Legal
Privacy Policy
Last updated: 08/10/2026
1. Who we are
The controller for the processing described here is Lars Hampe, see theimprint for the address (hereinafter "we", "us" or "boring.tools"). You can reach us about data protection atprivacy@boring.tools.
2. What data we process
- Account data — email address, name, optional profile picture, notification settings
- Organization data — organization name, members and their roles, invitations, the plan and trial of the organization
- Content data — SBOMs you upload, the products, versions and components derived from them, triage decisions, CRA reporting cases and the texts you write in them, and CI metadata you send with an upload (repository, branch, commit, pipeline URL)
- Technical data — IP address, time and path of requests in server logs, kept for 14 days
- Website usage data — on the website (boring.tools, not the application): pages viewed, clicked links and buttons, referrer, browser, operating system, device type and the approximate location derived from the IP address. See section 5 for how we measure this.
- Application usage data — in the application: pages viewed, actions such as creating a product, uploading an SBOM, inviting a member or opening the checkout, and subscription changes (plan, status, amount). These are linked to your user ID, name and email address and to your organization and its plan.
Vulnerability data (OSV, CISA KEV, ENISA EUVD, EPSS) comes from public sources and contains no personal data.
3. Why we process it
- To provide the service: sign-in, monitoring, triage, reporting cases
- To send emails you need: sign-in links, invitations, alerts about actively exploited vulnerabilities and, if enabled, the weekly digest
- To keep the service secure and fix errors
- To understand how the application is used, from sign-up to choosing a plan, so we can improve it
- To meet legal obligations, e.g. tax records
We do not sell your data and do not use it for advertising.
4. Legal basis (GDPR)
- Contract (Art. 6(1)(b)) — providing the service your organization signed up for
- Legitimate interests (Art. 6(1)(f)) — security, error analysis, the weekly digest, which you can turn off in your account, and measuring how the website and the application are used so we can improve them
- Legal obligation (Art. 6(1)(c)) — retention required by tax and commercial law
5. Service providers
- Hosting, storage and email — on infrastructure we operate ourselves, located in Germany.
- Website analytics — we use OpenPanel, an open-source analytics tool that we host ourselves in Germany; no data is passed to OpenPanel's makers or other third parties. OpenPanel sets no cookies. Visits are grouped by an identifier calculated on our server from the IP address and browser details with a salt that changes daily, so visits cannot be linked across days. The IP address itself is not stored. In the application, after you sign in, the same self-hosted OpenPanel receives the application usage data from section 2, linked to your account so we can follow usage across days. You can object to this at any time by writing to us (section 7).
- Polar Software, Inc. (USA) — handles payments as our merchant of record. When you buy a plan, Polar processes your billing details and payment data as its own controller; seePolar's privacy policy. We receive the subscription status, not your payment details.
- OpenAI, L.L.C. (USA) — only if AI triage is switched on for a project. We send vulnerability and component details, the deployment profile you entered for the project, and for report drafts the public facts of the vulnerability. We do not send names or email addresses. Transfer on the basis of [TO FILL: EU-US Data Privacy Framework / standard contractual clauses]; OpenAI does not use API data for training.
6. Retention
We keep your data for as long as your account or organization exists. Deleting a project removes its SBOMs, findings and triage data right away. After an account is deleted we delete the remaining personal data within 30 days, unless the law requires us to keep it longer. Website usage data is kept for as long as we need it to understand how the website is used and deleted once it is no longer needed for that purpose. Application usage data is deleted together with your account at the latest.
7. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you
- have inaccurate data corrected
- have your data deleted
- restrict or object to processing
- receive your data in a portable format
- lodge a complaint with a supervisory authority
Write to privacy@boring.tools. Organizations that need a data processing agreement (Art. 28 GDPR) can request one at the same address.
8. Cookies
boring.tools uses only strictly necessary cookies for your session. The website analytics described in section 5 work without cookies and without storing anything on your device; the application analytics also set no cookies. There is no advertising and no tracking across other websites.
9. Changes
We update this policy when the service changes. Material changes are announced by email or in the application.