Privacy Policy
Last Updated: June 28, 2026
This Privacy Policy describes how Silovik Engine ("Company," "we," "us," or "our") collects, uses, stores, and protects information in connection with the Silovik anti-bot detection and traffic filtering platform (the "Service").
1. INFORMATION WE COLLECT
1.1 Account Information (You Provide)
- Username and email address (for account creation and communication)
- Hashed password (irreversibly hashed — we never store plaintext passwords)
- API key (for Service authentication)
- Wallet balance and transaction records
- Campaign configurations (target URLs, decoy URLs, filtering rules)
1.2 Visitor Traffic Data (Processed by the Service)
When a visitor is routed through the Service, we temporarily process:
- IP address (used for GeoIP lookup and threat scoring)
- User-Agent string (browser identification)
- HTTP Referer header (traffic source identification)
- Browser fingerprint data (canvas hash, WebGL parameters, font list, audio fingerprint, mouse interaction patterns)
- TLS/SSL connection parameters (cipher suite, protocol version)
- Timestamp of request
1.3 Automatically Collected Information
- Server logs (IP, timestamp, requested URL, HTTP status code)
- Dashboard usage analytics (page views, feature usage)
- Session cookies for dashboard authentication
2. HOW WE USE INFORMATION
- 2.1 Bot Detection: Visitor traffic data is processed in real-time to determine whether the visitor is a human or automated bot. This is the core function of the Service.
- 2.2 Service Operation: Account information is used to authenticate you, process payments, and provide the dashboard interface.
- 2.3 Threat Intelligence: Aggregated and anonymized threat data (IP reputation scores, ASN statistics, fingerprint patterns) may be shared across our customer network to improve detection for all users. Individual visitor data is NOT shared — only statistical patterns.
- 2.4 Improvement: Aggregated, de-identified data may be used to improve the Service's detection algorithms.
3. DATA RETENTION
- 3.1 Traffic logs: Visitor IP addresses, user agents, and detection results are retained for a maximum of thirty (30) days, after which they are automatically purged, unless required longer by law enforcement request.
- 3.2 Account data: Retained for the duration of your account plus a reasonable period for legal compliance.
- 3.3 Threat intelligence: Aggregated, anonymized threat scores are retained indefinitely to continuously improve the detection engine.
- 3.4 Fingerprint hashes: Cryptographic hashes of browser fingerprints (not the raw fingerprint data) are stored for repeat visitor identification. These cannot be reversed to identify individual persons.
4. DATA SHARING & DISCLOSURE
We do NOT sell, rent, or trade your personal information or your visitors' data to third parties.
We may disclose information only:
- 4.1 To comply with valid legal process (subpoena, court order, warrant);
- 4.2 To protect our rights, property, or safety, or that of our users or the public;
- 4.3 To enforce our Terms of Service;
- 4.4 To detect, prevent, or address fraud, security, or technical issues;
- 4.5 With your explicit consent.
5. YOUR RESPONSIBILITIES
YOU ARE THE DATA CONTROLLER for your visitors. We are the DATA PROCESSOR.
- 5.1 You are responsible for obtaining appropriate consent from your website visitors for the collection and processing of their data through the Service, as required by applicable privacy laws (GDPR, CCPA, etc.).
- 5.2 You must post a privacy policy on your own website that discloses your use of third-party bot detection services and the types of data collected.
- 5.3 You represent that your collection and use of visitor data complies with all applicable privacy laws.
6. DATA SECURITY
- 6.1 We implement industry-standard technical and organizational measures to protect data against unauthorized access, alteration, disclosure, or destruction.
- 6.2 All data transmission between your server and our API is encrypted via TLS 1.2 or higher.
- 6.3 Passwords are hashed using bcrypt. API keys are stored encrypted at rest.
- 6.4 No security system is impenetrable. We cannot guarantee absolute security of data transmitted to or stored on the Service.
7. THIRD-PARTY SERVICES
- 7.1 The Service uses ip-api.com for GeoIP lookups. Their privacy policy is available at ip-api.com/docs/legal.
- 7.2 The dashboard may load fonts and icons from Google Fonts and Font Awesome CDNs.
- 7.3 We are not responsible for the privacy practices of third-party services integrated into the Service.
8. COOKIES
- 8.1 Dashboard: We use a session cookie to maintain your authenticated dashboard session. This cookie is essential for the Service to function.
- 8.2 Visitor Script: The client-side detection script sets a temporary cookie (
slvk_hydra_v2) on visitors' browsers containing an encrypted fingerprint payload. This cookie expires after two minutes and is used solely for bot detection.
- 8.3 We do not use tracking cookies, advertising cookies, or analytics cookies on the Service.
9. CHILDREN'S PRIVACY
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children.
10. INTERNATIONAL DATA TRANSFERS
If you access the Service from outside the country where our servers are located, your information may be transferred across international borders. By using the Service, you consent to such transfers.
11. YOUR RIGHTS
Depending on your jurisdiction, you may have rights to:
- Access the personal data we hold about you
- Request correction or deletion of your data
- Object to or restrict processing of your data
- Data portability
To exercise these rights, contact us at the address below. We will respond within the timeframe required by applicable law.
12. CONTACT
For privacy-related inquiries:
Email: privacy@your-domain.com
Subject: Privacy Request — [Your Username]
13. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. Material changes will be communicated via email or dashboard notice. Continued use after changes become effective constitutes acceptance.