Privacy Policy

Last updated: April 2026  |  We take your privacy seriously

1 Our Philosophy

ZION OFFSEC is built on the principle of minimal data collection. We believe that privacy is not a feature — it's a fundamental right. We collect only what is strictly necessary to operate the Platform, and we never sell, share, or monetize your personal data.

2 Data We Collect

Account Information:

  • Username (pseudonym accepted and encouraged)
  • Email address (for account recovery only)
  • Hashed password (bcrypt, never stored in plaintext)

Operational Data:

  • Order history (encrypted at rest)
  • Forum posts (public, under your chosen pseudonym)
  • Session tokens (temporary, auto-expire)

3 Data We Do NOT Collect

  • Real names or government IDs
  • IP addresses (not logged by policy)
  • Browser fingerprints or tracking cookies
  • Third-party analytics (no Google Analytics, no trackers)
  • Payment details (handled by cryptocurrency — we never see your wallet)
  • Behavioral data or usage patterns

4 Security Measures

  • All passwords hashed with bcrypt (cost factor 12)
  • CSRF protection on all forms
  • Prepared statements for all database queries (SQL injection prevention)
  • XSS sanitization on all user inputs
  • Secure session management with HttpOnly cookies
  • Regular security audits of our own infrastructure

5 Your Rights

  • Access: View all data we hold about you via your profile settings
  • Rectification: Update your information at any time
  • Deletion: Request complete account deletion — we will purge all data within 48 hours
  • Portability: Export your data in standard formats

6 Law Enforcement

We do not voluntarily share data with any government or law enforcement agency. In the event of a legally binding request, we will notify affected users unless prohibited by law. See our Warrant Canary for current status.

7 Contact

For privacy-related inquiries, contact us via our contact page or send a PGP-encrypted message using our public keys.

 Your privacy is our operational security

We practice what we preach. If we wouldn't trust a service with our own data, we won't build it that way.