Privacy Policy
Version 2026-10-06, effective 2026-10-06
This policy explains what personal data PentestHub AI processes, why, and the rights you have.
1. Data we collect
- Account data: name, email address, password hash, sign-in provider (Google or GitHub) identifiers, MFA settings.
- Workspace data: projects, targets, notes, evidence, findings, reports and team membership.
- Scan data: tool output and results of recon and vulnerability scans you run.
- Security and audit records: sign-ins, IP addresses, user agents, legal acceptances, target authorization declarations and scan starts.
- Technical data needed to operate the Service, such as logs and error reports.
2. Why we use it
- To provide and secure the Service and your account.
- To enforce the Terms and Acceptable Use Policy and investigate abuse.
- To comply with legal obligations and lawful requests from authorities.
- To contact you about your account and important changes.
3. Processors and third parties
We use infrastructure and service providers to run the Service. When you sign in with Google or GitHub, those providers process your sign-in. When you enable Cloud or Hybrid AI mode with your own API key, the content you send to the AI copilot is processed by the AI provider you chose (for example OpenAI, Anthropic, Google or OpenRouter) under their terms. In Local mode, AI requests go only to a model you host.
We do not sell your personal data.
4. Where data is stored
Service data is stored on servers operated for PentestHub AI by our hosting provider. Data you send to third-party AI providers may be processed in other countries.
5. Retention
We keep account and workspace data while your account is active. When you delete your account, we delete or anonymize your data within a reasonable period, except audit records (legal acceptances, target authorizations, scan starts), which we keep for as long as needed to investigate abuse and meet legal obligations.
6. Your rights
You can request access to, correction of, export of, or deletion of your personal data. Data export and account deletion are available through the API, or email support@pentesthubai.com. We may need to verify your identity before acting on a request.
7. Security
We protect data with encryption in transit, encryption at rest for secrets such as API keys, access controls and audit logging. Report vulnerabilities to security@pentesthubai.com.
8. Contact
Privacy questions and requests: support@pentesthubai.com.