LEGAL
Privacy Policy
Information about the processing of personal data when visiting this website.
1. About this website
This website is an independent security research project focused on technical research, vulnerability analysis, malware research and responsible disclosure.
The website primarily publishes security research, technical articles, vulnerability write-ups and information about ongoing research activity.
2. General information
Personal data is processed only where this is technically necessary to provide, operate and secure this website or where another legal basis permits such processing.
This website does not require visitors to create an account, provide a name or submit personal profile information.
3. Hosting and content delivery
This website is hosted using services provided by Cloudflare. Cloudflare may process technical connection data when visitors access this website.
This may include, in particular:
- IP address
- date and time of the request
- requested URL
- HTTP method and response status
- browser and user-agent information
- referrer information
- technical security and network information
This processing is necessary for the secure and reliable delivery of the website, including protection against abuse, attacks and other malicious traffic.
Where applicable, the legal basis for this processing is Art. 6(1)(f) GDPR. The legitimate interest consists of securely and reliably operating and delivering this website.
Cloudflare may process data on infrastructure located outside the European Economic Area. Where required, appropriate safeguards for international data transfers are used by the service provider.
4. Server and security logs
When this website is accessed, technical request information may be processed automatically by the hosting and network infrastructure.
Such information may be used for:
- delivering requested website content
- detecting technical errors
- preventing abuse
- detecting malicious requests
- maintaining the security of the website
Log information is not intentionally used by this website to create individual visitor profiles.
5. Research status API
The website includes a public research-status component. This component retrieves publicly available status information from an API operated as part of this website.
The status information may include data such as:
- current research status
- general research area
- public activity notes
- timestamps
The feature is intended only to display public research telemetry. It does not require visitors to create an account or provide personal information.
Technical request data may still be processed as part of the normal delivery of the API request.
6. Cookies
This website does not intentionally use its own advertising, profiling or marketing cookies.
Infrastructure providers may use technically necessary cookies or similar mechanisms where required for security, network protection, abuse prevention or reliable service delivery.
7. Analytics and tracking
This website currently does not intentionally use visitor profiling, advertising trackers or third-party marketing analytics.
No visitor profiles are intentionally created for advertising or marketing purposes.
If analytics or additional third-party services are introduced in the future, this privacy policy will be updated accordingly.
8. External links
Articles, write-ups and other parts of this website may contain links to external websites, vulnerability databases, security advisories, vendor websites, research publications or other third-party resources.
When you follow such a link, the destination website is responsible for its own data processing.
The privacy policies and terms of the respective third-party providers apply once you leave this website.
9. GitHub
This website may contain links to GitHub repositories, source code or profiles.
GitHub is operated independently from this website.
No data is intentionally transmitted to GitHub merely by viewing this website.
Data may be transferred to GitHub when you actively follow a GitHub link or interact with content hosted by GitHub.
10. No user accounts
This website does not provide visitor accounts, login functionality or user profiles.
No passwords, account credentials or user-generated profile data are collected through this website.
11. Contact
The only official contact channel for this website and its security research activities is Telegram.
Security research, responsible disclosure inquiries and other messages can be sent via:
@BreachWomp ↗If you contact the operator through Telegram, information contained in your message may be processed for the purpose of handling and responding to your inquiry.
Telegram is an external service and is operated independently from this website. When opening the Telegram link or communicating through Telegram, data may be processed by Telegram according to its own privacy policy.
Depending on the nature of the communication, the legal basis for processing may be Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR.
12. Data retention
Personal data is retained only for as long as necessary for the respective purpose or for as long as required by applicable legal obligations.
Technical logs retained by infrastructure providers may be subject to their own security and retention policies.
13. Your rights
Subject to the requirements of the GDPR, you may have the following rights regarding your personal data:
- right of access
- right to rectification
- right to erasure
- right to restriction of processing
- right to data portability
- right to object to processing
Where processing is based on consent, consent may generally be withdrawn for the future.
14. Right to lodge a complaint
You have the right to lodge a complaint with a competent data protection supervisory authority if you believe that the processing of your personal data violates applicable data protection law.
15. Security
Appropriate technical measures are used to protect this website and its infrastructure against unauthorized access, manipulation and abuse.
Communication with the website is provided via HTTPS.
Security controls may include network-level filtering, rate limiting, automated abuse detection and other defensive mechanisms provided by the hosting infrastructure.
16. Security research content
This website publishes technical security research and may discuss vulnerabilities, malware, software products, security incidents and other security-related subjects.
Published research may contain technical indicators, anonymized examples, vulnerability identifiers and other information relevant to security analysis.
Where appropriate, identifying or sensitive information may be removed, anonymized or otherwise limited before publication.
17. Changes to this privacy policy
This privacy policy may be updated when the website, its technical infrastructure or the services used by it change.
The current version available on this page applies.
Last updated: August 24, 2026