CVE Tools

Privacy Policy

Last updated September 21, 2026

Contents 13 clauses

1. Introduction

CVE Tools ("the Service"), operated by Pavel Buchnev ("we", "us", or "our"), respects your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

2. Information We Collect

2.1 Information You Provide

  • Account registration data (email address, name)
  • Authentication data from third-party providers (GitHub, Google, Telegram) when you choose to sign in via OAuth
  • Communications you send to us (support inquiries, feedback)

2.2 Information Collected Automatically

  • Usage data (pages visited, features used, search queries)
  • Device and browser information (browser type, operating system)
  • IP address and approximate location
  • How you first reached us — the referring site, the page you landed on, and any campaign tags in the link you followed
  • Cookies and similar tracking technologies

2.3 Information from Third Parties

  • Profile information from OAuth providers (GitHub username, avatar, email)
  • Payment information processed by Paddle (we do not store credit card details)

3. How We Use Your Information

We use the collected information to:

  • Provide, maintain, and improve the Service
  • Create and manage your account
  • Process payments and subscriptions (via Paddle)
  • Send transactional communications (account notifications, security alerts)
  • Analyze usage patterns to improve user experience
  • Detect, prevent, and address technical issues or abuse
  • Comply with legal obligations

4. Data Sharing and Disclosure

We do not sell your personal information. We may share your data with:

  • Paddle — our Merchant of Record for payment processing. Paddle's privacy policy is available at paddle.com/legal/privacy
  • Analytics providers — to understand Service usage: Google Analytics 4 (Google) and Clarity (Microsoft). Our own first-party analytics stay on our servers and are not shared with anyone
  • Law enforcement — when required by law or to protect our rights

5. Cookies and Tracking

These are the cookies the Service sets. We list every one of them, including how long it lasts and what it is for, so you can decide what you are comfortable with.

CookiePurposeLifetimeSet by
cve_auth_tokenKeeps you signed in. Without it the Service cannot recognise your account.30 daysSet by Us
sidGroups the actions of a single visit so we can count visits rather than clicks. Holds a random id, not an identity.30 minutesSet by Us
cve_ftRecords how you first found us — the referring site, the page you landed on and any campaign tags in the link. It lets us see which articles and channels are worth writing, since people often read first and sign up days later. The cookie itself holds no identifier for you; if you create an account, what it recorded is saved to your profile, so we can tell which article brought you. It is never used for advertising or profiling, and is never shared.90 daysSet by Us
cve_consentRemembers whether you accepted or declined analytics cookies, so we do not ask again on every page.1 yearSet by Us
_ga, _ga_*Google Analytics 4 — aggregate usage statistics.Up to 2 yearsSet by Google
_clck, _clskMicrosoft Clarity — aggregate usage statistics and interaction heatmaps.Up to 1 yearSet by Microsoft

You choose. On your first visit a bar at the bottom of the page asks whether analytics cookies are fine. If you decline, none of them are used: Google Analytics and Clarity are never loaded, our own analytics stop recording, and cve_ft is deleted. Nothing about the Service works differently either way. To change your mind later, use the Cookies link in the footer — we do not leave a floating button on the page.

Only the first one is strictly necessary. The rest exist so we can understand how the Service is used and which of our articles actually help people. You can block or delete any of them through your browser settings, and the Service will keep working — you will simply stay signed out if you block cve_auth_token.

To opt out of Google Analytics across all sites, Google provides a browser add-on. Most browsers also honour Global Privacy Control.

6. Data Retention

We retain your personal data for as long as your account is active or as needed to provide the Service. Upon account deletion, we will remove your personal data within 30 days, except where retention is required by law or for legitimate business purposes (e.g., fraud prevention, legal compliance).

7. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including encryption of data in transit (TLS), secure authentication mechanisms, and access controls. However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.

8. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your personal data
  • Object to or restrict processing of your data
  • Request data portability
  • Withdraw consent at any time (where processing is based on consent)

To exercise these rights, contact us at butschster@gmail.com.

9. International Data Transfers

Your data may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for any such transfers in compliance with applicable data protection laws.

10. Children's Privacy

The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.

11. Reusing Our Content

This Privacy Policy covers personal data only. Reuse of our content — including reposting or republishing our blog and editorial articles, in whole or in part — is governed by our Terms and Conditions (section 5, Intellectual Property), which require clear attribution to CVE Tools and a visible, followable link back to the original article on cve.tools.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via the Service or by email. Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.

13. Contact

If you have questions or concerns about this Privacy Policy, contact us at butschster@gmail.com.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store