LEGAL

Privacy Policy

Last updated: June 2026

THE SHORT VERSION

  • We collect the minimum data needed to run the service
  • We do not log what you do inside your terminal, ever
  • We do not sell your data or use it for advertising
  • Your VM runs in the EU and stays there
  • You can ask us to delete everything at any time

Who we are

HackShell provides managed Kali Linux boxes for security researchers, CTF players, and HTB enthusiasts. When this policy says “we”, “us”, or “HackShell”, it means the operator of hackshell.io.

For UK GDPR purposes, HackShell is the data controller for the personal data described in this policy.

Questions or requests: privacy@hackshell.io

What data we collect and why

Account data

When you sign up, we collect your email address and a hashed password (managed by Supabase Auth). We need this to identify you, let you log in, and contact you about your account.

Billing data

Payments are handled entirely by Stripe. We never see or store your card number, sort code, or bank details. Stripe gives us a customer ID and subscription status, that's all we keep on our side. Stripe's own privacy policy applies to the data they hold.

VM metadata

When a VM is provisioned for you, we store the VM instance ID, your Tailscale IP address, provisioning status and timestamps, and a hostname assigned to your box. We do not store the contents of your VM's filesystem.

Credentials

Your VM root password is generated when the box is provisioned. We store it encrypted (AES-256-GCM) so we can show it to you securely on your dashboard. The encryption key is never stored in the same place as the encrypted password. Every time you reveal your credentials, we log the timestamp and your IP address, not the password itself.

Audit log

We keep a minimal event log covering VM provisioning/deprovisioning, credential reveals (timestamp + IP, not the credential), and billing events. This log exists so we can respond to abuse reports and debug problems. It is retained for 90 days and then automatically deleted.

IP addresses

Your IP address is logged when you interact with the dashboard (credential reveals, account actions). It is not logged continuously and is not used for tracking.

What we do NOT collect

We do not log terminal session activity. What you type in your shell, what commands you run, what files you create, none of this is recorded or stored by HackShell. This is a deliberate design decision, not an oversight.

We also do not use:

  • Analytics or tracking scripts
  • Advertising networks
  • Session recording tools
  • Third-party marketing pixels

Who we share data with

We use a small number of third-party services to operate HackShell. Each one receives only the data they need to do their job.

ServicePurposeData shared
StripePayment processingEmail, billing info
OVHcloudVM hosting (EU datacentres)VM configuration, no personal content
SupabaseDatabase and authenticationAccount data, VM metadata, audit log
TailscalePrivate networkingVM hostname, network keys
VercelApplication hostingEncrypted credentials (key held separately)

We do not sell your data to anyone, ever.

Where your data is stored

Your VM runs in OVHcloud datacentres located in the European Union. HackShell uses OVHcloud's EU region specifically to keep your data in the EU. OVHcloud operates under a Data Processing Agreement that complies with UK GDPR.

Other services (Supabase, Vercel, Tailscale, Stripe) may process data outside the EU. Where this happens, appropriate safeguards (Standard Contractual Clauses or adequacy decisions) are in place.

How long we keep your data

DataRetention
Account dataUntil you delete your account
VM metadataSoft-deleted on cancellation, permanently deleted after 30 days
Encrypted credentialsDeleted immediately when your VM is deprovisioned
Audit log90 days, then automatically purged
Billing recordsAs required by Stripe and UK financial regulations (typically 7 years)

Your rights under UK GDPR

You have the right to:

  • Accessask us what personal data we hold about you
  • Rectificationask us to correct inaccurate data
  • Erasureask us to delete your data ("right to be forgotten")
  • Portabilityask for a copy of your data in a machine-readable format
  • Restrictionask us to stop processing your data in certain circumstances
  • Objectobject to processing based on legitimate interests

To exercise any of these rights, email privacy@hackshell.io. We will respond within 30 days.

If you are unhappy with how we have handled your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

Cookies

HackShell uses only the cookies necessary to keep you logged in. We do not use tracking or advertising cookies. There is no cookie consent banner because there is nothing to consent to.

Security

We take reasonable technical and organisational measures to protect your data, including:

  • Encryption of credentials at rest (AES-256-GCM)
  • HTTPS for all connections
  • Row-level security on all database tables
  • Access controls limiting who can query what

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the ICO as required by UK GDPR.

Changes to this policy

If we make significant changes to this policy, we will notify you by email before the changes take effect. The “last updated” date at the top of this page will always reflect the current version.

Contact

For privacy questions, data requests, or concerns:

privacy@hackshell.io