Skip to content

Privacy Policy

Last updated: September 3, 2026

ThreatCluster Ltd ("we", "us", or "our") is committed to protecting your privacy. This policy explains how we collect, use, disclose and safeguard your information when you use threatcluster.io, the ThreatCluster REST API or our feeds (together, the "Service"). It is designed to comply with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

Data Controller
ThreatCluster Ltd, Company No. 17124226
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
Contact: [email protected]

1. Information we collect

Personal data you provide

  • Email address: when you create an account or subscribe to a digest
  • Account information: if you sign in via Auth0, we receive your email and basic profile information
  • Preferences: tracked entities, keywords, custom feeds and alert rules you set to personalise your intelligence
  • Integration endpoints: webhook URLs and similar destinations you configure for alert delivery
  • Payment information: when you buy a subscription or a credit pack, payment details are collected and processed by Stripe. We do not store your full card details.

API keys and usage

  • Key metadata: when you mint an API key we store its identifier, scopes and settings. Treat keys as secrets; they identify your account.
  • Usage records: we record API requests made with your keys (endpoint, timestamp, credit cost, request counts) to meter allowances and credits, enforce rate limits, bill correctly and detect abuse. The same applies to keyed feed URLs.

Information collected automatically

  • Usage data: pages visited, features used and general interaction patterns
  • Device information: browser type, operating system and device type
  • IP address: for security, rate limiting and fraud prevention

The public feeds (RSS, the ransomware feed, the IOC blocklist, MISP) can be consumed without an account; requests to them appear in our server logs like any web request but are not tied to a profile.

2. How we use your information

  • Provide and maintain the Service, including the web platform, API and feeds
  • Personalise your feed and deliver the digests and alerts you configure
  • Meter API allowances and credits, and process payments and subscriptions via Stripe
  • Enforce plan limits and rate limits, and detect and prevent fraud or abuse
  • Communicate with you about service updates
  • Improve and optimise the platform

3. Legal basis for processing (GDPR)

  • Consent: when you subscribe to emails, or accept optional cookie categories
  • Contract: to provide the services you signed up for, including API metering and billing
  • Legitimate interest: to secure the Service, enforce limits and improve the product

4. Third-party services

We use the following processors. We share only the minimum data each needs to provide its service.

Authentication and payments

  • Auth0: authentication and account management. Processes your email and login credentials.
  • Stripe: payment processing for subscriptions and credit packs. Processes your payment method, billing address and transaction details; we do not store your full card number. See Stripe's Privacy Policy.

Analytics and marketing

  • PostHog (analytics, loaded only with your consent): EU-hosted product analytics recording which features you use, page views within the platform and a pseudonymous identifier. We do not send your plaintext email to PostHog — only your account ID and the domain part of your email (e.g. example.com). See PostHog's Privacy Policy.
  • Google Ads / Tag Manager (advertising, loaded only with your consent): conversion tracking to measure ad performance. May track your browsing across sites.
  • Apollo.io (visitor identification, loaded only with your consent): identifies the organisation (and, for U.S. visitors, the individual) visiting our site, sharing visitor data with Apollo and its identity partner LiveIntent. See Apollo's Privacy Policy and LiveIntent's Privacy Policy.
  • Umami Analytics (essential, no consent required): privacy-friendly, cookieless website analytics. Sets no cookies, collects no personal data, anonymises IP addresses. See Umami's Privacy Policy.

Infrastructure and communications

  • Cloudflare: sits in front of the Service for content delivery and DDoS protection, processing visitor IP addresses and request metadata in transit.
  • DigitalOcean: cloud hosting, database and caching infrastructure.
  • Postmark: delivery of digests, alerts and transactional email.
  • OpenAI: AI processing for generating threat summaries. No personal data about you is sent to OpenAI — only public threat reporting.

5. Data retention

  • Email subscriptions: until you unsubscribe
  • Account data: until you delete your account
  • API usage and credit records: while your account is active — they form your billing and allowance record
  • Payment records: as required by law for tax and accounting purposes (typically 7 years)
  • Server and security logs: up to 90 days

When you unsubscribe or delete your account, we delete your personal data within 30 days unless we are required to retain it for legal purposes.

6. Your rights under GDPR

If you are in the European Economic Area (or the UK), you have the right to:

  • Access a copy of the personal data we hold about you
  • Rectify inaccurate data
  • Erase your personal data ("right to be forgotten")
  • Restrict how we process your data
  • Port your data in a structured, machine-readable format
  • Object to processing based on legitimate interests
  • Withdraw consent at any time for consent-based processing

To exercise any of these rights, contact us using the details below. We respond within 30 days.

7. Data security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • Encryption of data in transit (TLS/SSL) and encrypted database connections
  • Scoped, revocable API keys — you can rotate or delete keys at any time from account settings
  • Access controls, authentication and rate limiting
  • Regular security assessments

No method of transmission over the Internet is 100% secure; while we strive to protect your data, we cannot guarantee absolute security. If you believe an API key has been compromised, rotate it immediately and contact us.

8. International data transfers

Your data may be transferred to and processed in countries outside your country of residence, including the United States. When we transfer data outside the EEA or UK, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions.

9. Cookies and tracking

  • Essential cookies: authentication, session management and core functionality. These cannot be disabled. Includes a cookieless first-party analytics tool (Umami) that sets no cookies and collects no personal data.
  • Analytics (requires consent): PostHog product analytics. A first-party cookie tc_aid (a random identifier, no personal data, 2-year lifetime) plus PostHog's own ph_-prefixed cookies measure how the platform is used. Loaded only after you consent to the "Analytics" category.
  • Advertising (requires consent): Google Ads conversion tracking, loaded via Google Tag Manager. May track your browsing across sites. Loaded only after you consent to the "Advertising" category.
  • Visitor identification (requires consent): Apollo.io and its partner LiveIntent identify the organisation — and, for U.S. visitors, the individual — visiting our site, and share that data with those providers. Loaded only after you consent to the "Visitor identification" category.

When you first visit, a consent banner lets you Accept all, Reject all or Manage each category individually. Nothing in the Analytics, Advertising or Visitor-identification categories loads until you consent to it. You can change or withdraw your choices at any time using the link, or through your browser settings. For more about Google's privacy practices, see Google's Privacy Policy.

The API itself sets no cookies: keyed requests are authenticated by the key alone.

10. Children's privacy

The Service is not intended for individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, contact us immediately and we will delete it.

11. Changes to this policy

We may update this Privacy Policy from time to time. We will post material changes on this page with a new "Last updated" date, and for significant changes we may also notify you by email if you have an account.

12. Contact us

If you have questions about this policy or wish to exercise your data rights, reach us via the contact page or at [email protected].

If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.