Privacy
What we hold about you, why we hold it, and how to get it changed or removed.
Effective
This describes how ThreatBharat handles personal data. It is written to be read, not to be survived. If anything here is unclear, ask us at support@threatbharat.com.
Two very different kinds of data
It matters which one you are asking about, because they are governed by different sections of this page.
- Data about you as a user of this site — because you have an account, contacted us, or simply loaded a page. That is covered immediately below.
- Data that appears inside a threat intelligence report — because a threat actor claimed to hold it. That is covered under personal data inside reports, and the rules are different.
If you visit the public site
You do not need an account to read published intelligence, and we do not ask you to create one. We do not use advertising trackers, and we do not sell or share visitor data with data brokers.
Our servers keep short-lived operational logs — the requested address, HTTP status, timing, and a truncated user agent — to keep the service running and to spot abuse. Request logs are configured to exclude credential-bearing headers. These logs rotate and are not used to build a profile of you.
If you have an account
We hold what an account needs to work:
- your email address and display name;
- a cryptographic hash of your password — never the password itself, and not in a form we can reverse;
- multi-factor authentication state, where you have enabled it, and single-use recovery codes stored hashed;
- session records so you can see where you are signed in and revoke a session you do not recognise;
- an authentication and authorisation audit trail — sign-ins, permission denials, and privileged actions — because an intelligence platform that cannot say who did what is not trustworthy.
Accounts are created by an administrator; there is no public self-registration. Access is deny-by-default: you see only what your role permits.
If you contact us
We keep your message and contact details for as long as they are relevant to the enquiry or to a published report they relate to. If you send us intelligence, see source and evidence handling — we do not publish who contacted us, and we can strip your contact details while retaining the substance.
Email we send
We send transactional email only: verification, password reset, invitations, and security notices. There is no marketing list, so there is nothing to unsubscribe from. Our mail is sent over an authenticated connection through our own configured provider.
A password-reset link is built from a single configured site address, never from whatever hostname a request arrived on. That is deliberate: it prevents an attacker from causing you to receive a genuine-looking reset link that points at their server.
Personal data inside reports
A threat actor’s claim may involve data about people. Our approach is that publishing the existence of a claim helps defenders, while republishing the data harms the people in it.
So, as stated in responsible publication:
- we never host, mirror, or link to a breached dataset;
- we do not publish names, contact details, identifiers, account or card numbers, or credentials of affected individuals;
- original screenshot captures are stored privately and are never publicly retrievable — only a separately approved, redacted derivative is ever shown.
If you believe personal data about you appears in a published report, tell us at support@threatbharat.com or through the correction form. We treat these as urgent and assess them ahead of the ordinary queue. You do not need to explain a legal basis to ask.
Who else sees your data
ThreatBharat runs on infrastructure we operate. The parties who necessarily see some data are our hosting provider and our email provider. We do not sell personal data, and we do not share it for advertising.
We may disclose data where we are compelled by a lawful order we cannot resist, or where it is necessary to investigate abuse of the platform.
How long we keep things
- Account records: while the account exists, and briefly afterwards so an accidental deletion can be reversed.
- Security and authorisation audit records: retained after account closure, because they are what makes an access review meaningful.
- Operational logs: short-lived and rotated.
- Correspondence: while relevant to an enquiry or a published report.
Your choices
You can ask us to:
- tell you what we hold about you;
- correct something that is wrong;
- delete your account and the personal data attached to it;
- remove personal data that appears in a published report.
Write to support@threatbharat.com. We will ask enough to be confident you are who you say you are — an intelligence platform that hands over account data to whoever asks is a liability.
Two honest limits. Security audit records are retained even after an account is closed, because deleting them on request would defeat their purpose. And we will not remove an accurate published report about an organisation on the basis that an individual would prefer it were not public — though we will always remove personal data that should not be there.
Security
Secrets are encrypted at rest under a key held only on the server. Traffic is served over HTTPS. Data stores are not reachable from the internet. Access is deny-by-default, and privileged actions require multi-factor authentication and a recent sign-in.
No system is perfect. If you find a weakness in ours, please tell us at security@threatbharat.com — see acceptable use for what testing is and is not welcome.
Changes
If we change how we handle personal data in a way that affects you, we will update this page and say what changed rather than swapping the text silently.