GenAgent Trust Hub
Menu

Bugcrowd

FTier FHighest risk · 32/100
  • The documents do not say whether your data trains AI.
  • Your data is used for personalized ads, including by third-party ad companies.
  • Data is shared with partners and affiliates; you can opt out.
  • The documents do not say who can read your content.

Bugcrowd collects IDs, selfies, and ads data, shares biometrics with Jumio for ML, and sells data for ads unless you opt out.

Highest riskMedium riskLow risk

Agent Trust Hub uses AI and may make mistakes. Review reports and confirm their contents before relying on them.

Privacy policy · August 18, 2026 ↗Terms · August 10, 2026 ↗28 min read · college graduate level23 lines verified word for word

Collected

What is collected

Name, photos, ID papers, selfies and face data, plus device IDs, cookies, and browsing.

Read the exact line

Privacy policy

“Biometric information, including your facial image, that is extracted from both your photos within your identification information and any selfies you submit;”

Training

How it is used

They run the service, check your ID, market to you, and use cookies for interest-based ads.

Read the exact line

Privacy policy

“We may use first-party or third-party cookies and web beacons to deliver content, including ads relevant to your interests, on our sites or on third party sites.”

Sharing

Who may see it

Vendors (including Jumio), business partners, ad partners, and anyone who can see public profiles.

Read the exact line

Privacy policy

“We may share any information we receive, including biometric information, with vendors and service providers.”

Kept

How long it is kept

They keep it while you use the service and as needed for law and business; biometrics up to one year where required.

Read the exact line

Privacy policy

“Bugcrowd retains the personal information we receive as described in this Privacy Policy for as long as you use our Services or as necessary to fulfill the purpose(s) for which it was collected”

Controls

Your controls

Email privacy@bugcrowd.com for access or deletion; California users can tap Do Not Sell or Share.

Read the exact line

Privacy policy

“Where permitted by applicable law, you may send an e-mail to privacy@bugcrowd.com or use any of the methods set out in this Privacy Policy to exercise your rights in personal information.”

Fine print

The fine print

Policy can change if they post it; yearly customer orders auto-renew unless you give 60 days’ notice.

Read the exact line

Privacy policy

“If at any point you do not agree to any portion of the Privacy Policy then in effect, you must immediately stop using the Services.”

Expand “Read the exact line” to see the source alongside the explanation.

What you can turn off

The controls and opt-outs their own documents describe, and where they say to find them.

  1. Opt out of sale and ad sharing (California)

    Click Do Not Sell or Share My Information on bugcrowd.com, or use Global Privacy Control

  2. Ask to access or delete your data

    Email privacy@bugcrowd.com with full name, account email, and a detailed request

  3. Unsubscribe from marketing email

    Use the unsubscribe link at the bottom of marketing emails

  4. Cancel an annual customer order

    Written notice no later than 60 days before the end of the then-current year’s term

If a switch is not where they say, the deletion request above still applies.

Line by line

The lines that matter most, worst first.

1 · What is collected

Your ID photos and face data can be used by Jumio to train and improve its own systems, not only to check who you are.

Read the exact line

Privacy policy

“Jumio, and its service providers, may use any information collected to verify your identity, to develop, provide and improve Jumio’s services, including through machine learning techniques”

For example, a selfie you take to prove you are a researcher could help Jumio’s face-matching software get better.

2 · How it is used

They admit they sell or share personal information so ads can follow you on other sites.

Read the exact line

Privacy policy

“We “sell” and “share” your personal information to provide you with “cross-context behavioral advertising” about Bugcrowd’s products and services.”

For example, visiting Bugcrowd could help an ad network show you Bugcrowd ads later on another website.

3 · How it is used

Anything you send them in messages can be used by Bugcrowd for almost any business purpose.

Read the exact line

Privacy policy

“You agree that Bugcrowd is free to use the content of any communications submitted by you via the Services, including any ideas, inventions, concepts, techniques, or know-how disclosed therein, for any purpose including developing, manufacturing, and/or marketing goods or Services.”

For example, a product idea you email support could be used in a future Bugcrowd feature without paying you.

4 · What is collected

Your researcher profile is not private by default.

Read the exact line

Privacy policy

“The information in your Profile may be visible to all Bugcrowd users and the general public.”

For example, your name, photo, and work samples could show up in a public web search.

5 · How it is used

Ad companies can get some of your personal details, not only stats.

Read the exact line

Privacy policy

“We may also share such information as well as selected personal information (such as demographic information and past purchase history) we have collected with third-party advertising partners.”

For example, your past purchases could be used to target ads on other sites.

6 · How it is used

Turning on Do Not Track in your browser will not stop their tracking.

Read the exact line

Privacy policy

“Please note that we do not respond to or honor DNT signals or similar mechanisms transmitted by web browsers.”

For example, Safari’s Do Not Track setting will not change how Bugcrowd cookies work.

7 · The fine print

Yearly customer contracts renew on their own unless you cancel in writing two months early.

Read the exact line

Terms of service

“All Orders placed on an annual basis will auto-renew for additional year-long terms at then-current pricing unless otherwise stated in the Order or unless either party notifies the other party in writing of its intention to terminate the Order no later than sixty (60) days before the end of the then-current year’s terms.”

For example, if you forget the 60-day window, you can be billed for another full year at the new price.

8 · The fine print

For business customers, they mostly promise nothing about the service working or finding every bug.

Read the exact line

Terms of service

“EXCEPT AS EXPRESSLY WARRANTED IN THIS SECTION 7, TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE HOSTED SERVICE AND TESTING SERVICES ARE PROVIDED “AS IS,””

For example, if a missed vulnerability leads to a breach, this language tries to limit their responsibility.

9 · How long it is kept

In places that require it, face data is not kept forever, but only up to a year.

Read the exact line

Privacy policy

“Where required by applicable law, your biometric information will be stored for no more than one year.”

For example, in some U.S. states your selfie used for ID checks should be deleted within a year.

10 · How it is used

California users get a clear way to stop sale and ad sharing of their data.

Read the exact line

Privacy policy

“California residents may exercise these rights by clicking on Do Not Sell or Share My Information and following the instructions on that prompt.”

For example, you can click that link so Bugcrowd stops sharing your info for ads on other sites.

Words to know

Legal words from the lines above, in plain English.

biometric
Measurements of your body that identify you, like your face, fingerprint or voice. For example, a selfie used to unlock the app or a voice recording matched to you.
third parties
Any company or person other than you and the app, such as advertisers, partners or analytics firms. For example, an analytics company that receives a record of every screen you tap is a third party.
cookies
Small files a website saves on your device so it can recognise you and remember what you did. For example, a cookie keeps you logged in and can also tell an ad company which sites you visited.
tracking pixels
Tiny invisible images or bits of code in a page, app or email that report back when and where you opened it. For example, a pixel in a marketing email tells the sender the moment you read it.
service providers
Outside companies that handle your data on the app's instructions, such as a cloud host or an email sender. For example, the company that stores the app's files in the cloud sees your data but only does what the app tells it.
personal data
Any information that is about you or can be linked to you, from your name to your phone's ID. For example, your email, your IP address and the list of apps on your phone are all personal data.
sell or share
Under California law, selling means passing your data to others for money or other value; sharing means passing it on for targeted ads. For example, letting an ad network use your browsing history in return for ad space counts as a sale.
targeted advertising
Ads chosen for you based on what you have done across other apps and websites, not just this one. For example, you look at shoes in one app and see shoe ads in a totally different app the next day.
de-identified
Data with your name and obvious identifiers removed, though it can sometimes still be traced back to you. For example, your chats with names stripped out may still be kept and studied after you delete your account.
auto-renewal
Your subscription keeps charging you at the end of each period until you cancel it. For example, a free trial turns into a paid monthly plan unless you cancel before it ends.
How we got here · grade F · score 32/100 · 15 of 15 policy answers backed by a verified quote · 3 not stated
  • What does the app collect beyond what it needs to work?

    They collect more than account basics: photos, ID documents, selfies, biometrics, advertising IDs, geo-location, and browsing across pages.

  • Does it record your voice, face or body, and what happens to that?

    Researchers give selfies and facial biometrics that are shared with Jumio, which may use them with machine learning to improve its services.

  • Are your chats and uploads used to train AI models, and is that off by default?

    Not stated in the documents.

  • Can employees or contractors read your conversations, and when?

    Not stated in the documents.

  • Are you profiled or tracked for advertising?

    Third-party ad partners set cookies and get personal information for interest-based ads on other sites.

  • Do they sell or share your data, and can you opt out?

    They say they sell and share personal information for cross-context ads, and California users can opt out.

  • What rights do they take over what you type and what the AI makes?

    They claim they are free to use anything you send through the services for any purpose, including making and marketing products.

  • How long do they keep your data after you delete it, and can you delete it in the app?

    Deletion is by emailing them; they keep data while you use the service and as needed for law and business. Biometrics may be limited to one year where required.

  • Does it build a lasting memory or profile of you, and can you see, edit or turn it off?

    They list inferences used to create a consumer profile, but they do not describe in-app memory controls.

  • Do they commit to basic security, and have they leaked data?

    The customer terms say they maintain a security program meant to protect the hosted service, in general industry-standard terms.

  • Is there a real age gate, and are teens protected?

    The service is not directed to children under 13 (or 16 in some places); they do not describe a real age check.

  • Will they tell you when the rules change, and is the policy specific?

    The privacy policy is dated, but they may just post updates and say you must stop using the service if you disagree.

  • Can they close your account without warning, and can you get your data out first?

    Not stated in the documents.

  • If something goes wrong, who pays?

    Customer terms are as-is with a fee cap, and the customer must defend Bugcrowd if access to their systems was not authorized.

  • Do subscriptions renew on their own, and can you get a refund?

    Annual customer orders auto-renew at then-current prices unless a party gives written notice at least 60 days before the term ends.

The privacy policy is 6,221 words at a college graduate level (Flesch reading ease 35); the terms are 4,647 words at a professional or legal expert level.

Your privacy
has an agent now

Be in control of your online privacy in the AI Era with confidence.

Gen

From Gen, the Company BehindNorton