Bugcrowd
- The documents do not say whether your data trains AI.
- Your data is used for personalized ads, including by third-party ad companies.
- Data is shared with partners and affiliates; you can opt out.
- The documents do not say who can read your content.
Bugcrowd collects IDs, selfies, and ads data, shares biometrics with Jumio for ML, and sells data for ads unless you opt out.
Agent Trust Hub uses AI and may make mistakes. Review reports and confirm their contents before relying on them.
Collected
Name, photos, ID papers, selfies and face data, plus device IDs, cookies, and browsing.
Read the exact line
Privacy policy
“Biometric information, including your facial image, that is extracted from both your photos within your identification information and any selfies you submit;”
Training
They run the service, check your ID, market to you, and use cookies for interest-based ads.
Read the exact line
Privacy policy
“We may use first-party or third-party cookies and web beacons to deliver content, including ads relevant to your interests, on our sites or on third party sites.”
Sharing
Vendors (including Jumio), business partners, ad partners, and anyone who can see public profiles.
Read the exact line
Privacy policy
“We may share any information we receive, including biometric information, with vendors and service providers.”
Kept
They keep it while you use the service and as needed for law and business; biometrics up to one year where required.
Read the exact line
Privacy policy
“Bugcrowd retains the personal information we receive as described in this Privacy Policy for as long as you use our Services or as necessary to fulfill the purpose(s) for which it was collected”
Controls
Email privacy@bugcrowd.com for access or deletion; California users can tap Do Not Sell or Share.
Read the exact line
Privacy policy
“Where permitted by applicable law, you may send an e-mail to privacy@bugcrowd.com or use any of the methods set out in this Privacy Policy to exercise your rights in personal information.”
Fine print
Policy can change if they post it; yearly customer orders auto-renew unless you give 60 days’ notice.
Read the exact line
Privacy policy
“If at any point you do not agree to any portion of the Privacy Policy then in effect, you must immediately stop using the Services.”
Expand “Read the exact line” to see the source alongside the explanation.
What you can turn off
The controls and opt-outs their own documents describe, and where they say to find them.
Opt out of sale and ad sharing (California)
Click Do Not Sell or Share My Information on bugcrowd.com, or use Global Privacy Control
Ask to access or delete your data
Email privacy@bugcrowd.com with full name, account email, and a detailed request
Unsubscribe from marketing email
Use the unsubscribe link at the bottom of marketing emails
Cancel an annual customer order
Written notice no later than 60 days before the end of the then-current year’s term
If a switch is not where they say, the deletion request above still applies.
Line by line
The lines that matter most, worst first.
Your ID photos and face data can be used by Jumio to train and improve its own systems, not only to check who you are.
Read the exact line
Privacy policy
“Jumio, and its service providers, may use any information collected to verify your identity, to develop, provide and improve Jumio’s services, including through machine learning techniques”
For example, a selfie you take to prove you are a researcher could help Jumio’s face-matching software get better.
They admit they sell or share personal information so ads can follow you on other sites.
Read the exact line
Privacy policy
“We “sell” and “share” your personal information to provide you with “cross-context behavioral advertising” about Bugcrowd’s products and services.”
For example, visiting Bugcrowd could help an ad network show you Bugcrowd ads later on another website.
Anything you send them in messages can be used by Bugcrowd for almost any business purpose.
Read the exact line
Privacy policy
“You agree that Bugcrowd is free to use the content of any communications submitted by you via the Services, including any ideas, inventions, concepts, techniques, or know-how disclosed therein, for any purpose including developing, manufacturing, and/or marketing goods or Services.”
For example, a product idea you email support could be used in a future Bugcrowd feature without paying you.
Your researcher profile is not private by default.
Read the exact line
Privacy policy
“The information in your Profile may be visible to all Bugcrowd users and the general public.”
For example, your name, photo, and work samples could show up in a public web search.
Ad companies can get some of your personal details, not only stats.
Read the exact line
Privacy policy
“We may also share such information as well as selected personal information (such as demographic information and past purchase history) we have collected with third-party advertising partners.”
For example, your past purchases could be used to target ads on other sites.
Turning on Do Not Track in your browser will not stop their tracking.
Read the exact line
Privacy policy
“Please note that we do not respond to or honor DNT signals or similar mechanisms transmitted by web browsers.”
For example, Safari’s Do Not Track setting will not change how Bugcrowd cookies work.
Yearly customer contracts renew on their own unless you cancel in writing two months early.
Read the exact line
Terms of service
“All Orders placed on an annual basis will auto-renew for additional year-long terms at then-current pricing unless otherwise stated in the Order or unless either party notifies the other party in writing of its intention to terminate the Order no later than sixty (60) days before the end of the then-current year’s terms.”
For example, if you forget the 60-day window, you can be billed for another full year at the new price.
For business customers, they mostly promise nothing about the service working or finding every bug.
Read the exact line
Terms of service
“EXCEPT AS EXPRESSLY WARRANTED IN THIS SECTION 7, TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE HOSTED SERVICE AND TESTING SERVICES ARE PROVIDED “AS IS,””
For example, if a missed vulnerability leads to a breach, this language tries to limit their responsibility.
In places that require it, face data is not kept forever, but only up to a year.
Read the exact line
Privacy policy
“Where required by applicable law, your biometric information will be stored for no more than one year.”
For example, in some U.S. states your selfie used for ID checks should be deleted within a year.
California users get a clear way to stop sale and ad sharing of their data.
Read the exact line
Privacy policy
“California residents may exercise these rights by clicking on Do Not Sell or Share My Information and following the instructions on that prompt.”
For example, you can click that link so Bugcrowd stops sharing your info for ads on other sites.
Words to know
Legal words from the lines above, in plain English.
- biometric
- Measurements of your body that identify you, like your face, fingerprint or voice. For example, a selfie used to unlock the app or a voice recording matched to you.
- third parties
- Any company or person other than you and the app, such as advertisers, partners or analytics firms. For example, an analytics company that receives a record of every screen you tap is a third party.
- cookies
- Small files a website saves on your device so it can recognise you and remember what you did. For example, a cookie keeps you logged in and can also tell an ad company which sites you visited.
- tracking pixels
- Tiny invisible images or bits of code in a page, app or email that report back when and where you opened it. For example, a pixel in a marketing email tells the sender the moment you read it.
- service providers
- Outside companies that handle your data on the app's instructions, such as a cloud host or an email sender. For example, the company that stores the app's files in the cloud sees your data but only does what the app tells it.
- personal data
- Any information that is about you or can be linked to you, from your name to your phone's ID. For example, your email, your IP address and the list of apps on your phone are all personal data.
- sell or share
- Under California law, selling means passing your data to others for money or other value; sharing means passing it on for targeted ads. For example, letting an ad network use your browsing history in return for ad space counts as a sale.
- targeted advertising
- Ads chosen for you based on what you have done across other apps and websites, not just this one. For example, you look at shoes in one app and see shoe ads in a totally different app the next day.
- de-identified
- Data with your name and obvious identifiers removed, though it can sometimes still be traced back to you. For example, your chats with names stripped out may still be kept and studied after you delete your account.
- auto-renewal
- Your subscription keeps charging you at the end of each period until you cancel it. For example, a free trial turns into a paid monthly plan unless you cancel before it ends.
How we got here · grade F · score 32/100 · 15 of 15 policy answers backed by a verified quote · 3 not stated
What does the app collect beyond what it needs to work?
They collect more than account basics: photos, ID documents, selfies, biometrics, advertising IDs, geo-location, and browsing across pages.
Does it record your voice, face or body, and what happens to that?
Researchers give selfies and facial biometrics that are shared with Jumio, which may use them with machine learning to improve its services.
Are your chats and uploads used to train AI models, and is that off by default?
Not stated in the documents.
Can employees or contractors read your conversations, and when?
Not stated in the documents.
Are you profiled or tracked for advertising?
Third-party ad partners set cookies and get personal information for interest-based ads on other sites.
Do they sell or share your data, and can you opt out?
They say they sell and share personal information for cross-context ads, and California users can opt out.
What rights do they take over what you type and what the AI makes?
They claim they are free to use anything you send through the services for any purpose, including making and marketing products.
How long do they keep your data after you delete it, and can you delete it in the app?
Deletion is by emailing them; they keep data while you use the service and as needed for law and business. Biometrics may be limited to one year where required.
Does it build a lasting memory or profile of you, and can you see, edit or turn it off?
They list inferences used to create a consumer profile, but they do not describe in-app memory controls.
Do they commit to basic security, and have they leaked data?
The customer terms say they maintain a security program meant to protect the hosted service, in general industry-standard terms.
Is there a real age gate, and are teens protected?
The service is not directed to children under 13 (or 16 in some places); they do not describe a real age check.
Will they tell you when the rules change, and is the policy specific?
The privacy policy is dated, but they may just post updates and say you must stop using the service if you disagree.
Can they close your account without warning, and can you get your data out first?
Not stated in the documents.
If something goes wrong, who pays?
Customer terms are as-is with a fee cap, and the customer must defend Bugcrowd if access to their systems was not authorized.
Do subscriptions renew on their own, and can you get a refund?
Annual customer orders auto-renew at then-current prices unless a party gives written notice at least 60 days before the term ends.
The privacy policy is 6,221 words at a college graduate level (Flesch reading ease 35); the terms are 4,647 words at a professional or legal expert level.