← Back to home
Privacy Policy
Last updated: 20 July 2026
This Privacy Policy describes how KernelSec ("we", "us", or "our") collects, uses, and shares information when you use our website and services (collectively, the "Service"). We are committed to handling your personal data transparently and in accordance with applicable privacy laws, including the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
1. Who we are
KernelSec operates the service available at kernelsec.app. For GDPR purposes, KernelSec is the data controller for personal data collected through the Service. Questions or requests related to this policy should be directed to [email protected].
2. Information we collect
We collect only what is necessary to provide and secure the Service:
- Account information: your email address and a hashed representation of your password. We use PBKDF2 with SHA-256 and a random salt (100,000 iterations) — we never store or transmit your plaintext password.
- Usage and security data: IP address, timestamps of requests, HTTP method and path, and HTTP status codes. This data is used for rate-limiting, abuse prevention, debugging, and security monitoring.
- Session tokens: a cryptographically random token issued at login, stored in your browser's local storage, and used to authenticate subsequent requests. Tokens expire after 8 hours.
We do not collect your name, phone number, payment card details (billing is handled directly by our payment processor), or any sensitive personal information beyond the above.
3. How we collect it
- Directly from you: when you register, log in, reset your password, or contact us.
- Automatically: IP address and request metadata are logged server-side whenever you interact with the API.
We do not use browser cookies for authentication. We do not embed third-party advertising, analytics, or tracking scripts on authenticated pages of the Service.
4. Legal basis for processing (GDPR)
If you are in the European Economic Area (EEA) or United Kingdom, our legal bases for processing your personal data are:
- Contract performance (Art. 6(1)(b) GDPR): processing your email address and password hash to create and maintain your account and to deliver the Service you requested.
- Legitimate interests (Art. 6(1)(f) GDPR): processing IP addresses and request logs to detect abuse, prevent fraud, enforce rate limits, and maintain the security of the Service. Our legitimate interests do not override your fundamental rights.
- Legal obligation (Art. 6(1)(c) GDPR): where we are required to retain or disclose data to comply with applicable law.
5. How we use your information
- To create, authenticate, and secure your account.
- To send transactional email you have explicitly requested (email confirmation, password reset). We do not send marketing email without your separate consent.
- To detect, investigate, and prevent fraudulent, abusive, or unlawful activity.
- To operate, maintain, and improve the Service.
- To comply with legal obligations and enforce our Terms of Service.
6. How we share your information
We do not sell, rent, or trade your personal information. We share data only in the following limited circumstances:
- Email delivery (Resend): your email address is passed to Resend solely to deliver transactional emails you have requested. Resend acts as a data processor under our instructions and may not use your data for other purposes.
- Legal compliance: we may disclose information if required by law, court order, or governmental authority, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
- Business transfer: if KernelSec is involved in a merger, acquisition, or asset sale, your data may be transferred as part of that transaction. We will notify you before your data is transferred and becomes subject to a different privacy policy.
7. Third-party data sources on the map
The OSINT map surface uses publicly available data from third-party providers (airplanes.live, AISStream, CelesTrak, USGS, NASA EONET, OurAirports, DeFlock, OpenFreeMap, and Esri). When your browser loads map tiles or makes requests to external data APIs, those third parties may log your IP address according to their own privacy policies. We have no control over and are not responsible for these third-party practices.
8. Data retention
- Account data (email, password hash) is retained for as long as your account is active.
- Session tokens expire after 8 hours and are purged on logout.
- Security logs (IP, timestamps) are retained for a period appropriate to your plan tier and then deleted.
- Upon account deletion, your email address, password hash, sessions, and associated tokens are permanently removed within 30 days.
9. Security
We implement technical and organisational measures designed to protect your personal data, including:
- HTTPS for all data in transit (TLS via Caddy / Cloudflare).
- PBKDF2-SHA256 password hashing with per-user random salts (100,000 iterations).
- Per-IP rate limiting on all authentication endpoints.
- Single-use, time-limited tokens for email confirmation and password reset.
- Parameterised database queries to prevent SQL injection.
No system is perfectly secure. We cannot guarantee absolute security but will notify you of any breach affecting your personal data as required by applicable law.
10. International data transfers
The Service is hosted on infrastructure in the United States. If you are located in the EEA, UK, or another jurisdiction with data transfer restrictions, your personal data may be transferred to and processed in the US. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for such transfers.
11. Children's privacy
The Service is not directed to children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, please contact us and we will promptly delete it.
12. Cookies and local storage
We do not use cookies for tracking or advertising. The Service uses browser local storage to store your session token and UI preferences (such as map layer settings). This data is stored only on your device and is not transmitted to third parties. Clearing your browser's local storage will log you out.
13. Your rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: request a copy of the personal data we hold about you.
- Rectification: request correction of inaccurate or incomplete data.
- Erasure ("right to be forgotten"): request deletion of your personal data, subject to legal retention obligations.
- Data portability: request your data in a structured, machine-readable format.
- Restriction: request that we restrict processing of your data in certain circumstances.
- Objection: object to processing based on legitimate interests.
- Withdraw consent: where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
California residents have additional rights under the CCPA, including the right to know, delete, and opt out of the sale of personal information. We do not sell personal information.
To exercise any of these rights, email [email protected]. We will respond within 30 days (or as required by applicable law). We may ask you to verify your identity before fulfilling your request.
If you are in the EEA or UK and believe we have not handled your data lawfully, you have the right to lodge a complaint with your local supervisory authority (e.g., your national data protection authority).
14. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated by updating the effective date above and, where appropriate, by email notification. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.
15. Contact
For privacy-related questions, requests, or complaints, contact us at [email protected].