Privacy Policy
Last updated: April 22, 2026
Threat Block ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-assisted OSINT workspace and related services at app.threatblock.co and threatblock.co.
Information We Collect
Account and profile
When you create an account or use our services, we collect:
- Name, email address, and contact information
- Organization and team details
- Account credentials and profile or notification settings
Case and investigation data
To provide the workspace, we process data you store or generate in Threat Block:
- Case names, notes, tags, and workspace structure you create
- Entities, URLs, identifiers, and files you add to a matter
- Discovery results and enrichments returned from sources you connect or invoke
- Reports, graphs, and exports you generate
Usage and technical data
We automatically collect information necessary to operate and improve the service:
- Log data, device and browser information, IP address
- Usage patterns and feature interactions
- Performance and error data
How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the OSINT workspace and AI features
- Process payments and manage your subscription and investigation credits
- Sync and display data from integrations when you connect them
- Send service-related notifications and support
- Analyze usage to improve the product and security
- Comply with legal obligations
Third-Party Services and Data
We use trusted service providers to run Threat Block. Data may be processed or stored by:
- Supabase — Authentication, database, and storage (see Supabase privacy policy)
- Stripe — Payment and subscription billing (we do not store full card numbers; see Stripe privacy policy)
- Google — On our public website (threatblock.co), we may use Google Analytics to understand traffic and product interest; see our Cookie Policy for how we obtain consent and what is collected.
- AI / LLM providers — Assistant features may involve sending prompts and your content to third-party AI services under our data processing agreements
- Other data providers — When you run discovery or enrichment, relevant request and response data may be processed by those providers under their terms
Data Storage and Security
We implement appropriate technical and organizational measures to protect your data, including encryption in transit and at rest, access controls, and secure infrastructure. We do not sell your personal information.
Data Sharing and Disclosure
We do not sell or rent your personal information. We may share information only:
- With your consent (e.g., when you connect an integration)
- With service providers who assist in operating our service (under strict obligations)
- To comply with law or protect rights and safety
- In connection with a merger, sale, or transfer of assets
Your Rights and Retention
We retain your information as long as needed to provide the service and comply with law. You have the right to:
- Access and correct your personal information
- Request deletion of your personal information
- Export your data in a portable format
- Opt out of marketing communications
- Lodge a complaint with a supervisory authority (e.g., in the EU/UK under GDPR)
If you are in the European Economic Area or UK, our legal basis for processing includes contract performance, consent where required, and legitimate interests. For California residents, we do not sell personal information; you may have additional rights under the CCPA.
Cookies and similar technologies
We use cookies, local storage, and similar technologies in line with this policy and our Cookie Policy.
Threat Block app (app.threatblock.co). We use first-party cookies and storage for authentication (e.g. Supabase session), security, and core product functionality. These are necessary to run the service.
Public marketing site (threatblock.co). When enabled, we load Google Analytics 4 (Google LLC) and use Google Consent Mode: analytics and related storage stay off until you interact with our cookie banner and choose Accept. If you reject or dismiss without accepting, we do not enable optional analytics measurement. Your choice is stored in your browser (e.g. localStorage). Details are in the Cookie Policy.
We do not operate third-party ad networks or sell your data for cross-site advertising on our sites. Accepting analytics on the marketing site uses Google's tags under Consent Mode; that may include consent flags Google associates with measurement (as configured in our implementation), not Threat Block-run retargeting ads.
Contact
For privacy-related requests or questions:
Email: hello@threatblock.co
Website: https://threatblock.co
This Privacy Policy is effective as of April 22, 2026. We may update it from time to time; the current version will always be on this page. Continued use of the service after changes constitutes acceptance.