Legal
Privacy
Policy
Last updated: 25 August 2026
10 sections
This policy explains what data Kali Hub ("we", "us", or "our") collects when you use our website, our
key system, or a Kali Premium subscription, why we collect it, and who else handles it. By using our
services you agree to this policy, and to the privacy policies of the third parties listed in Section 6.
01
What We Collect
We keep collection to what the service actually needs. Some data is handled by us directly, and some
by the providers we depend on.
Collected by us directly:
- IP address — used to rate-limit our endpoints and to detect abuse. For rate limiting it is stored only as an irreversible hash, not as a readable address.
- Licence key activity — the time of your last HWID reset, so the 48-hour cooldown can be enforced. Your key is stored as an irreversible hash, not in plain text.
- Key system progress — short-lived tokens that prove you completed the checkpoints, so a key can be issued.
- Gameplay telemetry — session information such as job IDs, player data, and in-game items (for example pets and fruits), used for community features and to improve our scripts.
Collected by our providers when you buy or authenticate:
- Order data (via SellAuth, our store and payment platform) — email address, Discord ID, IP address, the products purchased, invoice and delivery timestamps, and your acceptance of our Terms at checkout.
- Authentication data (via Luarmor, our key system provider) — IP address, hardware identifier (HWID), timestamps, and in some cases Discord ID.
- Payment data — handled entirely by the payment provider. We never receive or store your full card details.
02
Why We Use It
- To deliver the service — issuing keys, binding them to your device, processing subscriptions and renewals, and providing support.
- To prevent abuse — detecting key sharing, key system bypasses, automated requests, and other misuse.
- To respond to payment disputes — where a chargeback or dispute is raised, we may submit transaction and access records as evidence, including the invoice, delivery timestamps, email address, Discord ID, IP address at checkout, key activity, and your acceptance of our Terms. This is described in Section 6 of our Terms of Service.
- To improve stability and performance of our scripts and infrastructure.
We do not sell, rent, or trade your data, and we do not use it for advertising.
03
How Long We Keep It
- Rate-limit records and key system tokens are short-lived and are deleted automatically, typically within one to two days.
- HWID reset records are kept only for as long as the cooldown window requires.
- Order and invoice records are retained for as long as necessary for accounting, fraud prevention, and responding to payment disputes — including after your subscription ends, since a dispute can be raised months after a charge.
- Authentication data is retained according to Luarmor's own policy.
04
Browser Storage
- Our key system stores your active key and your checkpoint progress in your browser's local storage, so you do not lose progress on refresh. This stays on your device.
- We do not use advertising or cross-site tracking cookies.
- Third-party services embedded on our pages — such as the Cloudflare captcha on the HWID reset page, and the checkout window — may set their own cookies under their own policies.
- Clearing your browser data removes locally stored progress, but does not reset server-side limits such as the HWID reset cooldown.
05
Data Protection
- Sensitive identifiers such as IP addresses and licence keys are stored as irreversible hashes wherever they are only needed for comparison.
- Runtime data written by our endpoints is kept outside the public web root and is not reachable over the internet.
- Traffic to our site is encrypted in transit.
- No system is entirely secure. We apply reasonable safeguards, but use is at your own risk.
06
Third-Party Services
We rely on the following providers, each with their own privacy policy that also applies to you:
- Luarmor — key authentication and anti-tamper enforcement.
- SellAuth — storefront, checkout, subscriptions, and order records.
- Payment providers — card and alternative payment processing, reached through the checkout.
- Cloudflare — content delivery, DDoS protection, and the captcha used on the HWID reset page and the free key system.
- Boostellar (Bstlar) — free key system offer provider; receives your IP address and user-agent when you open the offer link, and issues a single-use key that we validate against your IP address.
- Adsterra — advertising shown during the free key system.
- ip-api.com — IP reputation lookup used to detect VPN and proxy connections during the free key system.
- Discord — support, community, and in some cases account linking.
07
Your Rights
- You may request a copy of the data we hold about you, or ask us to delete it, by opening a ticket in our Discord.
- Deleting your data ends any active subscription and revokes your key, since we can no longer authenticate you.
- We may retain the minimum records required for fraud prevention, accounting, and payment disputes even after a deletion request, where we are permitted or required to do so.
- Data held by Luarmor or by a payment provider must be requested from them directly, under their own policies.
08
Children
Our services are not directed at children under 13. If you are under the age of majority in your country,
you may only use our paid services with the consent and supervision of a parent or legal guardian, as set
out in Section 1 of our Terms of Service.
If you believe a child has provided us with personal data, contact us and we will remove it.
09
Policy Changes
We may update this policy at any time. The "last updated" date at the top of this page reflects the
current version. Continued use of our services after a change implies acceptance of the updated policy.
10
Contact
For any question about this policy, or to make a data request, open a ticket in our
Discord server.