Privacy Policy
Last updated: 2026-07-26 · Draft — pending final legal review
1. Who we are
VigilForge (vigilforge.io) is a cybersecurity education platform. The operating entity's legal status is currently being finalized — this section will be updated with a registered business name and address once that is settled.
2. What we collect
| Data | Why | Retention |
|---|---|---|
| Email, username, password (hashed) | Account creation and authentication | Until account deletion |
| Avatar, bio, social links (optional) | Public profile display | Until account deletion |
| Learning progress, quiz scores | Core product functionality | Until account deletion |
| IP address, browser user-agent | Security (login/session tracking, abuse prevention) | Session records: deleted on logout, or automatically purged once the underlying session has expired (currently 8 hours of inactivity), whichever comes first. Security audit log: 12 months, then automatically deleted |
| MFA/passkey credentials | Account security | Until removed or account deleted |
| Analytics (Google Analytics 4 / GTM) | Understand aggregate site usage | Only loaded after you accept the cookie/analytics consent banner |
Backups: account and profile data deleted from the live database (per the table above) may still exist in encrypted backups for up to 30 days afterward, since backups are retained on a rolling 7-30 day cycle for disaster-recovery purposes, not indefinitely.
3. Who we share it with
- Hetzner — hosting infrastructure (exact datacenter region to be confirmed).
- Cloudflare — CDN/proxy/TLS termination and DDoS protection; sees all traffic in transit.
- Google (Analytics 4 / Tag Manager) — aggregate usage analytics, only after consent.
- Gmail SMTP — transactional email delivery (verification, password reset, account deletion confirmation).
Some of these providers may process data outside Morocco. Where this applies, it will be documented here alongside the relevant legal basis once the entity/CNDP status above is resolved.
4. Your rights
- Access & rectification — edit your profile directly, or contact us for data we hold that isn't editable in-app.
- Erasure — delete your account and personal data yourself at any time from account settings. Security audit records are retained for a limited period afterward for fraud/abuse prevention (see table above) but are no longer linked to an active account.
- Objection — decline analytics cookies via the consent banner at any time.
5. Contact
Questions about this policy or your data: [email protected].