← H3x Kitty Inc.
Privacy Policy
Effective Date: August 16, 2025
Last Updated: August 23, 2025
H3x Kitty, Inc. ("we," "us," or "our") operates the website h3x-kitty.com and provides the H3x Kitty security analysis tool ("Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our Service.
Information We Collect
Personal Information
- Email Address: We collect your email address when you purchase a license to send you your license key and provide customer support.
- Payment Information: Payment processing is handled by Stripe. We store transaction details but not your full payment card information.
Usage Analytics
H3x Kitty collects minimal usage analytics from the CLI tool based on legitimate business interests:
- Tool execution events (for product improvement and support)
- License type (free/pro) for business metrics
- Count of security issues found (to measure tool effectiveness)
- Timestamps of tool usage
We do not collect:
- Your source code or any code details
- Specific vulnerability information or issue details
- Personal identifiers beyond what's necessary for the service
- Detailed system information
How We Use Your Information
We use the information we collect to:
- Deliver license keys to your email address
- Process payments through Stripe
- Provide customer support
- Improve our security analysis tool
- Understand product usage and effectiveness
- Comply with legal obligations
Legal Basis for Processing
We process your personal information based on:
- Contract: To fulfill paid license purchases and deliver license keys
- Legitimate Interest: For product improvement, analytics, business operations, and providing the free version of our service
- Consent: Where explicitly provided by you
Data Sharing and Disclosure
We share your information only in the following circumstances:
- Payment Processing: With Stripe to process payments
- Analytics: Anonymized usage data with Simple Analytics for product improvement
- Legal Requirements: When required by law or to protect our rights
We do not sell, rent, or share your personal information with third parties for marketing purposes.
Data Security
We implement appropriate technical and organizational measures to protect your personal information:
- Data encryption in transit and at rest
- Secure database hosting with Heroku
- Regular security updates and monitoring
- Access controls and authentication
Data Retention
We retain your personal information for:
- Transaction data and email addresses: 2 years from the date of purchase
- Usage analytics: 1 year from collection
- Legal obligations: As required by applicable law
After the retention period, we securely delete your personal information from our systems.
Your Rights
Depending on your location, you may have the following rights:
- Access: Request information about the personal data we hold about you
- Rectification: Request correction of inaccurate personal data
- Erasure: Request deletion of your personal data
- Portability: Request your data in a machine-readable format
- Object: Object to processing based on legitimate interests
- Opt-out: Disable usage analytics by setting the
ENABLE_METRICS environment variable to false
To exercise these rights, contact us at privacy@h3x-kitty.com. We will respond within 30 days and may need to verify your identity before processing your request.
International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place for any international transfers.
Children's Privacy
Our Service is not intended for individuals under 16 years of age. We do not knowingly collect personal information from children under 16.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last Updated" date.
California Privacy Rights (CCPA/CPRA)
Do We Sell or Share Personal Information?
We do not sell your personal information for monetary value. However, our usage analytics collection may constitute "sharing" under California law as defined by the CPRA. We share anonymous usage analytics with Simple Analytics for product improvement purposes.
If you are a California resident and wish to opt out of this data sharing, set the ENABLE_METRICS environment variable to false in your configuration. Since the tool runs on your infrastructure, this is the only method to disable analytics collection.
Your California Rights
If you are a California resident, you have the following rights:
- Right to Know: Request disclosure of personal information we collect, use, disclose, and sell
- Right to Delete: Request deletion of personal information we have collected
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt-Out: Opt out of the sale or sharing of your personal information
- Right to Limit: Limit use and disclosure of sensitive personal information
How to Exercise Your Rights
- Email us: privacy@h3x-kitty.com (for data access, deletion, correction requests)
- Opt-out of Analytics: Set
ENABLE_METRICS: false in your configuration
- We will respond to your request within 30 days
We do not discriminate against consumers who exercise their California privacy rights.
Contact Information
If you have any questions about this Privacy Policy or our privacy practices, please contact us at:
This Privacy Policy complies with the EU General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).