Legal / Privacy

Privacy Policy

Last updated: August 2026

This policy explains how ThreatDoc ("we", "us", "our") collects, uses, stores, and protects your personal data when you use our website and security documentation service (the "Service").

01

Data Controller

ThreatDoc is operated by ThreatDoc LLC, a Florida limited liability company. For questions about your data, contact us at:

support@threatdoc.com

02

Data We Collect

Account data

Email address, name (if provided), and a hashed password. We never store passwords in plain text.

Profile and billing data

Name and plan type. Payment information is processed and stored directly by Stripe. We never see or store your card details ourselves. A payment confirmation and truncated card identifier are visible to us only through Stripe's own dashboard, not within ThreatDoc.

Document content

Documents, artifacts, evidence images, and notes you create in the ThreatDoc desktop app. You retain full ownership of this content. If you choose to sync a document to the cloud, it is encrypted on your device before it ever reaches us — see Section 10 for what that means for what we can and can't see.

Usage and technical data

Server access logs (IP address, request path, timestamp) are retained briefly for security and abuse prevention. We do not use cross-site tracking or advertising cookies.

Uploaded files

Evidence images and PDFs you upload are stored in private, access-controlled storage. Signed URLs with short expiry windows are used to serve these files that are not publicly accessible.

Team collaboration

If you join a team, documents added to that team are encrypted with a key shared among active team members, so any of them can decrypt and work on it — we do not grant this access ourselves, and we cannot decrypt team document content any more than we can decrypt your personal documents. This access is limited to the team you're active on; it does not extend to your personal documents outside that team. If you're a team leader, see Section 07 of our Terms of Service for how sponsoring a member's seat is billed.

03

How We Use Your Data

PurposeLegal basis
Providing and operating the ServicePerformance of contract
Account creation and authenticationPerformance of contract
Processing payments and billingPerformance of contract
Generating and storing PDF documentsPerformance of contract
Sending transactional emails (document shares, password resets)Performance of contract
Security monitoring and abuse preventionLegitimate interest
Legal compliance and dispute resolutionLegal obligation
04

Third-Party Processors

We share data with the following providers who process it on our behalf:

ProviderPurposeLocation
SupabaseDatabase, authentication, and file storageUSA (SCCs)
VercelApplication hosting and edge deliveryUSA (SCCs)
Stripe, Inc.Payment processingUSA (SCCs)
ResendTransactional email deliveryUSA (SCCs)
CloudflareBot and abuse protection (Turnstile)USA (SCCs)
UpstashRate limiting and abuse prevention (stores IP address and account identifiers briefly)USA (SCCs)

For transfers outside your region, we rely on Standard Contractual Clauses or other appropriate safeguards.

05

Document Sharing

If you choose to share a generated PDF with a client using our share link feature:

  • A unique, non-guessable share token is generated for each PDF that touches our server. The link expires 14 days after the PDF is generated.
  • Every generated PDF is protected by a randomly generated password, shown to you once at generation time. The password is hashed using scrypt before storage, we cannot retrieve it in plain text, so it is your responsibility to relay it to your client through an alternative channel.
  • The client's email address you provide when sending a share link is used solely to deliver that link. It is not added to any marketing list.
  • PDF download links are signed and expire after 1 hour. The underlying storage bucket is private and not publicly accessible.
06

Cookies and Tracking

ThreatDoc uses only strictly necessary cookies for session management and authentication. We do not use advertising cookies, cross-site tracking, or third-party analytics scripts.

The session cookie is set when you log in and cleared when you sign out. It is marked HttpOnly and Secure.

07

Data Retention

Data typeRetention period
Account and profile dataDuration of active account; deleted immediately on account deletion
Documents and artifacts you currently holdDuration of active account; deleted immediately on account deletion
Evidence imagesDuration of active account; deleted immediately on account deletion
Share links and tokens14 days from PDF generation
Payment and billing recordsAs required by applicable tax law
Server access logs30 days, then deleted

Deleting your account, from Account Settings or by asking us to, is immediate and permanent, there is no recovery window afterward. Documents never synced to the cloud live only on your device and are never something we hold to delete in the first place. After any other applicable retention period above, data is permanently deleted or anonymized.

08

Your Rights

You have the right to:

  • Access request a copy of the personal data we hold about you.
  • Rectification request correction of inaccurate data. Your name, email address, and other profile data can be updated directly in Account Settings.
  • Erasure delete your account and all associated data yourself, at any time, from Account Settings, or request deletion by emailing us.
  • Portability request your data in a structured, machine-readable format.
  • Object object to processing based on legitimate interests.
  • Complain if you are located in the EU, UK, or EEA, lodge a complaint with your local data protection supervisory authority if you believe we have not adequately addressed your concerns.

To exercise any of these rights, email support@threatdoc.com. We will respond within 30 days.

09

California Privacy Rights

ThreatDoc does not sell or share personal information, as those terms are defined under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), and has not done so in the preceding 12 months. We do not use personal information for cross-context behavioral advertising. Where technically feasible, we honor Global Privacy Control (GPC) signals from your browser as a valid opt-out preference signal under the CCPA/CPRA.

California residents have the rights described in Section 08 above (access, correction, deletion, and portability), as well as the right to non-discrimination for exercising these rights. To exercise any of these rights, email support@threatdoc.com.

10

Security

We implement the following measures to protect your data:

  • Encryption of data in transit (TLS/HTTPS)
  • Passwords hashed using industry-standard algorithms
  • Private storage buckets with short-lived signed URLs for file access
  • Row-level security (RLS) enforced at the database level, users can only access their own data
  • Share tokens are unique, non-guessable UUIDs with a fixed expiry window
  • Every shared PDF is protected by a randomly generated password hashed using scrypt
  • Bot and abuse protection (Cloudflare Turnstile) on login and signup
  • Zero knowledge encryption: every document synced to the cloud is encrypted on your device using an account key (or, for team documents, a shared team key) generated in the desktop app and shown to you once. We never store this key or see your plaintext content — see our Terms of Service for what that means if it's lost

No method of transmission or storage is 100% secure. If you discover a security vulnerability in ThreatDoc, please report it to security@threatdoc.com.

In the event of a data breach that compromises your personal data, we will notify affected users without undue delay and in accordance with applicable law, no later than 30 days after we determine a breach has occurred, consistent with Florida's data breach notification statute (Fla. Stat. § 501.171), or within 72 hours to relevant supervisory authorities where required under GDPR.

11

Children's Privacy

ThreatDoc is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, contact us and we will delete it promptly.

12

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or the Service. Significant changes will be communicated via email or an in-app notice. The updated policy will be posted here with a revised date.

Continued use of the Service after changes are posted constitutes acceptance of the updated policy.

13

Contact

For any questions about this Privacy Policy or how we handle your data:

support@threatdoc.com

© 2026 ThreatDoc