Join
Legal

Privacy Policy

Last updated Mon, Sep 21, 2026. What we collect, why, what is public and what is never public, and how to have it removed.

1 Who we are and what this covers

PentestingHere (pentestinghere.com) is a community platform for penetration testers and bug bounty researchers, operated from Montaza, Alexandria, Egypt. PentestingHere decides what is collected here and why, which makes us the controller of it.

This policy covers the whole site: reading it, holding an account, publishing on it, running its labs, our email, and the manual payment process behind a membership. It sits alongside the Terms and Conditions, which cover the rules of using the site.

It is written to be checked rather than admired. Everything below is what the software does; where you can verify a claim from the outside, please do, and tell us if we have it wrong.

2 What you give us

Only what a feature needs, and only when you use it.

  • An account: a username, an email address and a password, which is stored hashed and is never readable by us or by anybody else. Everything else on a profile (display name, bio, avatar, cover image, social and website links) is optional and is yours to remove.
  • A second factor, if you set one up: the secret behind an authenticator app is encrypted at rest, and its recovery codes are burned as they are used.
  • A sign-in with Google or GitHub, if you choose one: we receive your account id there, the email address on it and your display name and picture. We never link a provider to an existing account on a matching email alone: you have to sign in to that account first.
  • What you publish: findings, writeups, resources, program reviews, comments, discussions and lab solves, with whatever you chose to put in them.
  • Support tickets and vulnerability reports: what you wrote, and, only if you opened one without an account, whatever contact detail you typed so that we can reply.
  • A membership payment claim: the payment method, the transaction reference you type in, and the amount and currency, so a member of staff can check the transfer against our own records.

We never see or store card details. Where a payment provider is connected, card data is entered on the provider's own page and handled by them; where a membership is paid by an Egyptian bank or wallet transfer, we receive the reference you send us and nothing else.

3 What the site records by itself

Running a site safely needs a small amount of technical record-keeping. This is all of it.

  • Sessions. While you are signed in, the session record holds your IP address and browser user agent, which is what lets us, and you, end a session that was taken by somebody else. It is deleted when the session ends or expires.
  • Last seen. The time of your most recent page view, written at most once a minute. It is used for one thing: the staff view of who is on the site right now.
  • Page views. For each page load we store the path, the route, the site you arrived from (the host only, never the full link), whether the reader was signed in, and a visitor hash. The hash is a one-way sha256 of the day, the address and the browser. It changes every night, so two days of reading cannot be joined together, and the address itself is never written down. There is no analytics script, no tracking cookie and no third-party analytics on this site. Rows are deleted after 180 days.
  • Labs. When you start a hosted lab we record the session, its lifecycle events and your progress, so the lab can be graded, reclaimed when idle, and reset when you ask.
  • Email. A record of each message we send you: the address, the kind of message, its subject, and whether it was sent, refused or bounced. It exists so that we can prove what was sent and stop sending to an address that is failing.
  • Moderation and staff actions. Reports, warnings, hidden content and every action a moderator or an administrator takes are written to an audit log with who did it and why.
  • Security reports and support tickets opened without an account carry the same daily-rotating hash as a page view, so a flood from one visitor can be grouped without storing their address.

No IP address is shown on any screen of this site, staff screens included.

4 Why we use it

Each of these is a purpose, and the only ones we have:

  • To run your account and show you what you asked for: necessary to provide the service you signed up to.
  • To publish what you chose to publish, with the visibility you chose for it.
  • To keep the platform and its members safe: moderation, suspension, abuse and fraud prevention, and defending the site against attack. That is our legitimate interest, and yours.
  • To send you email you asked for or that your account needs, and nothing else.
  • To check a payment and grant or refuse a membership: necessary to perform the agreement you entered into.
  • To count how the site is used, in aggregate only. The statistics screen shows totals; it cannot show a person, because the rows behind it do not identify one.
  • To meet a legal obligation, where one applies to us.

We do not sell your data, we do not rent it, and we do not share it with anybody for their own marketing. There is no advertising profile built from what you read here.

5 What is public, and what is not

This is a publishing platform, so some of your data is meant to be seen. The line is drawn deliberately and enforced in the queries, not in the page.

Public: your username, profile, published work, tags, reputation, rank, badges, solves and follower counts. Public work appears in listings, search, the sitemap, the feed and the weekly digest, and search engines index it.

Not public, ever:

  • Your email address. It is shown to administrators and to you, and to no other member, not even to a moderator.
  • Your drafts, and anything you marked private or unlisted. An unlisted item is reachable by its link and is kept out of listings, search engines and the digest.
  • A finding's target where you asked for it to be hidden. Anonymised shows a generic label, private shows a redaction, and both are applied when the finding is read rather than hidden in the markup, so the raw value is not in the page for anybody to find.
  • Your follower and following lists, if you set them to counts-only or private. That setting binds moderators and administrators too; an administrator can look past it from the admin screens, and doing so writes an audit record naming who looked.
  • Whether you are online, and your last-seen time. These appear on staff screens only. There is no presence dot on a profile.
  • Your IP address, your browser, your support tickets, your warnings, your vulnerability reports and your payment claims.

Anything you publish can be unpublished. Hiding or deleting it removes it from the site and from every listing; copies may survive briefly in backups and caches, and a message already sent by email cannot be recalled.

6 Cookies and what is stored in your browser

We set no advertising cookie and no analytics cookie. What we do set:

  • A session cookie, so the site knows you are signed in. Without it you cannot sign in at all.
  • A CSRF token cookie, which stops another site acting as you on this one.
  • A "remember me" cookie, only if you ask to be remembered.
  • A signed lab-session cookie while a hosted lab is running, so the lab runtime can tell your instance from somebody else's.
  • Your theme and sidebar preference, kept in your browser's local storage and never sent to us.

Cookies set by other companies on this site are described in the next section. Clearing them in your browser signs you out and forgets your preferences; nothing else breaks.

7 Other companies involved

We keep this list short on purpose, and it is the whole list.

  • Our hosting providers, who run the servers this site and its labs run on.
  • The company that delivers our email, which receives the address and the message in order to deliver it.
  • A payment provider, where checkout is open: you enter card details on their page, under their privacy policy, and we are told the result. A membership paid by Egyptian bank or wallet transfer involves your bank or wallet, whose own records are theirs, not ours.
  • Google and GitHub, if you choose to sign in with one of them: only then, and only the profile described above.
  • YouTube, for lesson videos. The player is not loaded until you press play, and it runs in privacy-enhanced mode so no Google cookie is set before that.
  • Google AdSense, where advertising is shown: it appears in the dialog that starts a free lab, for readers without a membership, and Google may set cookies and use device data there under its own policies. A membership removes ads entirely.
  • An AI provider, used for one thing only: classifying public security-news headlines we fetch from public feeds. No member content, no account data and no message of yours is ever sent to it.

These companies act on our instructions, except where they are named above as deciding for themselves (Google, GitHub, YouTube, AdSense and a payment provider), in which case their own privacy policies apply to what they do. Our providers may operate in other countries, so your data may be processed outside the one we are based in.

8 Email you receive from us

Some email is part of holding an account and cannot be switched off: a password reset, an email confirmation, a security notice. Everything else is optional, has an unsubscribe link in it, and can be turned off under Settings, Email.

One thing decides whether a person may be emailed at all, so a preference you set is honoured everywhere. An address that bounces is suppressed and stops receiving anything until it is fixed, and we never pass your address to anybody for their own use.

9 How long we keep it

Not longer than there is a reason to.

  • Your account and what you published: until you delete them or ask us to close the account.
  • Page-view rows: 180 days, then deleted automatically.
  • Sessions: until the session ends or expires.
  • Email delivery records, moderation records, warnings and audit logs: kept as the history of what happened, because a moderation decision nobody can look back at is a decision nobody can appeal.
  • Support tickets and vulnerability reports: kept while they are useful for support and for security, then removed.
  • Payment claims: kept as long as accounting and dispute handling require.
  • Backups: rotated, so a deleted row can survive in one for a short while before it is overwritten.

10 Your rights

Wherever you live, you can ask us to: tell you what we hold about you; correct it; give you a copy; delete your account and its content; stop sending you something; or object to how we are using it.

These rights apply to everybody who uses the site, whether or not the law where you live gives them to you. We would rather grant them to all of our members than work out which of them can compel us.

Ask through the support desk or by writing to noreply@pentestinghere.com. We answer within 30 days, and we will tell you if something has to be kept and why. A moderation record or an audit log usually does.

You can do several of these yourself, immediately: edit or delete your work, change what your profile shows, change who may see your follower lists, turn optional email off, end every session on your account, and close your account.

If you think we have got this wrong, tell us first: it is almost always faster. You are also entitled to complain to your data protection authority.

11 Decisions made automatically

We make no automated decision about you that has a legal effect. One automated action exists and it is worth naming: content reported as urgent by several members is hidden immediately, before a human has read it. That is a holding action, not a verdict. The author is told, it is reviewed by a moderator, and editing the work is how you appeal it.

12 Children

This site is not for children. You must be at least 16 to hold an account. If you believe a child has an account here, tell us and we will remove it.

13 How we protect it

Passwords are hashed, authenticator secrets are encrypted, traffic is served over HTTPS, and every page is written to escape what members type rather than trust it. You can add a second factor, see where your account is signed in, and end every session at once.

Our audience finds vulnerabilities for a living, and we would rather hear about one in this site than read about it later. The disclosure page is open to people with no account, deliberately, because the most valuable report we can receive is about the sign-in flow.

No platform is perfectly safe. If a breach ever affects your data, we will tell you what happened, what it touched and what to do, without waiting to be asked.

14 Changes to this policy

The site changes, and so will this page. The date at the top says when it last changed, and a change that matters to you is announced on the site rather than slipped in.

We will not start using what we already hold for a new and unrelated purpose without telling you first.

How to reach us about your data

PentestingHere, Montaza, Alexandria, Egypt noreply@pentestinghere.com 01505986111