Privacy Policy

Last updated: 2026-09-21 · Effective: 2026-09-10

1. Introduction

This Privacy Policy explains how RealExploit, operated by KeyStone Labs, collects, uses and protects personal data. The Operator is responsible for RealExploit account data. Contact privacy@realexploit.io for privacy requests.

By using the Service, you consent to the data practices described in this Policy. If you do not agree, please do not use the Service.

2. Data We Collect

Account data.

Service-usage data.

Bulk-analysis data.

Patch-tracking data (Pro, Team and Enterprise).

When you use patch tracking, we store the asset identifiers, hostnames, sites, owner or assignee labels, criticality, exposure flags, CVE associations and dates you submit, plus patch states, evidence notes, saved dashboard filters and authenticated actor identifiers. This data supports workspace prioritization and historical tracking. Saved executive reports retain a fixed copy of the selected data and author notes. Reports are private to their author in the current workspace and are erased when the author deletes their account or the owning organization is dissolved through account deletion. Hostnames and evidence notes are not sent to threat-intelligence providers. Use team labels and ticket references where possible; do not upload credentials or unrelated sensitive data.

Patch inventories and their audit history remain in the primary database while their workspace exists. Deleting the workspace removes its inventory, dashboards, import metadata and history. If an actor account is deleted while the workspace remains, the actor reference is cleared and the workspace history is retained. Temporary analysis rows and normalized import payloads are removed when an import completes or fails. These rules are separate from Bulk CSV export retention; backup retention follows the existing backup policy.

Historical Telegram activation data.

Customer webhook data.

Billing data. Creem (Armitage Labs OÜ) collects payment details as Merchant of Record. We store provider identifiers, plan, subscription state and the paid access period. Payment notifications can include payer contact and tax information; our audit keeps a digest and processing result rather than the complete notification. We do not collect or store full card numbers, CVVs or banking credentials.

Optional data. Any feedback, support correspondence, or content you voluntarily submit to us via email or the support form.

3. Purpose of Processing

We process the categories above for the following purposes:

4. Cookies and Tracking

The marketing site at realexploit.io sets no cookies. Authentication requests go to api.realexploit.io, which sets a host-only first-party session cookie (a JWT). The cookie is HttpOnly, Secure, and SameSite=Lax. The SPA sends API requests with credentials included; the cookie is not readable by SPA JavaScript and is not sent to app.realexploit.io or the marketing host.

When you select Stay signed in, an active session can renew for up to 30 days from that sign-in. Signing out, changing your password or signing in elsewhere revokes it. Social sign-in uses an additional host-only, HttpOnly transaction cookie that expires after ten minutes, with a single-use server record removed on completion. Browser storage retains only the non-sensitive session preference and selected plan.

We do not use third-party analytics pixels, advertising trackers, session-replay scripts, or behavioral profiling cookies. We do not participate in cross-site advertising networks. Because we set no advertising or analytics cookies, no Cookie Consent banner is required for compliance with EU/UK ePrivacy rules.

Links to Telegram leave our sites. Telegram processes your visit and bot interaction under its own policy; RealExploit does not place a Telegram tracker or widget on the marketing site or application.

5. Third-Party Service Providers

We use the following categories of service providers to operate RealExploit. Access is limited to the data needed for their function. Services that you choose directly are identified below:

Customer-directed webhook recipients are destinations selected and controlled by the customer, not RealExploit subprocessors. When a customer enables an endpoint, RealExploit sends the configured public CVE event and delivery headers to that recipient. The customer is responsible for its recipient, access controls, downstream retention, and applicable privacy notices.

We do not sell, rent, or trade personal data to any third party. We may disclose data when legally compelled (subpoena, court order, regulatory request) and will challenge overbroad requests where appropriate.

6. Data Hosting Location

Account, billing-reference, authentication, and job metadata are processed and stored on our primary infrastructure in Frankfurt, Germany (European Union). Static assets and private analysis exports are processed by network and storage services. These providers may process data internationally under their data-processing agreements and applicable transfer safeguards, including Standard Contractual Clauses where applicable. Contact privacy@realexploit.io for information about processors and international transfers relevant to your account.

Telegram interactions are processed separately on Telegram's infrastructure under Telegram's location and transfer practices. The RealExploit fingerprint and activation record remain in our primary database in Frankfurt.

Outbound customer webhooks necessarily transmit a signed event to the destination selected by that customer. Its hosting location and further processing are determined by the customer and destination provider.

7. Data Retention

8. Your Rights

Depending on your jurisdiction of residence, you have rights regarding your personal data. We comply with the following frameworks for residents of the relevant regions.

European Union and United Kingdom (GDPR / UK DPA)

If you are a resident of the European Economic Area or the United Kingdom, you have the following rights under the General Data Protection Regulation and equivalent UK law:

To exercise these rights, contact privacy@realexploit.io. We respond within 30 days; extensions of up to two further months are possible for complex requests, with notice.

California, United States (CCPA / CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act and the California Privacy Rights Act:

To exercise these rights, contact privacy@realexploit.io. Authorized agents may submit requests on your behalf with verifiable written authorization.

Other jurisdictions

Residents of other regions may have additional rights under local data-protection laws — including but not limited to Brazil's Lei Geral de Proteção de Dados (LGPD), Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), and Australia's Privacy Act 1988. Contact privacy@realexploit.io to exercise such rights; we honor reasonable requests in accordance with applicable local law.

9. Data Subject Verification

To protect your privacy and prevent fraudulent requests, we may request verification of your identity before fulfilling rights requests — typically by confirming control of the email address on file. For high-risk requests we may request additional reasonable verification.

10. Children's Privacy

The Service is not intended for users under 18 years of age. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact privacy@realexploit.io and we will promptly delete it.

11. Security Measures

12. Data Breach Notification

In the event of a personal data breach affecting your data, we will notify affected users without undue delay through the email address on your account and, where applicable, within 72 hours of becoming aware as required by GDPR Article 33. Notifications will include the nature of the breach, the categories of data affected, the likely consequences, and the remedial steps taken or recommended.

13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. For material changes, we will provide at least 30 days' advance notice via email and by posting the updated version on this page with a revised "Last updated" date. Continued use of the Service after the effective date constitutes acceptance.

14. Contact

RealExploit is offered under the KeyStone Labs brand. Use the contacts below for privacy, support and security requests.