settings, or email us at support [at] cvecrowd (dot) com for anything else, including requests concerning data we hold that is not directly editable in your account. We may need to verify your identity before acting on a request.

If you are in the EEA or UK and believe we are processing your personal data unlawfully, you have the right to lodge a complaint with a data protection supervisory authority, either the one in the country where you live or work, or the authority responsible for our business address in North Rhine-Westphalia, the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW). If you are in Switzerland, you may contact the Federal Data Protection and Information Commissioner (FDPIC).

9. Changes to This Policy

We may update this Privacy Policy from time to time, for example to reflect changes to the Services or to legal requirements. We will post the updated version here with a new "Last updated" date, and for material changes we will make reasonable efforts to notify you (e.g. by email or a notice on the Services) before they take effect.

10. Contact Us

For any question about this Privacy Policy or how we handle your personal data, contact:

KPWN IT-Services
c/o Werneburg Internet Marketing und Publikations-Service
Philipp-Kühner-Straße 2
99817 Eisenach
Germany
support [at] cvecrowd (dot) com

Cookie Policy

Last updated August 20, 2026

This section explains the cookies CVE Crowd sets when you visit https://cvecrowd.com.

What are cookies?

Cookies are small data files placed on your device when you visit a website. "First-party" cookies are set by the website you're visiting; "third-party" cookies are set by someone else, typically for tracking or advertising across sites you visit.

The cookies we use

We only set first-party cookies, and only for purposes that are strictly necessary to operate the Services: logging in, protecting forms from abuse, and remembering a couple of display preferences. We do not use any third-party, advertising, or cross-site tracking cookies, and because all of our cookies are strictly necessary, no cookie consent banner is required under applicable law; we still disclose them here for transparency.

Name Purpose
sessionid Keeps you logged in between requests.
csrftoken Protects forms against Cross-Site Request Forgery (CSRF) attacks.
altcha Stores your solved ALTCHA proof-of-work challenge, so you don't have to solve it again for a while, and lets our server apply search rate limiting.
p Remembers your preferred dashboard timeframe (e.g. last 24 hours, 7 days).
v Remembers which version of CVE Crowd you last saw, so we can highlight what changed since then.

ALTCHA

We use ALTCHA, a privacy-preserving, open-source CAPTCHA alternative, on sign-up and search to deter automated abuse. ALTCHA works by having your browser solve a small proof-of-work puzzle locally; unlike most CAPTCHAs, it does not call an external server, load third-party scripts, or track you across sites.

Changes to this Cookie Policy

We may update this Cookie Policy as the cookies we use change, or for legal or operational reasons. The date at the top reflects the last update.