Privacy Policy

Last updated: 2026-07-26 · Draft — pending final legal review

Notice: this policy is published in draft form. The legal entity operating VigilForge has not yet been finalized, and no declaration has been filed with the CNDP (Morocco's data protection authority) for this processing. Both points are being worked on. If you have concerns about how your data is handled in the meantime, contact [email protected].

1. Who we are

VigilForge (vigilforge.io) is a cybersecurity education platform. The operating entity's legal status is currently being finalized — this section will be updated with a registered business name and address once that is settled.

2. What we collect

Data Why Retention
Email, username, password (hashed)Account creation and authenticationUntil account deletion
Avatar, bio, social links (optional)Public profile displayUntil account deletion
Learning progress, quiz scoresCore product functionalityUntil account deletion
IP address, browser user-agentSecurity (login/session tracking, abuse prevention)Session records: deleted on logout, or automatically purged once the underlying session has expired (currently 8 hours of inactivity), whichever comes first. Security audit log: 12 months, then automatically deleted
MFA/passkey credentialsAccount securityUntil removed or account deleted
Analytics (Google Analytics 4 / GTM)Understand aggregate site usageOnly loaded after you accept the cookie/analytics consent banner

Backups: account and profile data deleted from the live database (per the table above) may still exist in encrypted backups for up to 30 days afterward, since backups are retained on a rolling 7-30 day cycle for disaster-recovery purposes, not indefinitely.

3. Who we share it with

  • Hetzner — hosting infrastructure (exact datacenter region to be confirmed).
  • Cloudflare — CDN/proxy/TLS termination and DDoS protection; sees all traffic in transit.
  • Google (Analytics 4 / Tag Manager) — aggregate usage analytics, only after consent.
  • Gmail SMTP — transactional email delivery (verification, password reset, account deletion confirmation).

Some of these providers may process data outside Morocco. Where this applies, it will be documented here alongside the relevant legal basis once the entity/CNDP status above is resolved.

4. Your rights

  • Access & rectification — edit your profile directly, or contact us for data we hold that isn't editable in-app.
  • Erasure — delete your account and personal data yourself at any time from account settings. Security audit records are retained for a limited period afterward for fraud/abuse prevention (see table above) but are no longer linked to an active account.
  • Objection — decline analytics cookies via the consent banner at any time.

5. Contact

Questions about this policy or your data: [email protected].