
Solana Audit Platform
hackhack.ai
Legal
Privacy Policy
Effective Date: April 12, 2026
This Privacy Policy describes how Decoy Research Inc. collects, uses, stores, and shares information in connection with HackHack AI, our Solana audit platform.
1. Scope
This Privacy Policy applies to HackHack AI and related services operated by Decoy Research Inc., a Delaware corporation ("Decoy Research," "HackHack," "we," "us," or "our"). It covers information we collect through the website, audit workspace, communications, and supporting operational systems.
By accessing or using the Service, you acknowledge this Privacy Policy and our Terms of Service.
2. Information We Collect
We may collect the following categories of information:
- Account information: your name, email address, login events, session information, and authentication records.
- Audit submission information: repository URLs, archive files, binaries, documents, patch files, notes, scope details, and related audit metadata.
- Payment information: billing details, quoted amounts, payment status, wallet addresses, on-chain transaction identifiers, and related records.
- Communications: messages you send us and emails we send for authentication, service updates, and support.
- Technical information: IP address, browser and device information, request logs, error logs, and usage data generated when you use the Service.
- Report and workflow information: audit status, generated reports, uploaded files, and operational records needed to manage the engagement.
3. How We Collect Information
We collect information:
- directly from you when you create an account, sign in, submit an audit, or contact us;
- automatically through platform activity, logs, cookies, and similar technologies; and
- from third parties involved in the Service, such as repository hosts, storage providers, email providers, wallet infrastructure, and payment or blockchain systems.
4. How We Use Information
We use information to:
- authenticate users and manage accounts;
- receive, store, process, and analyze audit submissions;
- scope engagements, generate reports, and deliver audit outputs;
- process or verify payments and maintain billing records;
- communicate with you about your account, audits, payments, and updates;
- operate, secure, maintain, and improve the Service;
- investigate abuse, fraud, and security incidents; and
- comply with legal obligations and enforce our agreements.
5. AI and Third-Party Processing
HackHack AI is a hybrid AI-human audit platform. To provide the Service, we may send audit submissions, code, metadata, and related materials to third-party infrastructure and AI providers that help us analyze submissions, support workflow operations, and generate outputs.
We may also use third-party service providers for storage, hosting, report delivery, authentication emails, payment verification, and business operations. Those providers may process information on our behalf under their own contractual and operational terms.
6. How We Share Information
We may share information:
- with service providers and subprocessors that help us operate the Service;
- with counterparties involved in payments, blockchain settlement, repository access, or audit delivery;
- when required by law, legal process, or government request;
- to protect rights, security, safety, or the integrity of the Service; and
- in connection with a merger, financing, acquisition, restructuring, asset sale, or similar corporate transaction.
We do not sell your personal information for money.
7. Data Retention
We retain information for as long as reasonably necessary to provide the Service, maintain business records, support security and fraud prevention, resolve disputes, enforce our agreements, and comply with legal obligations.
Retention periods may vary depending on the type of information, the nature of the audit, whether a report has been delivered, and our legal or operational requirements.
8. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information under our control. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. International Transfers
Your information may be processed in countries other than your own, including where our service providers, infrastructure, and subprocessors operate. By using the Service, you understand that such transfers may occur.
10. Your Choices and Rights
Depending on where you live, you may have rights to request access to, correction of, deletion of, or export of certain personal information, or to object to certain processing. These rights are subject to applicable law and our need to verify your identity.
To make a request, contact us at contact@hackhack.ai.
11. Cookies and Similar Technologies
We may use cookies and similar technologies to keep you signed in, maintain sessions, improve security, and understand how the Service is used. You can control cookies through your browser settings, though some platform functionality may not work properly if cookies are disabled.
12. Children's Privacy
The Service is not directed to children under 18, and we do not knowingly collect personal information from children under 18.
13. Changes to This Policy
We may update this Privacy Policy from time to time. If we do, we will post the updated version on this page and revise the effective date above. Your continued use of the Service after the revised policy takes effect means you accept it.
14. Contact
If you have questions about this Privacy Policy or our privacy practices, contact contact@hackhack.ai.