LEGAL
Privacy Policy
Last updated: June 2026
THE SHORT VERSION
- We collect the minimum data needed to run the service
- We do not log what you do inside your terminal, ever
- We do not sell your data or use it for advertising
- Your VM runs in the EU and stays there
- You can ask us to delete everything at any time
Who we are
HackShell provides managed Kali Linux boxes for security researchers, CTF players, and HTB enthusiasts. When this policy says “we”, “us”, or “HackShell”, it means the operator of hackshell.io.
For UK GDPR purposes, HackShell is the data controller for the personal data described in this policy.
Questions or requests: privacy@hackshell.io
What data we collect and why
Account data
When you sign up, we collect your email address and a hashed password (managed by Supabase Auth). We need this to identify you, let you log in, and contact you about your account.
Billing data
Payments are handled entirely by Stripe. We never see or store your card number, sort code, or bank details. Stripe gives us a customer ID and subscription status, that's all we keep on our side. Stripe's own privacy policy applies to the data they hold.
VM metadata
When a VM is provisioned for you, we store the VM instance ID, your Tailscale IP address, provisioning status and timestamps, and a hostname assigned to your box. We do not store the contents of your VM's filesystem.
Credentials
Your VM root password is generated when the box is provisioned. We store it encrypted (AES-256-GCM) so we can show it to you securely on your dashboard. The encryption key is never stored in the same place as the encrypted password. Every time you reveal your credentials, we log the timestamp and your IP address, not the password itself.
Audit log
We keep a minimal event log covering VM provisioning/deprovisioning, credential reveals (timestamp + IP, not the credential), and billing events. This log exists so we can respond to abuse reports and debug problems. It is retained for 90 days and then automatically deleted.
IP addresses
Your IP address is logged when you interact with the dashboard (credential reveals, account actions). It is not logged continuously and is not used for tracking.
What we do NOT collect
We do not log terminal session activity. What you type in your shell, what commands you run, what files you create, none of this is recorded or stored by HackShell. This is a deliberate design decision, not an oversight.
We also do not use:
- Analytics or tracking scripts
- Advertising networks
- Session recording tools
- Third-party marketing pixels
Who we share data with
We use a small number of third-party services to operate HackShell. Each one receives only the data they need to do their job.
| Service | Purpose | Data shared |
|---|---|---|
| Stripe | Payment processing | Email, billing info |
| OVHcloud | VM hosting (EU datacentres) | VM configuration, no personal content |
| Supabase | Database and authentication | Account data, VM metadata, audit log |
| Tailscale | Private networking | VM hostname, network keys |
| Vercel | Application hosting | Encrypted credentials (key held separately) |
We do not sell your data to anyone, ever.
Where your data is stored
Your VM runs in OVHcloud datacentres located in the European Union. HackShell uses OVHcloud's EU region specifically to keep your data in the EU. OVHcloud operates under a Data Processing Agreement that complies with UK GDPR.
Other services (Supabase, Vercel, Tailscale, Stripe) may process data outside the EU. Where this happens, appropriate safeguards (Standard Contractual Clauses or adequacy decisions) are in place.
How long we keep your data
| Data | Retention |
|---|---|
| Account data | Until you delete your account |
| VM metadata | Soft-deleted on cancellation, permanently deleted after 30 days |
| Encrypted credentials | Deleted immediately when your VM is deprovisioned |
| Audit log | 90 days, then automatically purged |
| Billing records | As required by Stripe and UK financial regulations (typically 7 years) |
Your rights under UK GDPR
You have the right to:
- Access — ask us what personal data we hold about you
- Rectification — ask us to correct inaccurate data
- Erasure — ask us to delete your data ("right to be forgotten")
- Portability — ask for a copy of your data in a machine-readable format
- Restriction — ask us to stop processing your data in certain circumstances
- Object — object to processing based on legitimate interests
To exercise any of these rights, email privacy@hackshell.io. We will respond within 30 days.
If you are unhappy with how we have handled your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
Cookies
HackShell uses only the cookies necessary to keep you logged in. We do not use tracking or advertising cookies. There is no cookie consent banner because there is nothing to consent to.
Security
We take reasonable technical and organisational measures to protect your data, including:
- Encryption of credentials at rest (AES-256-GCM)
- HTTPS for all connections
- Row-level security on all database tables
- Access controls limiting who can query what
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the ICO as required by UK GDPR.
Changes to this policy
If we make significant changes to this policy, we will notify you by email before the changes take effect. The “last updated” date at the top of this page will always reflect the current version.
Contact
For privacy questions, data requests, or concerns: