Salta al contenuto principale

CVE Watch

Informativa sulla privacy / Privacy Policy

Versione italiana

Ultimo aggiornamento: 20 agosto 2026

CVE Watch mostra le vulnerabilità informatiche sfruttate attivamente, tratte dal catalogo KEV della CISA statunitense, e avvisa quando ne compare una che riguarda un prodotto scelto dall'utente.

Nessun account, nessun profilo

Per usare CVE Watch non servono email, account, registrazione né alcun dato personale. L'app non chiede il nome, non accede alla rubrica, alla posizione, alle foto o al microfono, e non mostra pubblicità.

Cosa lascia il dispositivo

Solo se l'utente attiva le notifiche, e solo allora, l'app chiede al proprio server un identificativo casuale per questa installazione — non collegato alla persona, al dispositivo o ad alcun account — e da quel momento invia:

  • il token di notificaassegnato da Apple al dispositivo, che serve ad Apple per recapitare l'avviso e non identifica la persona;
  • l'ambiente di notifica(sviluppo o produzione) e l'identificativo dell'app, necessari perché Apple accetti la consegna;
  • i vendor e i prodotti scelti, cioè le regole di monitoraggio, per sapere quali avvisi inviare. Sono legate a quell'identificativo e a nessun altro: chi installa l'app non vede né modifica le regole di nessun altro.
  • se l'utente acquista o ripristina l'abbonamento, la transazione firmata da Apple, usata esclusivamente per verificare sul server che il diritto alle notifiche sia attivo. L'app non riceve né invia al proprio server il nome, l'email o le credenziali dell'ID Apple.
  • Non viene raccolto altro: nessun indirizzo IP conservato a fini di profilazione, nessuna statistica d'uso, nessun identificativo pubblicitario, nessun strumento di analisi di terze parti. Il codice non include alcun SDK esterno.

Come vengono usati

Esclusivamente per recapitare le notifiche richieste. I dati non vengono venduti, ceduti né condivisi con terzi, con la sola eccezione di Apple Push Notification service, che è il canale tecnico attraverso cui la notifica raggiunge il dispositivo ed è gestito da Apple secondo le proprie condizioni.

Per quanto tempo

Il token resta memorizzato finché l'app è installata e le notifiche sono attive. Disattivando le notifiche o disinstallando l'app, Apple segnala al server che il dispositivo non è più raggiungibile e il token viene disattivato.

Un'installazione rimasta senza dispositivo attivo per 30 giorni viene cancellata dal server insieme al suo identificativo, alle sue regole e allo storico delle consegne: la rimozione è automatica e non va richiesta. Per la cancellazione immediata è possibile scrivere a [email protected].

Consultazione senza notifiche

Chi non attiva le notifiche può consultare l'elenco e il dettaglio delle vulnerabilità senza che nulla lasci il dispositivo, a parte le normali richieste di rete necessarie a scaricare i dati pubblici.

Minori

L'app non è rivolta ai minori di 13 anni e non raccoglie consapevolmente dati che li riguardino.

Modifiche

Eventuali modifiche a questa informativa saranno pubblicate a questo indirizzo, con la data di aggiornamento in cima.

Contatti

[email protected]

English version

Last updated: August 20, 2026

CVE Watch shows actively exploited software vulnerabilities, sourced from the U.S. CISA Known Exploited Vulnerabilities catalog, and alerts you when a new one affects a product you have chosen to follow.

No account, no profile

CVE Watch requires no email, account, sign-up, or personal information. The app does not ask for your name and does not access your contacts, location, photos, or microphone. It shows no advertising.

What leaves your device

Only if you turn notifications on, and only then, the app asks its own server for a random identifier for this installation — not tied to you, to your device, or to any account — and from that moment sends:

  • the push token Apple assigns to your device, which Apple uses to deliver the alert and which does not identify you as a person;
  • the notification environment (development or production) and the app identifier, both required for Apple to accept the delivery;
  • the vendors and products you selected, so the server knows which alerts to send. They belong to that identifier and to no other: no one else installing the app can see or change your rules.
  • if you purchase or restore the subscription, the transaction signed by Apple, used solely to verify on the server that notification access is active. The app does not receive or send your Apple ID name, email address, or credentials to its server.
  • Nothing else is collected: no IP addresses retained for profiling, no usage analytics, no advertising identifier, no third-party analytics. The app bundles no third-party SDKs.

How it is used

Solely to deliver the alerts you asked for. Data is never sold, rented, or shared with third parties, with the single exception of Apple Push Notification service, the technical channel that carries the alert to the device, operated by Apple under its own terms.

How long it is kept

Your push token is stored while the app is installed and notifications are enabled. If you turn notifications off or delete the app, Apple reports the device as unreachable and the token is deactivated.

An installation left without an active device for 30 days is deleted from the server along with its identifier, its rules, and its delivery history: removal is automatic and does not need to be requested. For immediate deletion, write to [email protected].

Browsing without notifications

If you never enable notifications, you can browse and read vulnerabilities without anything leaving your device, beyond the ordinary network requests needed to download the public data.

Children

The app is not directed to children under 13 and does not knowingly collect their data.

Changes

Any change to this policy will be published at this address, with the update date at the top.

Contact

[email protected]