0xBURGER TEAM // ANDROID APP
Privacy policy.
This policy explains how the 0xBURGER Team Android app and 0xburger.com handle data. Weqet publishes the Android app, and 0xBURGER provides the team content and browser-based CTF challenges.
- Effective
- 21 July 2026
- App package
- com.weqet.zeroxburger
- Contact
- support@0xburger.com
01
What the Android app does
The app is a secure WebView for 0xburger.com. It requests only Android's Internet permission. The native app does not contain advertising or analytics SDKs, does not create accounts, and does not request location, contacts, camera, microphone, or device-file access.
The app stores normal WebView data, such as cookies, cached site resources, language choice, sound preferences, and browser history, on the device. Users can remove this local data by clearing the app's storage or uninstalling it.
02
Data processed by the website
When the app loads the website, hosting and security systems process standard request information such as IP address, browser or WebView user agent, requested URL, request time, and security signals. This is used to deliver the site, diagnose failures, prevent abuse, and keep the service secure.
When a user opens the optional practice challenges, the service may process:
- a randomly generated, pseudonymous challenge-session identifier;
- challenge progress, hints opened, solve status, and attempt timestamps;
- answers or flags submitted for validation; and
- anti-abuse signals when Cloudflare Turnstile is required.
Submitted challenge answers are validated in memory. The challenge database records the result of an attempt, not the answer that was submitted. The service does not use this information for advertising or user profiling.
03
Service providers and sharing
Cloudflare provides website delivery, security, rate limiting, and Turnstile. Supabase and PostgreSQL provide storage for pseudonymous challenge sessions and progress. These providers process data for us under their own security and privacy terms. External links opened from the app are governed by the privacy policy of the destination service.
We do not sell personal data, share it with data brokers, or use it for targeted advertising. We may disclose information when required by law or when reasonably necessary to protect users and the service from fraud, abuse, or security threats.
04
Retention and deletion
- Challenge-attempt records are scheduled for deletion after 30 days.
- Pseudonymous challenge sessions and progress expire after up to 365 days of inactivity.
- Operational and security logs are retained only as needed for delivery, security, troubleshooting, and legal obligations.
- On-device WebView data remains until it is cleared by the user or removed with the app.
The Reset progress control in the challenge area deletes the associated challenge session, progress, and attempts. Users may also email support@0xburger.com with a privacy or deletion question. Because challenge records are pseudonymous, we may need the session to still be available on the user's device to identify them.
05
Security, children, and changes
Website traffic uses HTTPS. Challenge identifiers are stored in a Secure, HttpOnly, SameSite cookie and are stored on the server as a cryptographic hash. No Internet service can guarantee absolute security, but access is restricted and the service uses rate limits and abuse controls.
The service is not designed to collect personal information from children. If you believe a child has provided personal information, contact us so we can investigate and delete it where possible.
We may update this policy when the app, website, providers, or legal requirements change. The effective date at the top identifies the current version.
