🚀ThreatReaper is now part of LockThreat

Privacy & Policy

Last Updated: January 1, 2026

Effective Date: January 1, 2026


1. Introduction

Welcome to ThreatReaper.ai (“ThreatReaper,” “we,” “us,” or “our“). We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered security platform and services (collectively, the “Services“).

By accessing or using our Services, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use our Services.

2. Information We Collect

2.1 Information You Provide to Us

Account Information: When you register for an account, we collect your name, email address, company name, job title, phone number, and billing information.

Profile Information: You may provide additional information in your user profile, including profile pictures, preferences, and communication settings.

Content and Data: We collect the content you submit to our Services, including prompts, queries, code snippets, API calls, security configurations, and any other data you upload or generate through our platform.

Communications: When you contact us for support or feedback, we collect the information you provide, including your correspondence and attachments.

Payment Information: Payment processing is handled by third-party payment processors. We do not store complete credit card information but may retain transaction records and billing addresses.

2.2 Information Automatically Collected

Usage Data: We automatically collect information about your interactions with our Services, including feature usage, API calls, response times, error logs, and performance metrics.

Device and Browser Information: We collect device identifiers, IP addresses, browser types and versions, operating systems, time zones, and device settings.

Cookies and Tracking Technologies: We use cookies, web beacons, and similar technologies to track activity and maintain sessions. See our Cookie Policy for more details.

Log Data: Our servers automatically log standard data provided by your web browser, including request dates and times, referring/exit pages, and clicked links.

2.3 Information from Third Parties

We may receive information from third-party services you connect to our platform, including authentication providers (OAuth, SSO), cloud service providers, and integration partners.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Service Delivery: To provide, operate, maintain, and improve our AI security services

  • Security and Threat Detection: To analyze prompts, detect security threats, identify vulnerabilities, and provide guardrails for AI applications

  • Account Management: To create and manage your account, authenticate users, and process transactions

  • Customer Support: To respond to inquiries, troubleshoot problems, and provide technical assistance

  • AI Model Training: To improve our machine learning models and algorithms (only with aggregated, anonymized data unless you explicitly opt-in)

  • Analytics and Insights: To understand usage patterns, generate analytics, and improve service performance

  • Communications: To send service updates, security alerts, technical notices, and marketing communications (with your consent)

  • Compliance and Legal: To comply with legal obligations, enforce our terms, and protect our rights and those of our users

  • Research and Development: To develop new features, products, and services

4. AI Model Training and Data Processing

Your Data, Your Control: We understand the sensitivity of data processed through our AI security platform. By default, your specific prompts and content are NOT used to train our models.

Anonymized Analytics: We may use aggregated, anonymized, and de-identified data to improve our models and threat detection capabilities. This data cannot be traced back to you or your organization.

Opt-In Model Training: Enterprise customers may opt-in to share specific data for custom model training to improve detection accuracy for their unique use cases. This is always optional and requires explicit consent.

Data Retention for Training: Anonymized training data is retained indefinitely. Identifiable data used for training (with consent) is retained according to your agreement terms.

5. Data Sharing and Disclosure

We do not sell your personal information. We may share your information in the following circumstances:

5.1 Service Providers

We engage third-party service providers to perform functions on our behalf, including:

  • Cloud infrastructure providers (AWS, Azure, GCP)
  • Payment processors (Stripe, PayPal)
  • Analytics services (Google Analytics, Mixpanel)
  • Customer support tools (Zendesk, Intercom)
  • Email service providers (SendGrid, Mailchimp)
  • Security and monitoring services

These providers have access to your information only to perform specific tasks and are obligated to protect your data.

5.2 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of assets, your information may be transferred to the successor entity. We will notify you before your information is transferred and becomes subject to a different privacy policy.

5.3 Legal Requirements

We may disclose your information if required by law, court order, or governmental regulation, or to:

  • Comply with legal processes and law enforcement requests
  • Protect the rights, property, or safety of ThreatReaper, our users, or the public
  • Detect, prevent, or address fraud, security, or technical issues
  • Enforce our Terms and Conditions

5.4 With Your Consent

We may share your information for purposes not described in this policy with your explicit consent.

6. Data Security

We implement industry-standard security measures to protect your information:

  • Encryption: All data is encrypted in transit (TLS 1.3) and at rest (AES-256)

  • Access Controls: Strict role-based access controls and multi-factor authentication

  • Infrastructure Security: Secure cloud infrastructure with regular security audits and penetration testing

  • Monitoring: 24/7 security monitoring and intrusion detection systems

  • Data Isolation: Multi-tenant architecture with logical data isolation

  • Incident Response: Comprehensive incident response plan and breach notification procedures

  • Employee Training: Regular security awareness training for all employees

While we strive to protect your information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security but maintain commercially reasonable safeguards.

7. Data Retention

We retain your information for as long as necessary to provide our Services and fulfill the purposes described in this policy:

  • Account Information: Retained while your account is active and for 90 days after account deletion

  • Usage Data and Logs: Retained for 12-24 months for analytics and security purposes

  • Security Analysis Data: Threat intelligence data may be retained longer in anonymized form

  • Backup Data: You need opt-in our default policy is 30 days

  • Legal Obligations: Some data may be retained longer to comply with legal, tax, or regulatory requirements

Upon request, we will delete or anonymize your personal information, except where retention is required by law.

8. Your Rights and Choices

Depending on your location, you may have the following rights:

8.1 Access and Portability

You have the right to request access to and receive a copy of the personal information we hold about you in a portable format.

8.2 Correction and Update

You can update your account information through your account settings or by contacting us to correct inaccurate data.

8.3 Deletion

You may request deletion of your personal information, subject to legal retention requirements and legitimate business needs.

8.4 Opt-Out of Marketing

You can opt out of marketing communications by clicking “unsubscribe” in emails or adjusting your communication preferences.

8.5 Cookie Management

You can control cookies through your browser settings. See our Cookie Policy for details.

8.6 Do Not Track

We do not currently respond to Do Not Track signals, as there is no industry standard for compliance.

To exercise these rights, contact us at [email protected]. We will respond within 30 days.

9. International Data Transfers

ThreatReaper operates globally. Your information may be transferred to and processed in countries other than your country of residence, including the United States, where data protection laws may differ.

For data transfers from the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Data Processing Agreements (DPAs) with appropriate safeguards
  • Adequacy decisions where applicable

You may request a copy of the safeguards we have in place by contacting [email protected].

10. GDPR Rights (European Users)

If you are located in the EEA or UK, you have additional rights under the General Data Protection Regulation (GDPR):

  • Right to Restriction: Request restriction of processing in certain circumstances

  • Right to Object: Object to processing based on legitimate interests or for direct marketing

  • Right to Withdraw Consent: Withdraw consent for processing at any time

  • Right to Lodge a Complaint: File a complaint with your local data protection authority

  • Automated Decision-Making: Not be subject to solely automated decisions with legal effects (our AI tools are human-supervised)

Legal Basis for Processing: We process your data based on:

  • Contract performance (to provide Services)
  • Legitimate interests (security, fraud prevention, service improvement)
  • Your consent (marketing, optional features)
  • Legal obligations (compliance, regulatory requirements)

11. CCPA Rights (California Users)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: Request disclosure of personal information collected, used, or shared

  • Right to Delete: Request deletion of personal information

  • Right to Opt-Out: Opt out of “sales” of personal information (we do not sell personal information)

  • Right to Non-Discrimination: Not receive discriminatory treatment for exercising your rights

Categories of Information Collected: Identifiers, commercial information, Internet activity, professional information, and inferences drawn from this data.

To exercise these rights, submit a verifiable request to [email protected].

12. Children’s Privacy

Our Services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child without parental consent, we will take steps to delete it promptly.

13. Third-Party Links and Services

Our Services may contain links to third-party websites or integrate with third-party services. We are not responsible for the privacy practices of these external sites or services. We encourage you to review their privacy policies.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations. We will notify you of material changes by:

  • Posting the updated policy on our website with a new “Last Updated” date
  • Sending an email notification to your registered email address
  • Displaying a prominent notice in our Services

Your continued use of our Services after the effective date of the updated policy constitutes acceptance of the changes.

15. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

ThreatReaper
Email: [email protected]
Support: [email protected]
Website: https://threatreaper.ai

Data Protection Officer:
Email: [email protected]


This Privacy Policy is effective as of January 1, 2026. By using ThreatReaper.ai Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.