Legal / Privacy
Last updated: August 2026
This policy explains how ThreatDoc ("we", "us", "our") collects, uses, stores, and protects your personal data when you use our website and security documentation service (the "Service").
ThreatDoc is operated by ThreatDoc LLC, a Florida limited liability company. For questions about your data, contact us at:
Account data
Email address, name (if provided), and a hashed password. We never store passwords in plain text.
Profile and billing data
Name and plan type. Payment information is processed and stored directly by Stripe. We never see or store your card details ourselves. A payment confirmation and truncated card identifier are visible to us only through Stripe's own dashboard, not within ThreatDoc.
Document content
Documents, artifacts, evidence images, and notes you create in the ThreatDoc desktop app. You retain full ownership of this content. If you choose to sync a document to the cloud, it is encrypted on your device before it ever reaches us — see Section 10 for what that means for what we can and can't see.
Usage and technical data
Server access logs (IP address, request path, timestamp) are retained briefly for security and abuse prevention. We do not use cross-site tracking or advertising cookies.
Uploaded files
Evidence images and PDFs you upload are stored in private, access-controlled storage. Signed URLs with short expiry windows are used to serve these files that are not publicly accessible.
Team collaboration
If you join a team, documents added to that team are encrypted with a key shared among active team members, so any of them can decrypt and work on it — we do not grant this access ourselves, and we cannot decrypt team document content any more than we can decrypt your personal documents. This access is limited to the team you're active on; it does not extend to your personal documents outside that team. If you're a team leader, see Section 07 of our Terms of Service for how sponsoring a member's seat is billed.
| Purpose | Legal basis |
|---|---|
| Providing and operating the Service | Performance of contract |
| Account creation and authentication | Performance of contract |
| Processing payments and billing | Performance of contract |
| Generating and storing PDF documents | Performance of contract |
| Sending transactional emails (document shares, password resets) | Performance of contract |
| Security monitoring and abuse prevention | Legitimate interest |
| Legal compliance and dispute resolution | Legal obligation |
We share data with the following providers who process it on our behalf:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, and file storage | USA (SCCs) |
| Vercel | Application hosting and edge delivery | USA (SCCs) |
| Stripe, Inc. | Payment processing | USA (SCCs) |
| Resend | Transactional email delivery | USA (SCCs) |
| Cloudflare | Bot and abuse protection (Turnstile) | USA (SCCs) |
| Upstash | Rate limiting and abuse prevention (stores IP address and account identifiers briefly) | USA (SCCs) |
For transfers outside your region, we rely on Standard Contractual Clauses or other appropriate safeguards.
If you choose to share a generated PDF with a client using our share link feature:
ThreatDoc uses only strictly necessary cookies for session management and authentication. We do not use advertising cookies, cross-site tracking, or third-party analytics scripts.
The session cookie is set when you log in and cleared when you sign out. It is marked HttpOnly and Secure.
| Data type | Retention period |
|---|---|
| Account and profile data | Duration of active account; deleted immediately on account deletion |
| Documents and artifacts you currently hold | Duration of active account; deleted immediately on account deletion |
| Evidence images | Duration of active account; deleted immediately on account deletion |
| Share links and tokens | 14 days from PDF generation |
| Payment and billing records | As required by applicable tax law |
| Server access logs | 30 days, then deleted |
Deleting your account, from Account Settings or by asking us to, is immediate and permanent, there is no recovery window afterward. Documents never synced to the cloud live only on your device and are never something we hold to delete in the first place. After any other applicable retention period above, data is permanently deleted or anonymized.
You have the right to:
To exercise any of these rights, email support@threatdoc.com. We will respond within 30 days.
ThreatDoc does not sell or share personal information, as those terms are defined under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), and has not done so in the preceding 12 months. We do not use personal information for cross-context behavioral advertising. Where technically feasible, we honor Global Privacy Control (GPC) signals from your browser as a valid opt-out preference signal under the CCPA/CPRA.
California residents have the rights described in Section 08 above (access, correction, deletion, and portability), as well as the right to non-discrimination for exercising these rights. To exercise any of these rights, email support@threatdoc.com.
We implement the following measures to protect your data:
No method of transmission or storage is 100% secure. If you discover a security vulnerability in ThreatDoc, please report it to security@threatdoc.com.
In the event of a data breach that compromises your personal data, we will notify affected users without undue delay and in accordance with applicable law, no later than 30 days after we determine a breach has occurred, consistent with Florida's data breach notification statute (Fla. Stat. § 501.171), or within 72 hours to relevant supervisory authorities where required under GDPR.
ThreatDoc is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, contact us and we will delete it promptly.
We may update this Privacy Policy from time to time to reflect changes in our practices or the Service. Significant changes will be communicated via email or an in-app notice. The updated policy will be posted here with a revised date.
Continued use of the Service after changes are posted constitutes acceptance of the updated policy.
For any questions about this Privacy Policy or how we handle your data: