GenAgent Trust Hub
Menu

HackAdvisor

ATier ALow risk · 57/100
  • The documents do not say whether your data trains AI.
  • The policy rules out using your data for targeted ads.
  • Data is shared only with the providers who run the service.
  • The documents do not say who can read your content.

Cybersecurity labs collect account and usage data, share some with AI vendors, and can close you anytime; you can delete in settings.

Highest riskMedium riskLow risk

Agent Trust Hub uses AI and may make mistakes. Review reports and confirm their contents before relying on them.

Privacy policy ↗Terms ↗10 min read · professional or legal expert level22 lines verified word for word

Collected

What is collected

Account info, optional profile, lab usage, IPs and browser data, plus org assessment details.

Read the exact line

Privacy policy

“When you register, we collect your username, email address, and password. Passwords are processed by Django's salted one-way password hasher and are never stored in plaintext.”

Training

How it is used

They run labs, show public scores, stop abuse, improve the product, and may send AI-feature content to vendors.

Read the exact line

Privacy policy

“Content submitted to an AI-assisted feature, including an organization vulnerability report or incident report when that feature is requested, may be transmitted to the configured AI provider.”

Sharing

Who may see it

Host, email, Cloudflare, optional analytics, and AI providers can see some data; they say they do not sell it.

Read the exact line

Privacy policy

“We do not sell, rent, or trade your personal information to any third party. We do not share your data with advertising networks or data brokers.”

Kept

How long it is kept

Active accounts stay until you delete; lab traffic 30 days; some backups and org records last longer.

Read the exact line

Privacy policy

“Account and learning records are retained while the account is active. Self-service deletion removes the active account, profile, avatar, and personal solve/activity records immediately after ownership checks”

Controls

Your controls

You can view, export, and delete from account settings or email admin@hackadvisor.io.

Read the exact line

Privacy policy

“You can of your active account and associated personal data through account settings or admin@hackadvisor.io.”

Fine print

The fine print

They can close you with no notice; service is as-is; you them; disputes go to courts.

Read the exact line

Terms of service

“We may terminate or suspend your access to the Platform at any time, with or without cause, with or without notice.”

Expand “Read the exact line” to see the source alongside the explanation.

What you can turn off

The controls and opt-outs their own documents describe, and where they say to find them.

  1. Delete your account in settings

    Account settings or admin@hackadvisor.io

  2. Export your data

    Account settings (profile, challenge history, points)

  3. Decline analytics cookies

    Cookie banner; GTM and PostHog load only after you accept

  4. Ask about blockchain certs before deleting

    Contact admin@hackadvisor.io before account deletion

If a switch is not where they say, the deletion request above still applies.

Line by line

The lines that matter most, worst first.

1 · The fine print

They can shut your account for any reason and do not have to warn you first.

Read the exact line

Terms of service

“We may terminate or suspend your access to the Platform at any time, with or without cause, with or without notice.”

For example, you could lose access to labs mid-challenge with no email explaining why.

2 · The fine print

If someone sues them because of how you used the platform, you may have to pay their legal bills.

Read the exact line

Terms of service

“You agree to , defend, and HackAdvisor Labs and its affiliates, officers, directors, employees, and agents from and against any and all claims”

For example, if you used a technique from a lab on a real website and they got sued, they could ask you to cover costs.

3 · How it is used

Text you put into AI lab tools can be sent to companies like OpenAI or Anthropic.

Read the exact line

Privacy policy

“Content submitted to an AI-assisted feature, including an organization vulnerability report or incident report when that feature is requested, may be transmitted to the configured AI provider.”

For example, a bug report you paste into an AI review feature could leave their servers.

4 · The fine print

They do not promise the labs will work, stay up, or be safe.

Read the exact line

Terms of service

“THE PLATFORM IS PROVIDED "AS IS" AND "AS AVAILABLE" OF ANY KIND, EXPRESS OR IMPLIED”

For example, if a container dies and you lose work, they say they are not responsible.

5 · What is collected

Your main account data lives on a server in Russia, and other vendors may process it elsewhere.

Read the exact line

Privacy policy

“Primary application data is stored on the Platform's production host in Moscow, Russia.”

For example, your email and solve history sit on a Moscow host even if you live in the EU.

6 · How long it is kept

Old certificates put on the blockchain can keep your old username forever.

Read the exact line

Privacy policy

“Historical Polygon transactions cannot be erased; future mints contain no account identifier.”

For example, deleting your account will not wipe a past on-chain certificate that used your username.

7 · How it is used

They say they will not sell your data or give it to ad networks.

Read the exact line

Privacy policy

“We do not sell, rent, or trade your personal information to any third party. We do not share your data with advertising networks or data brokers.”

For example, your lab scores should not be sold to a marketing list.

8 · How long it is kept

You can delete most of your account yourself and it is removed right away after they check it is you.

Read the exact line

Privacy policy

“Self-service deletion removes the active account, profile, avatar, and personal solve/activity records immediately after ownership checks”

For example, after you delete in settings, your bio and private solve list should disappear.

9 · How it is used

You still own what you upload; they only get a license to run the site.

Read the exact line

Terms of service

“You retain ownership of your original content. You represent that you have the right to submit any content you provide”

For example, a lab proposal you write stays yours even after they display it.

10 · Terms

you can go to court.

Read the exact line

Terms of service

“If negotiation fails, disputes shall be submitted to the competent courts.”

For example.

Words to know

Legal words from the lines above, in plain English.

sell or share
Under California law, selling means passing your data to others for money or other value; sharing means passing it on for targeted ads. For example, letting an ad network use your browsing history in return for ad space counts as a sale.
personal data
Any information that is about you or can be linked to you, from your name to your phone's ID. For example, your email, your IP address and the list of apps on your phone are all personal data.
third parties
Any company or person other than you and the app, such as advertisers, partners or analytics firms. For example, an analytics company that receives a record of every screen you tap is a third party.
data broker
A company that buys, collects and resells information about people, usually without ever meeting them. For example, your phone number and shopping habits can be sold as part of a list to a company you never heard of.
right to erasure
Your right to have a company delete the personal data it holds about you, with some exceptions. For example, you can ask a social app to wipe your old posts and profile and it must, unless a law says otherwise.
indemnify
You promise to pay the company's legal costs and losses if your use of the service gets it sued. For example, if you post a song you do not own and the label sues the app, you owe the app's lawyer bills.
affiliates
Other companies owned by or connected to the same parent company. For example, if you use one app, its sister apps under the same owner may also get your data.
as is
You get the service in whatever state it is in, with no promise that it works or will keep working. For example, if the app deletes your photos by mistake, it is not promising to fix that or pay you back.
warranty
A promise that a product will work as described; most apps say they make no such promise at all. For example, if a paid feature never works on your phone, a no-warranty clause says that is your problem.
How we got here · grade A · score 57/100 · 14 of 15 policy answers backed by a verified quote · 4 not stated
  • What does the app collect beyond what it needs to work?

    They collect account details, optional profile fields, lab usage, IPs, user-agent, and similar technical data.

  • Does it record your voice, face or body, and what happens to that?

    The documents do not describe collecting voice, face, or body data.

  • Are your chats and uploads used to train AI models, and is that off by default?

    Not stated in the documents.

  • Can employees or contractors read your conversations, and when?

    Not stated in the documents.

  • Are you profiled or tracked for advertising?

    They say they do not use advertising cookies or social tracking pixels; analytics load only after consent.

  • Do they sell or share your data, and can you opt out?

    They say they do not sell data; they share with hosting, email, Cloudflare, optional analytics, and AI providers who run features.

  • What rights do they take over what you type and what the AI makes?

    You keep ownership; they take a non-exclusive license only to operate the platform.

  • How long do they keep your data after you delete it, and can you delete it in the app?

    You can delete in account settings; they say the active account is removed immediately and rights requests within 30 days. Some certificates and backups remain.

  • Does it build a lasting memory or profile of you, and can you see, edit or turn it off?

    Not stated in the documents.

  • Do they commit to basic security, and have they leaked data?

    They describe TLS, hashed passwords, encryption, access controls, and rate limiting. No independent audit is named.

  • Is there a real age gate, and are teens protected?

    You must be 16+. Ages 16–18 must say they have parent consent. There is no described age-check beyond that.

  • Will they tell you when the rules change, and is the policy specific?

    They promise 14 days’ notice for material changes, but the copies we have have no last-updated date.

  • Can they close your account without warning, and can you get your data out first?

    They may suspend or terminate at any time, with or without cause or notice. You can still ask to delete data.

  • If something goes wrong, who pays?

    The platform is as-is, liability is capped at fees or €100, and you must indemnify them for claims tied to your use.

  • Do subscriptions renew on their own, and can you get a refund?

    Not stated in the documents.

The privacy policy is 2,144 words at a professional or legal expert level (Flesch reading ease 11.4); the terms are 1,871 words at a professional or legal expert level.

Your privacy
has an agent now

Be in control of your online privacy in the AI Era with confidence.

Gen

From Gen, the Company BehindNorton