Privacy Policy
Last updated: April 2026 | We take your privacy seriously
1 Our Philosophy
ZION OFFSEC is built on the principle of minimal data collection. We believe that privacy is not a feature — it's a fundamental right. We collect only what is strictly necessary to operate the Platform, and we never sell, share, or monetize your personal data.
2 Data We Collect
Account Information:
- ▸ Username (pseudonym accepted and encouraged)
- ▸ Email address (for account recovery only)
- ▸ Hashed password (bcrypt, never stored in plaintext)
Operational Data:
- ▸ Order history (encrypted at rest)
- ▸ Forum posts (public, under your chosen pseudonym)
- ▸ Session tokens (temporary, auto-expire)
3 Data We Do NOT Collect
- ✕ Real names or government IDs
- ✕ IP addresses (not logged by policy)
- ✕ Browser fingerprints or tracking cookies
- ✕ Third-party analytics (no Google Analytics, no trackers)
- ✕ Payment details (handled by cryptocurrency — we never see your wallet)
- ✕ Behavioral data or usage patterns
4 Security Measures
- ▸ All passwords hashed with bcrypt (cost factor 12)
- ▸ CSRF protection on all forms
- ▸ Prepared statements for all database queries (SQL injection prevention)
- ▸ XSS sanitization on all user inputs
- ▸ Secure session management with HttpOnly cookies
- ▸ Regular security audits of our own infrastructure
5 Your Rights
- ▸ Access: View all data we hold about you via your profile settings
- ▸ Rectification: Update your information at any time
- ▸ Deletion: Request complete account deletion — we will purge all data within 48 hours
- ▸ Portability: Export your data in standard formats
6 Law Enforcement
We do not voluntarily share data with any government or law enforcement agency. In the event of a legally binding request, we will notify affected users unless prohibited by law. See our Warrant Canary for current status.
7 Contact
For privacy-related inquiries, contact us via our contact page or send a PGP-encrypted message using our public keys.
Your privacy is our operational security
We practice what we preach. If we wouldn't trust a service with our own data, we won't build it that way.