★ Mayhem Monkies
Privacy Policy
Last updated: August 4, 2026
Overview
This policy explains what we collect, how we use it, and who we share it with when you use Mayhem Monkies. We collect only what we need to run hunts, bill you, secure the Service, and support you.
What we collect
- Account: your email address and sign-in settings. For authenticator sign-in we store a TOTP secret; for passkeys we store public keys only. We never receive your biometrics or device PIN.
- Hunt inputs: the target URLs, repositories, and code you submit, plus any session cookies, headers, or test credentials you provide for authenticated probing.
- Connected credentials: repository access tokens and read-only cloud credentials you connect, stored encrypted.
- Billing: handled by our payment processor. We receive subscription and payment status; we do not store your full card number.
- Usage and logs: operational logs, request metadata, and diagnostics used to run and secure the Service.
How we use it
To run the hunts you request and deliver findings; to process payments and manage your plan; to provide support; to secure, maintain, and improve the Service; and to comply with legal obligations. We do not sell your personal data, and we do not use your private code to train AI models.
Processing by AI models and subprocessors
To analyze a target, your submitted code, targets, and intermediate findings are processed by automated AI/LLM agents and by third-party subprocessors, which may include: AI model providers (to run the hunting agents), our payment processor (billing), our email provider (magic links and notifications), and our hosting and edge/CDN providers. These providers process data on our behalf to deliver the Service.
How we protect it
Connected credentials are stored encrypted and used only inside a sandboxed environment with restricted network egress. Read-only cloud credentials are requested where possible. Credentials supplied for a single hunt are purged when the hunt completes, and you can revoke connected credentials at any time from your dashboard.
Retention and your choices
We retain account data while your account is active and hunt artifacts for as long as needed to provide the Service and meet legal or security obligations, after which they are deleted or de-identified. You may request access to or deletion of your personal data, and you may delete connected credentials and revoke sessions yourself. To make a request, contact us below.
Browser extension
Our optional Chrome extension ("Mayhem Monkies Auth") lets you attach an authenticated session to a hunt without pasting cookies by hand. It reads the cookies for a target site only for the target you choose and only when you start a capture, and sends them to Mayhem Monkies solely to run that hunt against that target. It also stores a Mayhem Monkies API token and endpoint locally in the browser so the popup can list your hunts. It does not track your browsing, and it does not read cookies in the background or for sites you have not selected. You can remove the extension at any time; doing so deletes its locally stored token.
Cookies
We use a single essential, HttpOnly session cookie to keep you signed in. We do not use third-party advertising or cross-site tracking cookies.
Children
The Service is not directed to anyone under 18, and we do not knowingly collect their data.
Changes and contact
We may update this policy; the "last updated" date reflects the current version. Questions or requests:
[email protected].