Last updated: June 27, 2026 VulnEye ("we", "our", or "the app") is a security research reference tool for browsing Common Vulnerabilities and Exposures (CVEs). This policy explains what data we collect, how we use it, and your rights. We follow the spirit of Apple's privacy guidelines and the Saudi Personal Data Protection Law (PDPL). ⸻ 1. Information We Collect 1.1 Anonymous User Identifier On first launch, the app signs you in anonymously and silently. No phone number, email, name, or any personally identifiable information is collected. We generate: • Anonymous user ID (UID) — a random opaque identifier linked only to your device. Not tied to your identity in any way. This UID is used solely to: • Sync your saved CVEs across your devices • Deliver push notifications you have opted into 1.2 Locally Stored Data The following data stays on your device only: • CVE viewing history (cache) • App preferences (language, theme) 1.3 Notification Token (Optional) If you enable vulnerability alerts: • Anonymous push notification token — used solely to deliver push notifications for vulnerabilities matching your chosen filters. 1.4 Saved CVEs The IDs of CVEs you save and any folders you create to organize them are stored under your anonymous UID. ⸻ 2. What We Do NOT Collect We do not collect: • Real name, phone number, email, or postal address • Precise location or GPS data • Contacts, photos, calendar, or other device content • Health, financial, or biometric data • Analytics or behavioral tracking data • Advertising identifiers (IDFA) • Browsing history outside the app ⸻ 3. How We Use Your Information • Anonymous UID → Identify your saved CVEs and notification preferences • Notification token → Deliver push notifications for chosen severities/products • Saved CVE IDs & folders → Sync your list across your devices We do not sell, rent, or share your data with third parties for advertising or profiling. ⸻ 4. Third-Party Services VulnEye relies on trusted cloud infrastructure to store your saved CVEs and deliver notifications. All processing is limited to the purposes described in this policy. Apple Push Notification service (APNs) Used for delivering iOS push notifications. Apple's privacy practices apply: https://www.apple.com/legal/privacy/ ⸻ 5. Data Storage and Security • Cloud data is hosted on secure multi-region infrastructure. • All network traffic uses HTTPS (TLS 1.2+). • Security rules restrict cloud data so only the authenticated owner can read their own saved CVEs and preferences. • API keys and secrets are kept on our servers — never bundled with the app. ⸻ 6. Data Retention • Anonymous UID & account data → Until you delete your account or uninstall the app • Saved CVE IDs & folders → Until you remove them or delete your account • Notification token → Until you disable alerts or uninstall the app • Local cache → Until you clear it or uninstall the app ⸻ 7. Your Rights You have the following rights at any time, free of charge: 7.1 Delete Your Account Settings → Account → Delete Account. This permanently removes: • Your anonymous user record • All saved CVEs and folders associated with your account • All cloud data linked to your user ID Deletion is immediate and irreversible. 7.2 Disable Notifications Settings → Vulnerability Alerts → Toggle off. Stops all push notifications from VulnEye. 7.3 Access Your Data Email us to request a copy of your data: xhlaxz@gmail.com 7.4 Reset Your Session Uninstalling and reinstalling the app generates a new anonymous UID, effectively resetting your identity in our system. ⸻ 8. Children's Privacy VulnEye is not directed at children under 13. We do not knowingly collect personal information from anyone under 13. If you believe a child has provided us with personal information, please contact us and we will delete it. ⸻ 9. International Data Transfers Our cloud infrastructure may store data on servers located outside Saudi Arabia. By using the app, you consent to your data being processed in jurisdictions where our infrastructure providers operate, in compliance with applicable data protection laws. ⸻ 10. Lawful Basis (PDPL / GDPR) We process your data on the following lawful bases: • Legitimate interest — to provide the requested security research functionality • Consent — when you enable push notifications • Contract — to deliver the features the app offers ⸻ 11. Security Research Disclaimer VulnEye is intended for authorized security research and defensive purposes only. Vulnerability information shown in the app — including mitigation reports and references to public Proof-of-Concept (PoC) materials — comes from publicly available sources. Users are responsible for following responsible disclosure practices and applicable laws in their jurisdiction. ⸻ 12. Changes to This Policy We may update this policy from time to time. The "Last updated" date at the top reflects the most recent change. Significant changes will be communicated through the app. ⸻ 13. Contact For any privacy-related questions or requests: Email: xhlaxz@gmail.com Built with ❤️ from Saudi Arabia 🇸🇦 ⸻ © 2026 VulnEye. All rights reserved.