BountyOS Privacy Policy

Privacy Policy

Last updated: 12 September 2026

The short version

BountyOS has no account system and no backend. There is no server operated by the developer, so there is nothing for us to collect, store or sell. Your credentials and your report data stay on your device, and leave it only to reach the services you explicitly connected.

1. What we collect

Nothing. BountyOS does not include analytics, crash reporting, advertising or any other telemetry. The developer of this app does not receive, store or have access to any of your data.

2. What is stored on your device

The following remains in the app's private storage and is never uploaded to the developer:

Uninstalling the app, or clearing its data, removes all of the above.

3. What leaves your device

BountyOS contacts external services only to perform actions you requested. Every connection uses HTTPS.

Destination What is sent Why
HackerOne, Bugcrowd, Intigriti, YesWeHack The credentials you supplied for that platform, and the identifiers of the reports you request To retrieve your own reports, programs and activity
ExploitDB (public archive) No personal data To display exploit entries you chose to browse
MITRE ATT&CK (public dataset) No personal data To download the tactic and technique matrix
AI service, when you use the in-app assistant The message you typed, using the credentials you configured To return a response in the assistant panel

No data is sent to the developer, to advertisers, or to any party not listed above.

4. Permissions

5. Third-party services

Your use of HackerOne, Bugcrowd, Intigriti, YesWeHack, ExploitDB, MITRE ATT&CK and any AI provider you configure is governed by their own terms of service and privacy policies. This policy covers the BountyOS app only.

6. Data retention and deletion

Because all data is stored on your device, you are in full control of it. To delete everything, uninstall the app or clear its storage from Android settings. Revoking an API token in the relevant platform's account settings immediately invalidates the credential BountyOS holds.

7. Children

BountyOS is intended for security professionals and is not directed at children. It is not designed for, and should not be used by, anyone under 18.

8. Changes to this policy

If this policy changes, the revised version will be published at this URL with an updated date. Material changes will also be noted in the app's release notes.

9. Contact

Questions about this policy: johnmelodymel@qq.com