Privacy & Policy
Last Updated:Â January 1, 2026
Effective Date:Â January 1, 2026
1. Introduction
Welcome to ThreatReaper.ai (“ThreatReaper,” “we,” “us,” or “our“). We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered security platform and services (collectively, the “Services“).
By accessing or using our Services, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use our Services.
2. Information We Collect
2.1 Information You Provide to Us
Account Information:Â When you register for an account, we collect your name, email address, company name, job title, phone number, and billing information.
Profile Information:Â You may provide additional information in your user profile, including profile pictures, preferences, and communication settings.
Content and Data:Â We collect the content you submit to our Services, including prompts, queries, code snippets, API calls, security configurations, and any other data you upload or generate through our platform.
Communications:Â When you contact us for support or feedback, we collect the information you provide, including your correspondence and attachments.
Payment Information:Â Payment processing is handled by third-party payment processors. We do not store complete credit card information but may retain transaction records and billing addresses.
2.2 Information Automatically Collected
Usage Data:Â We automatically collect information about your interactions with our Services, including feature usage, API calls, response times, error logs, and performance metrics.
Device and Browser Information:Â We collect device identifiers, IP addresses, browser types and versions, operating systems, time zones, and device settings.
Cookies and Tracking Technologies: We use cookies, web beacons, and similar technologies to track activity and maintain sessions. See our Cookie Policy for more details.
Log Data:Â Our servers automatically log standard data provided by your web browser, including request dates and times, referring/exit pages, and clicked links.
2.3 Information from Third Parties
We may receive information from third-party services you connect to our platform, including authentication providers (OAuth, SSO), cloud service providers, and integration partners.
3. How We Use Your Information
We use the information we collect for the following purposes:
Service Delivery:Â To provide, operate, maintain, and improve our AI security services
Security and Threat Detection:Â To analyze prompts, detect security threats, identify vulnerabilities, and provide guardrails for AI applications
Account Management:Â To create and manage your account, authenticate users, and process transactions
Customer Support:Â To respond to inquiries, troubleshoot problems, and provide technical assistance
AI Model Training:Â To improve our machine learning models and algorithms (only with aggregated, anonymized data unless you explicitly opt-in)
Analytics and Insights:Â To understand usage patterns, generate analytics, and improve service performance
Communications:Â To send service updates, security alerts, technical notices, and marketing communications (with your consent)
Compliance and Legal:Â To comply with legal obligations, enforce our terms, and protect our rights and those of our users
Research and Development:Â To develop new features, products, and services
4. AI Model Training and Data Processing
Your Data, Your Control: We understand the sensitivity of data processed through our AI security platform. By default, your specific prompts and content are NOT used to train our models.
Anonymized Analytics:Â We may use aggregated, anonymized, and de-identified data to improve our models and threat detection capabilities. This data cannot be traced back to you or your organization.
Opt-In Model Training:Â Enterprise customers may opt-in to share specific data for custom model training to improve detection accuracy for their unique use cases. This is always optional and requires explicit consent.
Data Retention for Training:Â Anonymized training data is retained indefinitely. Identifiable data used for training (with consent) is retained according to your agreement terms.
5. Data Sharing and Disclosure
We do not sell your personal information. We may share your information in the following circumstances:
5.1 Service Providers
We engage third-party service providers to perform functions on our behalf, including:
- Cloud infrastructure providers (AWS, Azure, GCP)
- Payment processors (Stripe, PayPal)
- Analytics services (Google Analytics, Mixpanel)
- Customer support tools (Zendesk, Intercom)
- Email service providers (SendGrid, Mailchimp)
- Security and monitoring services
These providers have access to your information only to perform specific tasks and are obligated to protect your data.
5.2 Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of assets, your information may be transferred to the successor entity. We will notify you before your information is transferred and becomes subject to a different privacy policy.
5.3 Legal Requirements
We may disclose your information if required by law, court order, or governmental regulation, or to:
- Comply with legal processes and law enforcement requests
- Protect the rights, property, or safety of ThreatReaper, our users, or the public
- Detect, prevent, or address fraud, security, or technical issues
- Enforce our Terms and Conditions
5.4 With Your Consent
We may share your information for purposes not described in this policy with your explicit consent.
6. Data Security
We implement industry-standard security measures to protect your information:
Encryption:Â All data is encrypted in transit (TLS 1.3) and at rest (AES-256)
Access Controls:Â Strict role-based access controls and multi-factor authentication
Infrastructure Security:Â Secure cloud infrastructure with regular security audits and penetration testing
Monitoring:Â 24/7 security monitoring and intrusion detection systems
Data Isolation:Â Multi-tenant architecture with logical data isolation
Incident Response:Â Comprehensive incident response plan and breach notification procedures
Employee Training:Â Regular security awareness training for all employees
While we strive to protect your information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security but maintain commercially reasonable safeguards.
7. Data Retention
We retain your information for as long as necessary to provide our Services and fulfill the purposes described in this policy:
Account Information:Â Retained while your account is active and for 90 days after account deletion
Usage Data and Logs:Â Retained for 12-24 months for analytics and security purposes
Security Analysis Data:Â Threat intelligence data may be retained longer in anonymized form
Backup Data: You need opt-in our default policy is 30 days
Legal Obligations:Â Some data may be retained longer to comply with legal, tax, or regulatory requirements
Upon request, we will delete or anonymize your personal information, except where retention is required by law.
8. Your Rights and Choices
Depending on your location, you may have the following rights:
8.1 Access and Portability
You have the right to request access to and receive a copy of the personal information we hold about you in a portable format.
8.2 Correction and Update
You can update your account information through your account settings or by contacting us to correct inaccurate data.
8.3 Deletion
You may request deletion of your personal information, subject to legal retention requirements and legitimate business needs.
8.4 Opt-Out of Marketing
You can opt out of marketing communications by clicking “unsubscribe” in emails or adjusting your communication preferences.
8.5 Cookie Management
You can control cookies through your browser settings. See our Cookie Policy for details.
8.6 Do Not Track
We do not currently respond to Do Not Track signals, as there is no industry standard for compliance.
To exercise these rights, contact us at [email protected]. We will respond within 30 days.
9. International Data Transfers
ThreatReaper operates globally. Your information may be transferred to and processed in countries other than your country of residence, including the United States, where data protection laws may differ.
For data transfers from the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data Processing Agreements (DPAs) with appropriate safeguards
- Adequacy decisions where applicable
You may request a copy of the safeguards we have in place by contacting [email protected].
10. GDPR Rights (European Users)
If you are located in the EEA or UK, you have additional rights under the General Data Protection Regulation (GDPR):
Right to Restriction:Â Request restriction of processing in certain circumstances
Right to Object:Â Object to processing based on legitimate interests or for direct marketing
Right to Withdraw Consent:Â Withdraw consent for processing at any time
Right to Lodge a Complaint:Â File a complaint with your local data protection authority
Automated Decision-Making:Â Not be subject to solely automated decisions with legal effects (our AI tools are human-supervised)
Legal Basis for Processing:Â We process your data based on:
- Contract performance (to provide Services)
- Legitimate interests (security, fraud prevention, service improvement)
- Your consent (marketing, optional features)
- Legal obligations (compliance, regulatory requirements)
11. CCPA Rights (California Users)
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):
Right to Know:Â Request disclosure of personal information collected, used, or shared
Right to Delete:Â Request deletion of personal information
Right to Opt-Out:Â Opt out of “sales” of personal information (we do not sell personal information)
Right to Non-Discrimination:Â Not receive discriminatory treatment for exercising your rights
Categories of Information Collected:Â Identifiers, commercial information, Internet activity, professional information, and inferences drawn from this data.
To exercise these rights, submit a verifiable request to [email protected].
12. Children’s Privacy
Our Services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child without parental consent, we will take steps to delete it promptly.
13. Third-Party Links and Services
Our Services may contain links to third-party websites or integrate with third-party services. We are not responsible for the privacy practices of these external sites or services. We encourage you to review their privacy policies.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations. We will notify you of material changes by:
- Posting the updated policy on our website with a new “Last Updated” date
- Sending an email notification to your registered email address
- Displaying a prominent notice in our Services
Your continued use of our Services after the effective date of the updated policy constitutes acceptance of the changes.
15. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
ThreatReaper
Email:Â [email protected]
Support:Â [email protected]
Website:Â https://threatreaper.ai
Data Protection Officer:
Email:Â [email protected]
This Privacy Policy is effective as of January 1, 2026. By using ThreatReaper.ai Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.