Privacy

Preliminary notice. This is a plain-language description of current data handling, not a complete or counsel-reviewed privacy policy, and not legal advice. It may change as the service develops.

What we process

ThreatDossier aggregates and analyzes publicly available threat-intelligence sources (government advisories, news, and openly-posted social/leak-site material). That material can incidentally contain personal data — including names and, in some contexts, IP addresses, which may themselves be personal data. Source text is processed by automated systems (including AI models, routed via Cloudflare AI Gateway) before publication.

Redaction and review

Before an item is published we apply automated redaction of detected structured personal data (emails, phone numbers, national IDs, payment cards) and mask personal names except from official government/court sources. Redaction is automated and best-effort — it may be incomplete or over-broad. Automated risk reviews decide whether an item is published, hedged as unverified, or withheld.

Retention

Feed items and derived analysis are retained for a bounded window (on the order of weeks) and then pruned; derived rows (enrichment, translations, screenshots, vectors, dossiers) are removed with their source item. Upstream AI Gateway request/response logs may be retained separately under Cloudflare's controls.

Corrections and removal

To request a correction or removal, email corrections@threatdossier.com with the URL or indicator in question. We will review requests and remove or correct published material and its derivatives where appropriate. Because sources are re-fetched, a corrected upstream record is the most durable fix.