Overview

ThreatBook ATI is a professional cyber threat intelligence platform designed for security analysts, SOC teams, threat hunters, incident responders, and cybersecurity researchers. Our application enables users to search and analyze threat intelligence for IP addresses, domains, file hashes, and vulnerabilities (CVEs).

By downloading, installing, or using ThreatBook ATI, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree, please discontinue use of the application.

Scope: This policy applies to the ThreatBook ATI mobile application (iOS and Android), our API services, and any related support communications. It does not apply to third-party websites or services that may be linked from within the application.

Data We Collect

We collect the following categories of information when you use ThreatBook ATI:

2.1 Account Information

  • Email address (if you register an account or contact us)
  • Username or display name (if provided)
  • Authentication credentials (stored in encrypted form)
  • Account preferences and settings

2.2 Search & Query Data

  • Threat intelligence queries submitted (IP addresses, domains, file hashes, CVE identifiers)
  • Search history and timestamps
  • Saved or bookmarked indicators

Search queries may contain security indicators (such as IP addresses or file hashes). We treat this data with high sensitivity and use it solely for service delivery, security analytics, and product improvement.

2.3 Device & Technical Information

  • Device type, model, and operating system version
  • Application version and build number
  • IP address of the device accessing our services
  • Unique device identifiers (e.g., device ID, advertising ID)
  • Language and regional settings
  • Crash logs and error reports

2.4 Usage Analytics

  • Features accessed and frequency of use
  • Session duration and activity patterns
  • In-app navigation and interaction events
  • Performance metrics and loading times

2.5 Notification Preferences

  • Push notification opt-in status
  • Alert preferences for threat reports and vulnerability notifications
Category Collected Required
Account InformationWhen registeringFor account features
Search QueriesDuring useCore service delivery
Device IdentifiersAutomaticallySecurity & analytics
Usage AnalyticsAutomaticallyProduct improvement
Push PreferencesOn permission grantAlerts & notifications

How We Use Your Data

We use the information we collect for the following purposes:

3.1 Service Delivery

  • Processing and responding to threat intelligence search queries
  • Delivering real-time threat alerts, vulnerability notifications, and threat reports
  • Providing access to threat actor profiles and intelligence databases
  • Authenticating users and maintaining account security

3.2 Product Improvement

  • Analyzing usage patterns to identify performance bottlenecks and bugs
  • Understanding feature adoption to prioritize development
  • Conducting A/B testing and feature experimentation

3.3 Security & Integrity

  • Detecting, investigating, and preventing fraudulent or unauthorized activity
  • Protecting the integrity of our threat intelligence platform
  • Monitoring for abuse of API access or search services

3.4 Communications

  • Sending critical security alerts and vulnerability notifications (with your consent)
  • Delivering service announcements and policy updates
  • Responding to customer support inquiries

3.5 Legal Compliance

  • Complying with applicable laws, regulations, and legal process
  • Enforcing our Terms of Service and User Agreement

We rely on the following legal bases for processing under the Singapore Personal Data Protection Act (PDPA) and other applicable data protection frameworks: consent, performance of a contract, legitimate interests, and legal obligation.

Data Sharing

We do not sell, rent, or trade your personal data to third parties. We may share data in the following limited circumstances:

4.1 Service Providers

We engage trusted third-party vendors to support our operations, including cloud infrastructure providers, analytics platforms, and push notification services. These providers are contractually bound to process data only on our behalf and in accordance with this policy.

4.2 Legal Requirements

We may disclose information when required by law, court order, governmental authority, or to protect the rights, property, or safety of ThreatBook, our users, or the public.

4.3 Business Transfers

In the event of a merger, acquisition, or sale of all or a portion of our assets, personal data may be transferred as part of the transaction. We will notify users of any such change in data controller.

4.4 Aggregated & De-identified Data

We may share aggregated, anonymized, or de-identified data that cannot reasonably be used to identify any individual, for research, industry reporting, or product benchmarking purposes.

We will never sell your personal data. Any sharing with third parties is limited to operational necessity and subject to strict data processing agreements.

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes described in this policy, or as required by applicable law. Our standard retention periods are:

Data Type Retention Period
Account informationDuration of account + 12 months
Search query logs12 months from query date
Device & analytics data24 months from collection
Crash logs & error reports90 days
Support communications36 months from last contact
Legal hold dataAs required by law or court order

Upon account deletion or expiration of the applicable retention period, personal data will be securely deleted or anonymized from our active systems. Backup systems may retain data for up to an additional 90 days before permanent deletion.

Data Security

As a cybersecurity company, we apply industry-leading security measures to protect your personal data:

  • All data transmissions are encrypted using TLS 1.2 or higher
  • Data at rest is encrypted using AES-256 encryption
  • Access to personal data is restricted to authorized personnel on a need-to-know basis
  • We conduct regular security assessments and penetration testing
  • Multi-factor authentication is enforced for administrative access
  • Security incident response procedures are maintained and regularly tested

While we employ robust security measures, no method of electronic transmission or storage is 100% secure. We encourage users to maintain strong, unique passwords and enable available security features.

In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected users and relevant regulatory authorities in accordance with applicable legal requirements.

International Data Transfers

ThreatBook ATI is operated by THREATBOOK PTE. LTD., headquartered in Singapore. Your data may be processed and stored on servers located in Singapore and other jurisdictions where our service providers operate, including but not limited to Asia-Pacific regions.

When transferring personal data across borders, we ensure appropriate safeguards are in place, including contractual clauses and compliance with the Singapore PDPA's transfer limitation obligations. By using our services, you acknowledge that your information may be transferred to and processed in countries outside your country of residence.

Your Rights

Subject to applicable law, you have the following rights regarding your personal data:

8.1 Access

You may request a copy of the personal data we hold about you.

8.2 Correction

You may request correction of inaccurate or incomplete personal data.

8.3 Deletion

You may request deletion of your personal data, subject to our legal obligations and legitimate business interests. Account deletion can be initiated from within the application or by contacting us.

8.4 Withdrawal of Consent

Where processing is based on your consent, you may withdraw consent at any time without affecting the lawfulness of prior processing. Note that withdrawal may limit your ability to use certain features.

8.5 Data Portability

Where technically feasible, you may request your personal data in a structured, commonly used, machine-readable format.

8.6 Objection to Processing

You may object to processing based on legitimate interests, particularly for direct marketing purposes. Objecting to marketing will be honored immediately.

To exercise any of these rights, please contact us at app@threatbook.cn. We will respond to verified requests within 30 calendar days. We may require identity verification before processing certain requests.

Children's Privacy

ThreatBook ATI is intended exclusively for professional use by security analysts, IT professionals, and other adults. Our services are not directed at children under the age of 18 (or the applicable age of digital consent in your jurisdiction).

We do not knowingly collect personal data from minors. If we become aware that we have inadvertently collected data from a person under the relevant age of consent, we will take prompt steps to delete that information. If you believe a minor has provided us with personal data, please contact us immediately.

Third-Party Services

ThreatBook ATI may display links to or integrate with third-party threat intelligence feeds, external reports, and research sources. This Privacy Policy does not govern the data practices of such third parties.

We use limited third-party services to support our platform operations, including:

  • Cloud infrastructure and content delivery networks
  • Mobile analytics platforms (for crash reporting and performance monitoring)
  • Push notification delivery services

Each third-party service provider is selected based on their data protection practices and is bound by contractual data processing agreements. We encourage you to review the privacy policies of any third-party services you access through our application.

Policy Changes

We may update this Privacy Policy from time to time to reflect changes in our data practices, legal requirements, or service offerings. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this document
  • Display an in-app notification for significant changes
  • Request renewed consent where required by law

Your continued use of ThreatBook ATI after the effective date of any changes constitutes your acceptance of the updated policy. We encourage you to review this policy periodically.

Contact Us

For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact our Data Protection team:

Company
THREATBOOK PTE. LTD.
Phone
Address
12 Marina View, #11-01 Asia Square Tower 2, Singapore 018961

If you are not satisfied with our response to your request, you have the right to lodge a complaint with the Personal Data Protection Commission (PDPC) of Singapore at www.pdpc.gov.sg.