Last updated 2026-10-09. This page describes what the site stores and why, in plain terms.
AI Sec Watch has no user accounts and does not collect email addresses. Every page, feed and API endpoint is public and works without signing in. An earlier email newsletter has been discontinued and its subscriber records removed.
The site counts page views itself, without cookies and without any third-party analytics service. Each view stores the date, the page path, the referring website's host name (for example news.ycombinator.com) and a visitor hash. The hash is computed from a server secret, the date, the client address and the browser's user-agent string, so it changes every day: the site can count distinct visitors per day but cannot recognize a returning visitor on a later day or recover the address. Requests from automated clients, and browsers that send Do Not Track or Global Privacy Control signals, are not counted. Raw page views are kept for at most 13 months.
Records on this site are collected from public sources (vulnerability databases, advisories, research repositories and news outlets). Each record links to its source. Summaries and labels are generated by an automated classifier and may contain errors; use the feedback button on an item to report one.
The site sets a cookie only for the administrator login. Your theme preference is kept in your browser's local storage and never sent to the server. Files you send to Stack Check are processed in memory and not stored; with the vulnerability lookup on, their package names and versions are sent to OSV (osv.dev) to find matching advisories.
Contact details are on the maintainer's site linked in the footer. Licenses for the dataset, the live service and the code are on the terms page; citation details are on the dataset page.