Editing
Privacy concerns and data handling at Hack Club
Jump to navigation
Jump to search
Warning:
You are not logged in. Your IP address will be publicly visible if you make any edits. If you
log in
or
create an account
, your edits will be attributed to your username, along with other benefits.
Anti-spam check. Do
not
fill this in!
Hack Club has faced ongoing community scrutiny and external criticism regarding its data privacy practices, compliance with regulations, and the security of its systems. These concerns center on the collection and retention of personal data, particularly from minors, the security of its digital infrastructure, and its adherence to data protection laws like the General Data Protection Regulation (GDPR). == Debates on Data Practices == Internal discussions within the Hack Club Slack have highlighted privacy concerns. Community members have repeatedly questioned GDPR compliance, citing the lack of a formal privacy policy for an extended period and the indefinite retention of government-issued identification documents used for YSWS verification. In response, staff members acknowledged the complexity of GDPR for an organization of Hack Club's structure and the challenges of verifying the identities of international high schoolers at scale. They stated that a privacy policy was being developed and that IDs were set to be automatically deleted after 90 days, though this was debated as a balance between privacy and the "legitimate interest" of preventing fraud. Further concerns were raised about marketing practices, with users noting that signing up for programs like HCB automatically enrolled them in organizational newsletters, a practice that critics argued should be opt-in rather than opt-out under regulations like PECR and CAN-SPAM. Staff acknowledged the issue and pointed to functional unsubscribe links in marketing emails. == Security Incidents == The internal debates were compounded by a series of public incidents documented in external blog posts. In July 2025, a former member of Hack Club disclosed multiple unprotected API endpoints across Hack Club programs. One endpoint in the Neighbourhood program allegedly exposed participants' full legal names using only their Slack ID, without any authentication. Internal communications provided by the researcher suggested this lack of protection was an intentional design decision by a developer, despite being warned by another team member that it constituted a GDPR breach. Subsequently, in September 2025, a separate incident occurred where a developer committed a log file containing three minors' full names, email addresses, home addresses, dates of birth, and phone numbers to a public repository. The response from Hack Club was described as attempting to overwrite the data and later making the repository private, but the data reportedly persisted in forks and web archives. The former member characterized this as a pattern of "gross, willful negligence" rather than an isolated error. A third area of concern involved "Orpheus Engine," an internal analytics pipeline. According to a technical analysis, this system was used to profile grant applicants by scraping their activity across various social platforms and using third-party APIs to infer demographic data like gender. Critics argued this constituted extensive profiling without opt-in or transparency. == Governance and Response == The response to these disclosures became a point of contention. The researcher reported that initial contact with Hack Club staff, some of whom were teenage interns, yielded legally inaccurate responses, including the claim that GDPR did not apply to the US-based organization and that advice had been sourced from ChatGPT. Leadership was criticized for being dismissive of formal breach notifications. Furthermore, the dedicated GDPR contact email (gdpr@hackclub.com) was taken offline shortly after the issues were raised publicly, with operations staff later explaining it was a temporary solution managed by a part-time contributor. Hack Club's leadership acknowledged the need for improved policies. The COO stated in a Slack message that the organization was in the process of assembling its policies for publication. In internal discussions, staff expressed a philosophy that the need for formal policy documents was a sign of underlying issues but agreed that clarity for users was necessary.
Summary:
Please note that all contributions to Hack Club Wiki may be edited, altered, or removed by other contributors. If you do not want your writing to be edited mercilessly, then do not submit it here.
You are also promising us that you wrote this yourself, or copied it from a public domain or similar free resource (see
Hack Club Wiki:Copyrights
for details).
Do not submit copyrighted work without permission!
Cancel
Editing help
(opens in new window)
Navigation menu
Personal tools
Not logged in
Talk
Contributions
Create account
Log in
associated-pages
Page
Discussion
English
Views
Read
Edit
View history
More
Search
Navigation
Main page
Recent changes
Random page
Help about MediaWiki
Special pages
Tools
What links here
Related changes
Page information