Who is responsible
ThreatNoir is run by Marcus Lenngren in Sweden, who is the controller of the personal data described here. Write to contact@threatnoir.com with any question or request about your data. Organisation number and registration details are available on request.
This policy covers threatnoir.com and its emails, alerts, feeds and API. The weekly quiz and ThreatNoir Academy for organisations, at quiz.threatnoir.com, have their own privacy notice.
When you read the site
You can read articles, lessons, briefs, the IOC feeds and the podcast without an account. Pages load only from threatnoir.com, cdn.threatnoir.com (our podcast and video files) and, when you sign in, our authentication provider. We embed no third-party trackers, ads, fonts or videos.
- Visit statistics. When a page loads, your browser sends us a page-view event: the page address, the website that sent you (on the first page of a visit only), your browser's user-agent string and a keyed hash of your IP address. The hash is made with a secret key and shortened, so we can count visitors without storing the address. From page addresses we keep only campaign tags such as
utm_source. No cookies are involved. - Vercel Web Analytics. Our hosting provider also counts page views for us, without cookies. Vercel tells visits apart by a hash of the request, which it discards after 24 hours, and receives the page address with only campaign tags kept.
- Opting out. If your browser sends Global Privacy Control or Do Not Track, it sends neither kind of statistics.
- Server logs. Our hosting and database providers see your IP address when they answer a request, and keep it in their logs for a short time for security and troubleshooting.
What we store in your browser
We set no advertising or analytics cookies, which is why there is no cookie banner. The site's framework saves one display setting (dark mode) in your browser, with no identifier in it. Everything else is stored only when you use a feature that needs it:
- Signing in: cookies that keep you signed in. They are set when you sign in and removed when you sign out.
- Rating an article: a random identifier, so each article gets one rating from you and you can see your own. It is created the first time you rate.
- The weekly quiz: a random player token, the display name you choose and which quizzes you have played.
You can clear all of these in your browser settings at any time.
Newsletters and alerts
When you sign up for the daily brief, the weekly digest or Vendor Watch alerts, we store your email address, your name if you give one, what you subscribed to and when, and the tokens behind your confirmation and unsubscribe links. Nothing is sent until you confirm by email, and every email has a one-click unsubscribe link. Our emails contain no tracking pixels, and their links are not rewritten to track clicks.
- Your watchlist: the vendors and products you list, which we match against new stories. It stays private: it never appears in email subject lines, and we keep it out of our logs.
- Other channels: if you send alerts to Discord, Telegram or your own webhook, we store that channel's address and deliver the alerts there. Discord and Telegram then handle those messages under their own privacy policies.
- Delivery log: which stories we sent you and when, so you don't get the same alert twice.
Accounts and signing in with Google, Microsoft or GitHub
An account is optional. It lets you manage your subscriptions and watchlist in one place and create API keys.
- Email and password: we store your email address. Our authentication provider stores your password only as a salted hash.
- Google, Microsoft or GitHub: when you choose one, that provider sends us your email address, your name or username, a link to your profile picture and an account identifier. We use them only to create your ThreatNoir account, sign you in and send the emails you ask for. We receive nothing else from those accounts: no password, contacts, files or calendar. We don't use this data for advertising, and we share it only with the service providers listed below. ThreatNoir's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- Security records: the authentication service records sign-ins, including the IP address, to protect your account.
- API keys: we store only a hash of each key and its first few characters, so you can tell your keys apart.
Messages, tips and the quiz
- Contact form: your name, email address, subject and message reach us as an email. They are not stored in our database.
- Tips you submit: the tip, plus your name and email address if you give them. We store them with the tip, and use the email address only to limit how many tips one person can send.
- Feature requests: when you tell us you want something, such as room for more vendors, we store your email address, what you asked for and, if you give it, your company size.
- The weekly quiz: your display name, score and time appear on the public leaderboard. We keep that result, not your individual answers, together with your player token and a keyed hash of your IP address to limit repeat attempts.
Why we use your data
- Newsletters and alerts you asked for: your consent (GDPR Article 6(1)(a)). You can withdraw it at any time with the unsubscribe link or in your settings.
- Your account and the features you use, such as API keys, settings, the quiz and ratings: to provide the service you asked for (Article 6(1)(b)).
- Keeping the site secure, stopping abuse and counting visits: our legitimate interest in running a safe and reliable service (Article 6(1)(f)), using hashed or shortened data wherever we can.
- Answering your messages: our legitimate interest in replying to you (Article 6(1)(f)).
We do not sell personal data, use it for advertising or make automated decisions about you.
Who helps us
The first five handle personal data for us, only to run ThreatNoir. The others come into play only when you choose them, and handle your data under their own policies.
| Provider | What they do | Where |
|---|---|---|
| Supabase | Database and sign-in | EU (Ireland) |
| Vercel | Hosting the website and visit statistics | EU (Dublin, Ireland) for the site's server code, plus a global delivery network. Vercel Inc. is based in the USA. |
| Resend | Sending email | USA |
| Cloudflare | DNS and our podcast and video files | Global network. Cloudflare Inc. is based in the USA. |
| Google Workspace | Our email inbox: contact messages and the mail you send us | Google's data centres in the EU and the USA |
| Google, Microsoft, GitHub | Sign-in, only if you choose it | Under their own privacy policies |
| Discord, Telegram | Alert delivery, only if you choose it | Under their own privacy policies |
We use AI services to summarise public news and write lessons. We don't send them your personal data.
When a provider handles personal data outside the EU/EEA, the transfer is covered by the EU-US Data Privacy Framework or by the European Commission's standard contractual clauses.
How long we keep data
- Subscriptions and your watchlist: until you unsubscribe or delete your account. After you unsubscribe we keep your email address, marked as unsubscribed, so we don't email you again by mistake.
- Your account: until you delete it in Settings. That removes your account, subscriptions, watchlist and alert history at once.
- Unconfirmed Vendor Watch requests: the confirmation link works for 7 days, and the request is deleted within a day after that.
- Visit statistics: 24 months.
- Contact messages: in our mailbox for as long as we need to deal with your request.
- Tips, feature requests and quiz entries: for as long as they serve the service. Ask us and we remove your details.
- Provider logs: for the short periods each provider sets.
Your rights
You can ask for a copy of your data, have it corrected or deleted, restrict or object to how we use it, and get it in a portable format. Write to contact@threatnoir.com and we will answer within a month. You can also unsubscribe from any email with one click, and delete your account yourself in Settings.
If you think we handle your data wrongly, you can complain to the Swedish Authority for Privacy Protection (IMY) or to the data protection authority where you live.
Security
All traffic is encrypted, and every database table is protected by row-level security. Passwords and API keys are stored only as hashes, and the IP addresses in our own statistics and quiz records only as keyed hashes.
Children
ThreatNoir is not aimed at children under 16, and we don't knowingly collect their data.
Changes to this policy
We change the date at the top whenever this policy changes. For significant changes we will also tell subscribers by email.