Privacy Policy
ExploitGrid is committed to protecting your privacy and ensuring the security of your personal information. This policy explains how we collect, use, and safeguard your data.
Last updated: 9/18/2026
Information We Collect
Personal Information
- • Account Information: Handle, email address, password (encrypted)
- • Profile Data: Optional profile information you provide
- • Payment Information: Billing details for subscriptions (processed securely via Stripe, Paddle, or PayPal depending on your selected payment method)
- • Contact Information: When you contact us for support or inquiries
- • Social Account Data: Information from connected social accounts (such as Google, GitHub, or LinkedIn) when you use social sign-in, including your name, email, and profile identifier
Technical Information
- • Usage Data: Platform interactions, feature usage, performance metrics
- • Device Information: Browser type, operating system, device identifiers
- • Network Data: IP addresses, VPN connection and disconnection logs, network performance
- • Security Logs: Authentication attempts (including IP address and user agent), security events, audit trails
- • Geolocation Data: Approximate geographic location derived from your IP address, including country, city, and approximate coordinates, used for security monitoring and abuse prevention
Activity Information
- • PvP Session Data: Detailed logs of your attack and defense activities, including commands executed during PvP sessions, attack outcomes (e.g., owned, defended, foothold, timeout), timestamps, and session metadata. This data is collected for platform integrity, security enforcement, and compliance purposes
- • Virtual Machine Activity: Box creation, start/stop events, snapshot activity, firewall configurations, and resource usage (VM hours, snapshot storage, egress bandwidth)
- • Communication: Messages sent through our platform chat features (stored in encrypted format)
- • AI Assistant Usage: Interactions with our AI MentorBot, including chat sessions and token usage, used to manage quotas and improve the service
- • Leaderboard and Achievements: Matchmaking rating (MMR), badges earned, public achievements, and ranking data
- • Marketing Attribution: Referral codes, campaign identifiers (UTM parameters), and traffic source information used to measure the effectiveness of our marketing efforts
- • Support and Feedback: Support tickets, satisfaction scores, and feedback you provide
How We Use Your Information
Service Provision
- • Provide and maintain the ExploitGrid platform
- • Authenticate users and manage accounts
- • Process payments and manage subscriptions
- • Deliver personalized cybersecurity training content
- • Enable communication features and collaboration
- • Facilitate PvP matchmaking and manage competitive rankings
- • Provision and manage virtual machine infrastructure
Platform Improvement
- • Analyze usage patterns to improve user experience
- • Develop new features and enhance existing ones
- • Monitor platform performance and security
- • Conduct research and analytics for platform optimization
Security, Integrity, and Compliance
- • Detect and prevent abuse, fraud, and unauthorized access
- • Monitor PvP sessions and command activity to enforce platform rules and acceptable use policies
- • Maintain audit trails for compliance with legal obligations and law enforcement requests
- • Enforce sanctions and export control compliance
Communication
- • Send important account and security notifications
- • Provide customer support and respond to inquiries
- • Share platform updates and new features
- • Send marketing communications (with consent)
Legal Basis for Processing
If you are located in the European Economic Area (EEA), United Kingdom, or another jurisdiction that requires a legal basis for processing personal data, we rely on the following legal bases:
Performance of Contract
Processing necessary to provide you with the ExploitGrid platform and services you have signed up for, including account management, PvP matchmaking, virtual machine provisioning, payment processing, and customer support.
Legitimate Interests
Processing necessary for our legitimate interests, including: security monitoring and abuse prevention; platform integrity enforcement; fraud detection; analytics and platform improvement; and maintaining audit trails. We balance these interests against your rights and only rely on this basis where our interests are not overridden by your data protection rights.
Consent
Processing based on your explicit consent, including: marketing communications, non-essential cookies, and optional data sharing. You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
Legal Obligation
Processing necessary to comply with legal obligations, including: tax and financial record-keeping, responding to lawful law enforcement requests, court orders and subpoenas, and sanctions/export control compliance.
Platform Activity Monitoring
Important Notice: ExploitGrid actively monitors all activity on the platform, including commands executed during PvP sessions, VPN traffic patterns, and virtual machine operations. This monitoring is essential to maintain platform security, enforce acceptable use policies, and comply with legal obligations. By using the platform, you acknowledge and consent to this monitoring.
What We Monitor
- • PvP Command Logs: All commands executed by attackers and defenders during PvP sessions are recorded and stored
- • VPN Activity: Connection and disconnection events, traffic patterns, and cross-subnet communication attempts
- • Abuse Detection: Automated systems monitor for unauthorized access attempts, cross-subnet traffic, port scanning outside of sanctioned PvP activities, and other suspicious behavior
- • Authentication Events: All login attempts, password changes, and session activity are logged with IP address and device information
Law Enforcement and Legal Disclosure
Notice: Activity logs, command histories, PvP session records, and other platform data may be disclosed to law enforcement agencies, regulatory bodies, or other government authorities in response to valid legal process, including subpoenas, court orders, search warrants, or other lawful requests. We may also proactively report activity to law enforcement if we have reasonable grounds to believe that a user is engaged in illegal activity or poses a threat to the safety of others. We will attempt to notify affected users of such disclosures unless prohibited by law or court order.
Automated Decision-Making
ExploitGrid uses automated systems to make certain decisions that may affect your experience on the platform. Under applicable data protection laws (including GDPR Article 22), you have rights regarding automated decision-making:
Matchmaking (MMR-based)
Our system automatically matches you with opponents based on your Matchmaking Rating (MMR) and other factors to ensure fair and competitive PvP sessions.
Abuse Detection
Automated systems monitor for policy violations, including cross-subnet traffic, unauthorized access attempts, and suspicious behavior. Detection of abuse may result in automated VPN revocation, account suspension, or other enforcement actions.
Credit and Usage Management
Automated systems manage daily usage allowances, credit deductions, and tier-based access limits.
You have the right to request human review of any automated decision that significantly affects you, to express your point of view, and to contest such decisions. To exercise these rights, contact us at [email protected].
Data Security and Protection
Security Measures
- • Encryption: AES-256-CBC encryption for all sensitive data at rest
- • Transport Security: TLS 1.3 for all data in transit
- • Access Controls: Role-based access with principle of least privilege
- • Authentication: Multi-factor authentication for admin accounts
- • Monitoring: 24/7 security monitoring and threat detection
Data Retention
- • Account data is retained while your account is active
- • PvP session logs, command histories, and security data are retained for up to 2 years for compliance and security purposes
- • Payment information is retained as required by law
- • Geolocation and authentication logs are retained for up to 2 years for security monitoring
- • You can request data deletion at any time (subject to legal retention requirements)
Incident Response
In the event of a data breach, we will notify affected users within 72 hours and take immediate action to secure systems and prevent further unauthorized access. Where required by law (e.g., GDPR), we will also notify the relevant supervisory authority within the same timeframe.
Data Sharing and Third Parties
Third-Party Services
Payment Processing
We use Stripe, Paddle, and/or PayPal for secure payment processing, depending on your selected payment method and region. These providers handle payment card data in compliance with PCI DSS standards. Paddle may act as the merchant of record for certain transactions.
AI Services
Our AI MentorBot feature uses third-party AI providers (such as OpenAI, Anthropic, and Google) to process your queries. Your AI chat interactions may be sent to these providers for processing. We do not share your personal identity with AI providers.
Analytics and Monitoring
We use analytics tools to improve our platform. These tools may collect anonymized usage data.
Infrastructure Providers
Our platform is hosted on secure cloud infrastructure with appropriate data processing agreements in place. Virtual machine infrastructure may be provisioned through third-party providers subject to data processing agreements.
Legal Disclosure
We may disclose personal information if required by law, court order, subpoena, or government request, or to protect our rights, property, or safety, or that of others. This includes disclosure to law enforcement agencies in connection with suspected illegal activity or violations of our Terms and Conditions. See the "Platform Activity Monitoring" section above for further details.
No Sale of Personal Data
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
Your Rights and Choices
Data Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- • Access: Request a copy of your personal data
- • Rectification: Correct inaccurate or incomplete data
- • Erasure: Request deletion of your personal data (subject to legal retention obligations, including data retained for law enforcement compliance)
- • Portability: Export your data in a structured, commonly used, machine-readable format
- • Restriction: Limit how we process your data
- • Objection: Object to processing based on legitimate interests
- • Withdraw Consent: Where processing is based on consent, withdraw your consent at any time
- • Lodge a Complaint: File a complaint with your local data protection supervisory authority
Exercising Your Rights
To exercise any of these rights, contact us at [email protected]. We will respond to your request within 30 days (or sooner where required by law). We may need to verify your identity before processing your request. Note that certain data may be exempt from deletion requests where we are legally required to retain it (for example, PvP session logs retained for law enforcement compliance).
Communication Preferences
- • Opt out of marketing communications at any time
- • Manage notification preferences in your account settings
- • Unsubscribe links are provided in all marketing emails
Account Management
- • Update your profile information at any time
- • Download your data from your account settings
- • Delete your account and associated data
Cookies and Tracking
Cookie Usage
Essential Cookies
Required for authentication, security, and basic platform functionality. These cannot be disabled.
Performance Cookies
Help us understand how users interact with our platform to improve performance.
Preference Cookies
Remember your settings and preferences for a better user experience.
Managing Cookies
You can control cookies through your browser settings. Note that disabling certain cookies may affect platform functionality. For non-essential cookies, we will obtain your consent before placing them on your device where required by applicable law.
International Data Transfers
ExploitGrid operates globally, and your data may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for all international data transfers, including:
- • Standard contractual clauses approved by relevant authorities
- • Adequacy decisions by data protection authorities
- • Appropriate technical and organizational measures
- • Regular compliance reviews and audits
If you are located in the EEA or UK, your data may be transferred to countries outside these regions, including the United States, for the purposes described in this policy. In such cases, we ensure transfers comply with Chapter V of the GDPR through the safeguards listed above.
Age Requirements
Important: ExploitGrid is designed exclusively for users 18 years of age and older. Due to the nature of our platform, which involves offensive and defensive cybersecurity techniques in a live environment, we do not permit use by minors under any circumstances.
We do not knowingly collect personal information from anyone under 18 years of age. If we become aware that we have collected personal information from a person under 18, we will take steps to delete such information and terminate the associated account promptly.
If you are a parent or guardian and believe your child has provided us with personal information or created an account, please contact us immediately at [email protected].
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify users of any material changes through:
- • Email notification to registered users
- • Prominent notice on our platform
- • Updated "Last Modified" date on this policy
Where required by applicable law (including GDPR), material changes that affect the legal basis for processing or introduce new categories of data collection will require your affirmative consent before taking effect. We will not rely on continued use alone as evidence of consent for material changes that require it under applicable law.
Privacy Questions?
If you have questions about this Privacy Policy, our data practices, or wish to exercise your data rights, please contact our designated Privacy Contact:
If you are located in the EEA or UK and are unsatisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.