synced 5 MIN AGO
01 Legal

Privacy Policy

exploit.cc has no accounts, sets no cookies of its own, and asks you for nothing in order to read it. This policy covers the little that is left: the request data every web server receives, the two analytics services we run, and what happens to any of it if this business is ever sold.

We do not sell personal information. Section 9 explains why that sentence and a possible future sale of the Site are not in conflict.

Effective
Last modified
Entity
EVECS, LLC

02 Overview

This Privacy Policy describes how EVECS, LLC ("exploit.cc", "we", "us") collects, uses and discloses information in connection with the website at https://exploit.cc and its subdomains (the "Site").

The Site is a public reference. There are no accounts, no sign-in, no paywall and nothing you have to tell us in order to read every page. That shapes everything below: we hold almost nothing about you, because the product does not need it.

What we do hold falls into three groups: the request data every web server receives, measurement data from two analytics services, and anything you choose to put in an email to us. Sections 3 through 5 cover each in turn.

03 What we do not collect

Stating the absences first, because they remove most of the usual questions:

  • No accounts. We do not ask for, and cannot store, a name, password, phone number or billing detail. There is nothing to sign in to.
  • No first-party cookies of our own. The Site sets no cookie to identify you, remember you, or profile you. The cookies present in your browser on this domain come from analytics and from Cloudflare's security layer, both described in our Cookie Policy.
  • No advertising, no retargeting, no data brokers. We run no ad network, no advertising pixels and no cross-site retargeting tags, and we do not supply your information to anyone who does.
  • No sale of personal information. See section 9.

04 Request data

The Site runs on Cloudflare's network. Serving a page requires receiving a request, and a request carries information about the machine that sent it. That data is processed at Cloudflare's edge and in our own application logs, and includes:

  • IP address, and the approximate location, network and country derived from it
  • User agent string, browser and operating system, and preferred language
  • The URL requested, the referring URL where the browser sends one, and query strings
  • Timestamp, response status, bytes transferred, timing, and the Cloudflare data centre that served the request
  • Diagnostic and error records when something fails

We use this to serve pages, to keep the Site available, to investigate errors and abuse, and to understand load. It is not used to build a profile of you and is not combined with the analytics measurement described in section 5 to identify an individual.

05 When you contact us

If you email contact@exploit.cc, we receive your address, your message, anything you attach, and the routing data every email carries. We use it to answer you, to keep a record of the exchange, and to handle any legal or safety issue it raises.

Correspondence is retained for as long as it is useful for those purposes. Do not send us confidential material, credentials, or personal information you would not want held in an ordinary mailbox.

06 Analytics

We measure traffic with two services. They work differently and it is worth being precise about which is which.

Cloudflare Analytics

Cloudflare reports on traffic and performance from the requests our Site already receives at its network edge. It needs no script in your browser and sets no cookie, and it does not place an identifier on your device. This is the measurement we rely on for load, errors and performance.

Google Analytics, delivered first-party

We also use Google Analytics. It reaches you through Cloudflare's Google tag gateway, which changes the delivery path in a way that a reader inspecting their browser deserves to have spelled out:

  • The measurement script is served from a path on https://exploit.cc, not from a Google domain.
  • Measurement events are sent to https://exploit.cc and forwarded from there to Google.
  • Because the requests are first-party, the cookies Google Analytics uses are set as first-party cookies on this domain, and browser controls or extensions that block third-party analytics domains will not block them here.
  • Google still receives the data. A first-party delivery path does not make the recipient first-party. Google processes it under its own privacy policy.

The data measured this way is the usual analytics set: pages viewed, referrer, approximate location, device and browser, and a pseudonymous identifier that lets Google count a returning browser as one visitor rather than several. We use it to see which records and searches people find useful. We do not use it to identify you, and we have not enabled Google Analytics advertising or audience features that would feed it into ad targeting.

Section 12 sets out how to opt out. Our Cookie Policy lists the specific cookies involved.

07 How we use information

We use the information described above only for the following purposes:

  • Operate the Site. Serve pages, route requests, cache responses and keep the Site reachable.
  • Secure the Site. Detect and stop abuse, scraping that threatens availability, denial-of-service traffic and attempts to interfere with the Site or its data.
  • Measure and improve. Understand which pages are used, where performance is poor, and what to build next.
  • Support. Answer messages you send us.
  • Comply and defend. Meet legal obligations, respond to lawful requests, and establish or defend legal claims.

Where the law requires a legal basis for processing, ours are our legitimate interests in running and securing a public reference site and in understanding its use, our compliance with legal obligations, and your consent where consent is what applies.

08 Who else sees it

We do not share personal information for anyone else's independent marketing. It reaches the following recipients and no others:

  • Cloudflare. Our infrastructure provider. Cloudflare delivers, caches and secures the Site, runs the compute and storage behind it, and provides the analytics described in section 5. It processes request data on our behalf under its privacy policy.
  • Google. Receives Google Analytics measurement data as described in section 5.
  • Professional advisors. Lawyers, accountants, auditors and insurers, under confidentiality obligations, where there is a reason to involve them.
  • Legal and safety. Where we believe in good faith that disclosure is reasonably necessary to comply with law or legal process, to enforce our Terms of Use, or to protect the rights, property or safety of EVECS, LLC, our visitors or the public.
  • An acquirer. See section 9.
  • Aggregated figures. Counts and statistics that do not identify anyone, which we may publish or share freely.

09 Personal information inside vulnerability records

This section is about other people's information, not yours, and it is the one category on this Site that a visitor cannot affect by changing a browser setting.

Vulnerability records published by their issuing authorities sometimes contain personal information: the name or handle of a researcher credited with a discovery, an email address in a reference, a link to a personal blog or a social media account. We reproduce those records as the authority published them. We do not add personal information to a record, and we do not enrich, cross-reference or build a profile from what a record contains.

If a record here contains personal information about you, the authority that published it is the source of record, and correcting it there is what causes the correction to propagate everywhere, including here. Write to contact@exploit.cc and we will tell you which authority published the record. We will also consider a request about our own copy on its merits, taking into account the public interest in a complete and unaltered vulnerability record, our legal obligations, and the fact that the record will remain published upstream regardless of what we do.

10 Sale of information and business transfers

We do not sell personal information. We do not rent, lease or trade it, and we do not disclose it to third parties for their own advertising or commercial exploitation. We do not "sell" or "share" personal information for cross-context behavioural advertising as those terms are defined by the California Consumer Privacy Act or comparable state laws.

A sale of the business is a different thing, and it may happen. We may sell, transfer or otherwise dispose of some or all of the Site or of EVECS, LLC, including in a merger, acquisition, financing, reorganisation, bankruptcy or sale of assets. In any such transaction the information we hold in connection with the Site, including the categories described in this policy, may be among the assets transferred to the acquirer or successor.

An acquirer would receive that information subject to this policy or a successor policy providing comparable protection, and we will give notice and any choices the law requires if a transfer would materially change how information is handled in a way that is less protective. We say this plainly rather than burying it: we do not sell user data as a product, and a future sale of this business may nonetheless include the data the business holds.

11 Retention, security and location

Retention

Detailed request and diagnostic logs are kept for a short operational window, measured in days rather than months, and then expire. Aggregated traffic figures, which identify nobody, are kept indefinitely. Analytics data is retained by each analytics provider according to the retention setting we have configured with that provider. Email correspondence is kept for as long as it remains relevant. Where the law requires us to keep something longer, we keep it for that period and no longer.

Security

The Site is served over HTTPS, holds no accounts to compromise, and stores no payment details, because it takes none. Infrastructure access is restricted and logged. No system is perfectly secure and we do not claim otherwise. If you find a security problem with this Site, report it to contact@exploit.cc.

Where information is processed

EVECS, LLC is based in the United States. Cloudflare serves the Site from data centres worldwide, so a request is normally processed near where it originates, and information may be transferred to and stored in the United States and other countries whose data protection laws differ from those where you live. Where a cross-border transfer requires a safeguard, we rely on the mechanism our provider offers for it.

12 Cookies and browser storage

The Site sets no cookie of its own. Cookies present on this domain come from Google Analytics, delivered first-party as described in section 5, and from Cloudflare's security and delivery layer. Our Cookie Policy names each one, what it does and how long it lasts.

Where the law requires consent before non-essential cookies are set, we will present a consent mechanism and honour the choice made through it.

13 Your choices and rights

Opting out of analytics

  • Block or delete cookies for this domain in your browser. Nothing on the Site depends on a cookie, so blocking all of them costs you no functionality here.
  • Install Google's opt-out browser add-on, which applies wherever Google Analytics runs.
  • Use a browser or extension that blocks analytics scripts. Because the tag is served first-party here, a blocklist keyed to Google domains may not catch it; a content blocker that works on script behaviour rather than hostname will.

Statutory rights

Depending on where you live, you may have the right to request access to the personal information we hold about you, its correction or deletion, a portable copy, restriction of or objection to processing, and to withdraw consent where processing rests on consent. California residents have the rights to know, delete, correct and opt out of sale or sharing, and not to be treated differently for exercising them.

Make a request by writing to contact@exploit.cc. Be aware of what we actually hold: with no accounts, we have no record keyed to your identity, and for most visitors the only data associated with you is an IP address in a short-lived log and a pseudonymous analytics identifier we cannot connect to a person. We may need enough information to locate a record before we can act on a request, and we will not collect new identifying information solely to make a search possible.

If you are in the EEA, the UK or Switzerland, you may also complain to your local supervisory authority. We would rather you told us first.

Do Not Track and Global Privacy Control

Do Not Track was never standardised and browsers send it inconsistently, so like most sites we do not act on it. We do not sell or share personal information, so a Global Privacy Control signal has no sale to stop; where applicable law gives that signal a broader meaning, we treat it as the opt-out request the law says it is.

14 Children

The Site is a professional security reference and is not directed to children. We do not knowingly collect personal information from anyone under 13, or under 16 where local law sets that threshold for consent-based processing. If you believe a child has provided us personal information, write to contact@exploit.cc and we will delete it.

15 Changes to this policy

We may update this policy as the Site changes. When we do, we revise the last-modified date at the top, and for a material change we will give the notice the law requires. Continuing to use the Site after an update takes effect means you accept it, to the extent the law permits. Prior versions are not archived here; if you need to know what the policy said on a particular date, ask us.

16 Contact

Privacy questions and requests go to:

Email

contact@exploit.cc

Mail
EVECS, LLC
944 Deltona Blvd #5096
Deltona, FL 32725

This policy describes our practices. It is not legal advice, and it does not create rights beyond those the law gives you.