Privacy concerns and data handling at Hack Club
- Privacy concerns and data handling at Hack Club
Hack Club has faced ongoing community scrutiny and external criticism regarding its data privacy practices, compliance with regulations, and the security of its systems. These concerns center on the collection and retention of personal data, particularly from minors, the security of its digital infrastructure, and its adherence to data protection laws like the General Data Protection Regulation (GDPR).
- Debates on Data Practices
Internal discussions within the Hack Club Slack have highlighted privacy concerns. Community members have repeatedly questioned GDPR compliance, citing the lack of a formal privacy policy for an extended period and the indefinite retention of government-issued identification documents used for YSWS verification. In response, staff members acknowledged the complexity of GDPR for an organization of Hack Club's structure and the challenges of verifying the identities of international high schoolers at scale. They stated that a privacy policy was being developed and that IDs were set to be automatically deleted after 90 days, though this was debated as a balance between privacy and the "legitimate interest" of preventing fraud.
Further concerns were raised about marketing practices, with users noting that signing up for programs like HCB automatically enrolled them in organizational newsletters, a practice that critics argued should be opt-in rather than opt-out under regulations like PECR and CAN-SPAM. Staff acknowledged the issue and pointed to functional unsubscribe links in marketing emails.
- Security Incidents
The internal debates were compounded by a series of public incidents documented in external blog posts. In July 2025, a former member of Hack Club disclosed multiple unprotected API endpoints across Hack Club programs. One endpoint in the Neighbourhood program allegedly exposed participants' full legal names using only their Slack ID, without any authentication. Internal communications provided by the researcher suggested this lack of protection was an intentional design decision by a developer, despite being warned by another team member that it constituted a GDPR breach.
Subsequently, in September 2025, a separate incident occurred where a developer committed a log file containing three minors' full names, email addresses, home addresses, dates of birth, and phone numbers to a public repository. The response from Hack Club was described as attempting to overwrite the data and later making the repository private, but the data reportedly persisted in forks and web archives. The former member characterized this as a pattern of "gross, willful negligence" rather than an isolated error.
A third area of concern involved "Orpheus Engine," an internal analytics pipeline. According to a technical analysis, this system was used to profile grant applicants by scraping their activity across various social platforms and using third-party APIs to infer demographic data like gender. Critics argued this constituted extensive profiling without opt-in or transparency.
- Governance and Response
The response to these disclosures became a point of contention. The researcher reported that initial contact with Hack Club staff, some of whom were teenage interns, yielded legally inaccurate responses, including the claim that GDPR did not apply to the US-based organization and that advice had been sourced from ChatGPT. Leadership was criticized for being dismissive of formal breach notifications. Furthermore, the dedicated GDPR contact email (gdpr@hackclub.com) was taken offline shortly after the issues were raised publicly, with operations staff later explaining it was a temporary solution managed by a part-time contributor.
Hack Club's leadership acknowledged the need for improved policies. The COO stated in a Slack message that the organization was in the process of assembling its policies for publication. In internal discussions, staff expressed a philosophy that the need for formal policy documents was a sign of underlying issues but agreed that clarity for users was necessary.