Privacy Policy
Privacy Policy
THREATBOOK PTE. LTD. ("ThreatBook", "we", "our", or "us") is committed to protecting your personal data.
This Privacy Policy explains how we collect, use, store, and share information when you use the
ThreatBook ATI mobile application and related services.
ThreatBook ATI is a professional cyber threat intelligence platform designed for security analysts,
SOC teams, threat hunters, incident responders, and cybersecurity researchers. Our application enables
users to search and analyze threat intelligence for IP addresses, domains, file hashes, and vulnerabilities (CVEs).
By downloading, installing, or using ThreatBook ATI, you acknowledge that you have read, understood,
and agree to be bound by this Privacy Policy. If you do not agree, please discontinue use of the application.
Scope: This policy applies to the ThreatBook ATI mobile application (iOS and Android),
our API services, and any related support communications. It does not apply to third-party websites or services
that may be linked from within the application.
We collect the following categories of information when you use ThreatBook ATI:
2.1 Account Information
- Email address (if you register an account or contact us)
- Username or display name (if provided)
- Authentication credentials (stored in encrypted form)
- Account preferences and settings
2.2 Search & Query Data
- Threat intelligence queries submitted (IP addresses, domains, file hashes, CVE identifiers)
- Search history and timestamps
- Saved or bookmarked indicators
Search queries may contain security indicators (such as IP addresses or file hashes). We treat this data with
high sensitivity and use it solely for service delivery, security analytics, and product improvement.
2.3 Device & Technical Information
- Device type, model, and operating system version
- Application version and build number
- IP address of the device accessing our services
- Unique device identifiers (e.g., device ID, advertising ID)
- Language and regional settings
- Crash logs and error reports
2.4 Usage Analytics
- Features accessed and frequency of use
- Session duration and activity patterns
- In-app navigation and interaction events
- Performance metrics and loading times
2.5 Notification Preferences
- Push notification opt-in status
- Alert preferences for threat reports and vulnerability notifications
| Category |
Collected |
Required |
| Account Information | When registering | For account features |
| Search Queries | During use | Core service delivery |
| Device Identifiers | Automatically | Security & analytics |
| Usage Analytics | Automatically | Product improvement |
| Push Preferences | On permission grant | Alerts & notifications |
We use the information we collect for the following purposes:
3.1 Service Delivery
- Processing and responding to threat intelligence search queries
- Delivering real-time threat alerts, vulnerability notifications, and threat reports
- Providing access to threat actor profiles and intelligence databases
- Authenticating users and maintaining account security
3.2 Product Improvement
- Analyzing usage patterns to identify performance bottlenecks and bugs
- Understanding feature adoption to prioritize development
- Conducting A/B testing and feature experimentation
3.3 Security & Integrity
- Detecting, investigating, and preventing fraudulent or unauthorized activity
- Protecting the integrity of our threat intelligence platform
- Monitoring for abuse of API access or search services
3.4 Communications
- Sending critical security alerts and vulnerability notifications (with your consent)
- Delivering service announcements and policy updates
- Responding to customer support inquiries
3.5 Legal Compliance
- Complying with applicable laws, regulations, and legal process
- Enforcing our Terms of Service and User Agreement
We rely on the following legal bases for processing under the Singapore Personal Data Protection Act (PDPA)
and other applicable data protection frameworks: consent, performance of a contract,
legitimate interests, and legal obligation.
We do not sell, rent, or trade your personal data to third parties. We may share data in the following
limited circumstances:
4.1 Service Providers
We engage trusted third-party vendors to support our operations, including cloud infrastructure providers,
analytics platforms, and push notification services. These providers are contractually bound to process
data only on our behalf and in accordance with this policy.
4.2 Legal Requirements
We may disclose information when required by law, court order, governmental authority, or to protect
the rights, property, or safety of ThreatBook, our users, or the public.
4.3 Business Transfers
In the event of a merger, acquisition, or sale of all or a portion of our assets, personal data may
be transferred as part of the transaction. We will notify users of any such change in data controller.
4.4 Aggregated & De-identified Data
We may share aggregated, anonymized, or de-identified data that cannot reasonably be used to identify
any individual, for research, industry reporting, or product benchmarking purposes.
We will never sell your personal data. Any sharing with third parties is limited to
operational necessity and subject to strict data processing agreements.
We retain personal data only for as long as necessary to fulfill the purposes described in this policy,
or as required by applicable law. Our standard retention periods are:
| Data Type |
Retention Period |
| Account information | Duration of account + 12 months |
| Search query logs | 12 months from query date |
| Device & analytics data | 24 months from collection |
| Crash logs & error reports | 90 days |
| Support communications | 36 months from last contact |
| Legal hold data | As required by law or court order |
Upon account deletion or expiration of the applicable retention period, personal data will be
securely deleted or anonymized from our active systems. Backup systems may retain data for up to
an additional 90 days before permanent deletion.
As a cybersecurity company, we apply industry-leading security measures to protect your personal data:
- All data transmissions are encrypted using TLS 1.2 or higher
- Data at rest is encrypted using AES-256 encryption
- Access to personal data is restricted to authorized personnel on a need-to-know basis
- We conduct regular security assessments and penetration testing
- Multi-factor authentication is enforced for administrative access
- Security incident response procedures are maintained and regularly tested
While we employ robust security measures, no method of electronic transmission or storage is 100%
secure. We encourage users to maintain strong, unique passwords and enable available security features.
In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected
users and relevant regulatory authorities in accordance with applicable legal requirements.
ThreatBook ATI is operated by THREATBOOK PTE. LTD., headquartered in Singapore. Your data may be
processed and stored on servers located in Singapore and other jurisdictions where our service
providers operate, including but not limited to Asia-Pacific regions.
When transferring personal data across borders, we ensure appropriate safeguards are in place,
including contractual clauses and compliance with the Singapore PDPA's transfer limitation obligations.
By using our services, you acknowledge that your information may be transferred to and processed in
countries outside your country of residence.
Subject to applicable law, you have the following rights regarding your personal data:
8.1 Access
You may request a copy of the personal data we hold about you.
8.2 Correction
You may request correction of inaccurate or incomplete personal data.
8.3 Deletion
You may request deletion of your personal data, subject to our legal obligations and legitimate
business interests. Account deletion can be initiated from within the application or by contacting us.
8.4 Withdrawal of Consent
Where processing is based on your consent, you may withdraw consent at any time without affecting the
lawfulness of prior processing. Note that withdrawal may limit your ability to use certain features.
8.5 Data Portability
Where technically feasible, you may request your personal data in a structured, commonly used,
machine-readable format.
8.6 Objection to Processing
You may object to processing based on legitimate interests, particularly for direct marketing purposes.
Objecting to marketing will be honored immediately.
To exercise any of these rights, please contact us at app@threatbook.cn.
We will respond to verified requests within 30 calendar days. We may require identity
verification before processing certain requests.
ThreatBook ATI is intended exclusively for professional use by security analysts, IT professionals,
and other adults. Our services are not directed at children under the age of 18 (or the applicable
age of digital consent in your jurisdiction).
We do not knowingly collect personal data from minors. If we become aware that we have inadvertently
collected data from a person under the relevant age of consent, we will take prompt steps to delete
that information. If you believe a minor has provided us with personal data, please contact us immediately.
ThreatBook ATI may display links to or integrate with third-party threat intelligence feeds,
external reports, and research sources. This Privacy Policy does not govern the data practices
of such third parties.
We use limited third-party services to support our platform operations, including:
- Cloud infrastructure and content delivery networks
- Mobile analytics platforms (for crash reporting and performance monitoring)
- Push notification delivery services
Each third-party service provider is selected based on their data protection practices and is
bound by contractual data processing agreements. We encourage you to review the privacy policies
of any third-party services you access through our application.
We may update this Privacy Policy from time to time to reflect changes in our data practices,
legal requirements, or service offerings. When we make material changes, we will:
- Update the "Last Updated" date at the top of this document
- Display an in-app notification for significant changes
- Request renewed consent where required by law
Your continued use of ThreatBook ATI after the effective date of any changes constitutes your
acceptance of the updated policy. We encourage you to review this policy periodically.
For any questions, concerns, or requests regarding this Privacy Policy or your personal data,
please contact our Data Protection team:
If you are not satisfied with our response to your request, you have the right to lodge a complaint
with the Personal Data Protection Commission (PDPC) of Singapore at
www.pdpc.gov.sg.