GenAgent Trust Hub
Menu

Hackerone

DTier DMedium risk · 36/100
  • The policy allows AI training; it does not describe an opt-out.
  • Your data is used for personalized ads, including by third-party ad companies.
  • Data is shared only with the providers who run the service.
  • The documents do not say who can read your content.

They collect IDs, chats, and face scans, keep much of it for years, use ML on your content, and you them.

Highest riskMedium riskLow risk

Agent Trust Hub uses AI and may make mistakes. Review reports and confirm their contents before relying on them.

Privacy policy · July 25, 2026 ↗Terms · May 11, 2026 ↗20 min read · professional or legal expert level27 lines verified word for word
  • Uses your content for AI training with no opt-out

Collected

What is collected

Account info, chats, device data, payments, and for researchers IDs, SSN, and face scans.

Read the exact line

Privacy policy

“Vetting Data or other Community Member related information including: your Account Data; survey data; date of birth; nationality; current and previous addresses; social security (or tax identification) number; identification documents”

Training

How it is used

They run the service, market to you, check IDs, and use machine learning on how you use it and what you submit.

Read the exact line

Privacy policy

“We use machine learning to understand more about Community Members and customers, and how we can improve our business and Services.”

Sharing

Who may see it

Vendors (hosting, ads, payments, ID checks, AI chatbot) and, if you agree, public reports tied to your profile.

Read the exact line

Privacy policy

“We may share your personal data with third-party service providers, who will process it on our behalf for the purposes identified above.”

Kept

How long it is kept

Account, payment, and vetting data can be kept 7 years after you leave; chatbot chats up to 12 months.

Read the exact line

Privacy policy

“Account Data, Payment Data, and Vetting Data: 7 years from when our relationship with you ends, except where a different period is required by applicable law.”

Controls

Your controls

You can unsubscribe from marketing, disable your profile, and email privacy@hackerone.com to use / rights.

Read the exact line

Privacy policy

“You may choose to disable your HackerOne account at any time. This means your user profile will no longer be visible through the Services.”

Fine print

The fine print

Services are as-is, fees are non-refundable, and customers must HackerOne in several cases.

Read the exact line

Terms of service

“The HackerOne Fees and Reward payments to Community Members are non-refundable, except as otherwise specifically provided herein or in the applicable Order Form.”

Expand “Read the exact line” to see the source alongside the explanation.

What you can turn off

The controls and opt-outs their own documents describe, and where they say to find them.

  1. Manage marketing emails

    https://ma.hacker.one/SubscriptionManagement.html or the unsubscribe link in emails

  2. Withdraw Google Analytics consent

    The Google Analytics opt-out link referenced in the privacy policy

  3. Disable your account / exercise deletion rights

    Disable in the product; email privacy@hackerone.com to ask them to restrict or delete data

  4. Withdraw consent they rely on

    Email privacy@hackerone.com

If a switch is not where they say, the deletion request above still applies.

Line by line

The lines that matter most, worst first.

1 · What is collected

They can take face scans and measurements from your ID photos to prove who you are.

Read the exact line

Privacy policy

“images and/or videos, including face scans and other measurements extracted from the same which are used to authenticate the Community Member”

For example, when you join a paid bug-bounty program they may scan your passport photo and your face.

2 · How it is used

They run machine learning on how you use the platform and the content you submit, with no opt-out described.

Read the exact line

Privacy policy

“We use machine learning to understand more about Community Members and customers, and how we can improve our business and Services.”

For example, reports you file could be used to shape their products and marketing.

3 · How long it is kept

Even after you leave, they can keep your account, payment, and ID-check data for seven years.

Read the exact line

Privacy policy

“Account Data, Payment Data, and Vetting Data: 7 years from when our relationship with you ends, except where a different period is required by applicable law.”

For example, your passport copy and SSN could sit in their files long after you disable the account.

4 · The fine print

If someone sues over your data or how you used a researcher’s report, you may have to pay HackerOne’s legal bills.

Read the exact line

Terms of service

“The Customer will , defend, and HackerOne and its officers, directors, employees, and agents, from and against any claims”

For example, if a report you published leads to a lawsuit, you could have to cover their lawyers.

5 · The fine print

They do not promise the platform will work, be secure, or fit your needs.

Read the exact line

Terms of service

“THE SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE" AND OF ANY KIND, EXPRESS OR IMPLIED”

For example, if a bug in the platform leaks a report, these terms try to limit their duty to you.

6 · How it is used

They use outside ad and analytics companies so you can see HackerOne ads elsewhere.

Read the exact line

Privacy policy

“we can use our third parties to deliver ads for HackerOne Services to you later on websites and those of third parties”

For example, after you visit the site, you might see HackerOne ads on other websites via Google or Meta.

7 · How long it is kept

They build skill and preference profiles about researchers from the data they collect.

Read the exact line

Privacy policy

“Inferences drawn from any of the information identified to create a profile about a consumer reflecting the consumer's preferences, intelligence, abilities, and aptitudes”

For example, they may rate your skills from your reports without a simple in-app way to turn that off.

8 · How it is used

The website chatbot vendor is not allowed to train its own AI on your chats.

Read the exact line

Privacy policy

“This provider processes chat content and contact information you submit via the chatbot, and technical data required to operate the website AI chatbot, solely on our behalf and for our business purposes, and is contractually prohibited from using your data for its own purposes or to train AI models.”

For example, a question you type in the help chatbot should not be used to train that vendor’s model.

9 · How it is used

They say they do not sell or share your data for ads that follow you across other companies’ sites.

Read the exact line

Privacy policy

“WE DO NOT SELL OR SHARE YOUR PERSONAL DATA FOR CROSS-CONTEXT BEHAVIORAL ADVERTISING.”

For example, they claim they will not sell a list of your browsing to an ad network for that purpose.

10 · How it is used

They take a license to use your uploaded data to run and improve the service, not a full ownership grab.

Read the exact line

Terms of service

“By making any Customer Data available through the Services, the Customer hereby grants to HackerOne a non-exclusive, non-transferable, non-, worldwide, license to use, copy, reproduce, display, modify, adapt, transmit, and distribute copies of such Customer Data for the purpose of providing and improving the Services.”

For example, they can copy a program policy you upload so the platform can show it to researchers.

11 · The fine print

Kids under 13 are told to have a parent submit, but they also say skilled members are not determined by age.

Read the exact line

Privacy policy

“If you are under the age of 13 and want to submit a vulnerability report to us, please ask your parent or guardian to submit it for you.”

For example, a 14-year-old could still register; rewards are only for adults who accept the member terms.

Words to know

Legal words from the lines above, in plain English.

personal data
Any information that is about you or can be linked to you, from your name to your phone's ID. For example, your email, your IP address and the list of apps on your phone are all personal data.
third parties
Any company or person other than you and the app, such as advertisers, partners or analytics firms. For example, an analytics company that receives a record of every screen you tap is a third party.
service providers
Outside companies that handle your data on the app's instructions, such as a cloud host or an email sender. For example, the company that stores the app's files in the cloud sees your data but only does what the app tells it.
indemnify
You promise to pay the company's legal costs and losses if your use of the service gets it sued. For example, if you post a song you do not own and the label sues the app, you owe the app's lawyer bills.
as is
You get the service in whatever state it is in, with no promise that it works or will keep working. For example, if the app deletes your photos by mistake, it is not promising to fix that or pay you back.
warranty
A promise that a product will work as described; most apps say they make no such promise at all. For example, if a paid feature never works on your phone, a no-warranty clause says that is your problem.
profiling
Building a picture of who you are, what you like and what you might do next from your data. For example, an app may guess your income, health or politics from what you watch and tap.
model training
Using your content and conversations as examples to teach an AI system, which can then echo them in future answers. For example, a story you write in a chatbot may be studied by the company to make the next version of the bot.
sell or share
Under California law, selling means passing your data to others for money or other value; sharing means passing it on for targeted ads. For example, letting an ad network use your browsing history in return for ad space counts as a sale.
targeted advertising
Ads chosen for you based on what you have done across other apps and websites, not just this one. For example, you look at shoes in one app and see shoe ads in a totally different app the next day.
sublicensable
The company can pass its rights over your content on to other companies without asking you. For example, an app can let an advertiser or a partner reuse your video under the licence you gave.
royalty-free
The company can use your content without ever paying you for it. For example, your photo can appear in the app's ads and you get nothing.
How we got here · grade D · score 36/100 · 15 of 15 policy answers backed by a verified quote · 1 not stated
  • What does the app collect beyond what it needs to work?

    They collect account and content data plus analytics, device IDs, ads data, and for researchers IDs, SSN, addresses, and face scans.

  • Does it record your voice, face or body, and what happens to that?

    They collect video, audio, and face scans for meetings and ID checks, and vetting data is kept with the account for years.

  • Are your chats and uploads used to train AI models, and is that off by default?

    They use machine learning on service use and submitted content with no opt-out described. The website chatbot vendor is barred from training its own models.

  • Can employees or contractors read your conversations, and when?

    Not stated in the documents.

  • Are you profiled or tracked for advertising?

    They use Google Analytics, LinkedIn, Meta, and remarketing so ads for HackerOne can follow you on other sites.

  • Do they sell or share your data, and can you opt out?

    They share with service providers and say they do not sell or share for cross-context behavioral advertising.

  • What rights do they take over what you type and what the AI makes?

    Customers keep ownership of their data and grant a non-sublicensable license only to provide and improve the services.

  • How long do they keep your data after you delete it, and can you delete it in the app?

    You can disable your profile, but account, payment, and vetting data may be kept 7 years after the relationship ends.

  • Does it build a lasting memory or profile of you, and can you see, edit or turn it off?

    They draw inferences to profile researchers’ skills and preferences; no in-app memory controls are described.

  • Do they commit to basic security, and have they leaked data?

    They describe technical and organizational measures and Data Privacy Framework certification, but no independent audit of the product is detailed.

  • Is there a real age gate, and are teens protected?

    They welcome members of any skill age, tell under-13s to have a parent submit, and pay rewards only to adults.

  • Will they tell you when the rules change, and is the policy specific?

    The privacy policy is dated and lists data types, purposes, and retention; they may email or post before changes take effect.

  • Can they close your account without warning, and can you get your data out first?

    They can cut off access immediately for trade-control reasons, and disabling a profile does not remove internal copies or public reports.

  • If something goes wrong, who pays?

    Services are as-is, and customers must indemnify HackerOne for several third-party claims, including over customer data.

  • Do subscriptions renew on their own, and can you get a refund?

    Customer fees and reward payments are non-refundable except where an order form says otherwise.

The privacy policy is 4,554 words at a professional or legal expert level (Flesch reading ease 9.7); the terms are 4,422 words at a professional or legal expert level.

Your privacy
has an agent now

Be in control of your online privacy in the AI Era with confidence.

Gen

From Gen, the Company BehindNorton