What is covered
This notice covers DJames617, NerdDual, and HDJames. DJames617 is mostly public content. NerdDual public tools may process submitted indicators. HDJames stores account, authorization, application, and study-progress data for protected applications.
Account and application data
HDJames stores the information needed to authenticate users, authorize application access, record audit events, and keep application progress. Study applications may keep their own progress stores until central SSO migration is complete.
Security-tool submissions
Do not submit private or sensitive indicators to public tools unless you understand the external API behavior. Some enrichment workflows may query providers such as VirusTotal or GreyNoise, and those providers may retain submitted data under their own terms.
Cookies and sessions
Protected HDJames routes use secure session cookies where HTTPS is available. Session tokens are not placed in URLs and should not appear in logs.
Retention and backups
Operational data is retained only as needed for the application purpose, troubleshooting, security auditing, and recoverability. Backups may retain deleted data for their configured retention period.
Requests
Use the support page for account, access, data export, or deletion requests. Security vulnerabilities should use the responsible disclosure process instead of normal feedback.