Privacy Policy

Effective date: 14 July 2026

This policy explains what data novahunting.ai (the "Site") collects, how it is used, and the choices you have. The Site is operated by SecurityBreak Pty Ltd ("SecurityBreak", "we", "us"). The short version: there are no accounts and no advertising or analytics trackers, but content you submit to the free tools is retained for security research — so don't submit anything personal or confidential.

1. What we collect

When you use the rule playground, we store for each scan:

  • the detection rules and the prompt you submitted (raw text),
  • the scan results, rule count and processing latency,
  • a salted one-way hash of your IP address (we do not store the IP itself), your country code, and a timestamp,
  • any feedback verdict ("correct" / "incorrect") you give on a result.

When you use the skill scanner, we store for each scan:

  • the skill content you submitted or referenced (repository URL, uploaded file name, skill name, description and scanned file contents),
  • the verdict and full scan results,
  • the same salted IP hash, country code and timestamps as above.

Our infrastructure provider (Cloudflare) additionally processes standard request data — IP address, user agent, request logs — to serve the Site, enforce rate limits and run Turnstile bot protection.

2. What we do not collect

  • No user accounts, names or email addresses — the tools work anonymously.
  • No advertising cookies and no third-party analytics trackers.
  • No raw IP addresses in our own database — only salted hashes.

3. How we use the data

Submitted rules, prompts, skills and results are used for security research: studying adversarial prompt techniques, improving NOVA detection quality, and publishing aggregate insights. IP hashes and country codes are used for abuse prevention, rate limiting and coarse usage statistics. We do not sell your data.

4. Public information

Skill scanner results are published by default. Scanned skills — including their name, description, source and verdict — appear in a public feed on the Site with permanent links. You can opt out per scan with the "Private scan" option: a private scan is not listed in the feed, but it is still stored and retained for research (see section 3) and remains reachable by anyone who has its result link. If the same skill is later scanned publicly by anyone, it appears in the feed. Playground submissions are not published, but treat anything you submit as potentially reviewable by our researchers.

5. Third-party services

The Site loads services from these providers, each governed by its own privacy policy:

  • Cloudflare — hosting, CDN, Turnstile bot protection and the D1 database where scan data is stored.
  • Google Fonts — font delivery (your browser requests font files from Google's servers).
  • asciinema — the terminal demo player embedded on the home page.
  • GitHub — fetched server-side when you scan a skill by repository URL.

6. Retention

Scan data is retained for as long as it remains useful for research. Cloudflare's operational logs are retained per Cloudflare's own policies.

7. Your rights

Depending on where you live (including under the GDPR and the Australian Privacy Principles), you may have rights to access, correct or delete personal data. Note that scan data is stored pseudonymously — we generally cannot link a stored scan back to you unless you provide the specific content or permalink in question. To make a request, contact SecurityBreak via securitybreak.io.

8. Do not submit personal data

The tools are built for testing detection rules against adversarial content, not for processing real personal or confidential information. Please redact or anonymize anything sensitive before submitting it.

9. Changes

We may update this policy from time to time; the effective date above reflects the latest revision. Material changes will be visible on this page.