Privacy

Last updated 13 August 2026.

The short version

CyberCVE sets no cookies, runs no advertising trackers, and has no accounts to sign into. You can read every page on this site without giving us anything. The only personal data we ever hold is what you deliberately type into the corrections form.

What we collect

If you submit a correction

The corrections form stores what you send:

  • the category of problem, your description, and any evidence link you provide;
  • the CVE ID and the page you reported from, so the report can be acted on;
  • your email address, only if you choose to give one. It is used to follow up on your report and nothing else. It is never displayed on the site, never included in the public issue that may be opened to track a fix, and never added to a mailing list;
  • your browser's user-agent string, and a salted hash of your IP address — not the address itself. The hash exists so we can tell whether one source is flooding the form. It cannot be reversed to an IP address, and rotating the salt makes every stored hash meaningless.

Submissions are protected by Cloudflare Turnstile, which checks that you are a person rather than a script. Turnstile is Cloudflare's alternative to a CAPTCHA and does not track you across sites.

If you just read the site

We use Cloudflare Web Analytics for aggregate traffic counts — which pages are read, roughly where readers come from. It sets no cookies, builds no profile, and uses no cross-site identifier, which is precisely why it was chosen: it means this site needs no consent banner and there is nothing to opt out of.

Cloudflare also serves this site and keeps short-lived operational logs, as any host does. See Cloudflare's own privacy documentation for what that involves.

What we never do

  • Sell, rent, or share your data with anyone.
  • Send marketing email. There is no mailing list.
  • Use advertising or cross-site tracking technology.
  • Ask for anything you do not need to give us.

How long we keep it

Corrections are kept while they are useful — an accepted report explains why a mapping looks the way it does. If you gave an email address and would rather we did not keep it, ask and it will be removed from the record while the correction itself stays.

Your data

Ask us and we will tell you what we hold about you, correct it, or delete it. Because the only thing we can link to a person is an email address you typed yourself, in practice this means: write to us from that address and say what you want done.

Contact: contact@cybercve.com

Security reports

For a vulnerability in this site rather than in the data it publishes, see security.txt or write to security@cybercve.com.

Changes

If this policy changes materially, the date above changes with it. The site's source code is public, so the history of this page is public too.