Legal

Privacy Policy

Last updated: 08/10/2026

1. Who we are

The controller for the processing described here is Lars Hampe, see theimprint for the address (hereinafter "we", "us" or "boring.tools"). You can reach us about data protection atprivacy@boring.tools.

2. What data we process

Vulnerability data (OSV, CISA KEV, ENISA EUVD, EPSS) comes from public sources and contains no personal data.

3. Why we process it

We do not sell your data and do not use it for advertising.

4. Legal basis (GDPR)

5. Service providers

6. Retention

We keep your data for as long as your account or organization exists. Deleting a project removes its SBOMs, findings and triage data right away. After an account is deleted we delete the remaining personal data within 30 days, unless the law requires us to keep it longer. Website usage data is kept for as long as we need it to understand how the website is used and deleted once it is no longer needed for that purpose. Application usage data is deleted together with your account at the latest.

7. Your rights

Under the GDPR you have the right to:

Write to privacy@boring.tools. Organizations that need a data processing agreement (Art. 28 GDPR) can request one at the same address.

8. Cookies

boring.tools uses only strictly necessary cookies for your session. The website analytics described in section 5 work without cookies and without storing anything on your device; the application analytics also set no cookies. There is no advertising and no tracking across other websites.

9. Changes

We update this policy when the service changes. Material changes are announced by email or in the application.