Privacy Policy
ThreatWatch ("we," "us") operates a hosted cyber threat intelligence platform at this domain. This policy explains what we collect when you use the Community plan, why, and what control you have over it.
What we collect
- Account data — name, email address, and password hash when you register.
- Organization content — indicators, cases, incidents, reports, notes, and other intelligence data you or your team create or import into your organization's workspace.
- Usage data — log-level data such as IP address, browser/device information, and timestamps of requests, used for security monitoring and abuse prevention.
- Third-party feed data — indicators and enrichment results pulled from the threat-feed integrations you configure (e.g. VirusTotal, Shodan, MISP). Requests to those providers are subject to their own terms.
How we use it
- To operate, secure, and improve the platform.
- To enforce TLP (Traffic Light Protocol) clearance and role-based access control within your organization.
- To send account, security, and service-related emails (password resets, failed-job alerts, AI research agent notifications).
- To generate AI enrichment results when you enable an AI provider — enrichment requests are sent to the provider you configure (Claude, Groq, or a self-hosted Ollama instance) and are not used to train our own models.
Data isolation
Intelligence data is scoped to your organization. We do not share one organization's indicators, cases, or reports with another. Access within an organization is governed by role (admin/analyst) and TLP clearance, as described in the product documentation.
Retention & deletion
We retain account and organization data for as long as your account is active. You can request deletion of your account and associated organization data by contacting us — we will remove it within a reasonable period, except where retention is required for security or legal purposes.
Third parties
We do not sell your data. We share data only with the third-party services you explicitly configure (threat-feed integrations, AI providers, SMTP) and with infrastructure providers necessary to host the platform, under their standard confidentiality terms.
Contact
Questions about this policy or a data request can be sent through the contact details on your account or organization admin.
This page is a general-purpose starting point and is not a substitute for legal advice tailored to your organization's obligations (e.g. GDPR, CCPA).