Privacy Policy
How Meekware LLC handles the small amount of personal data ThreatLoops needs to work. Written to be read, not skimmed past.
Last updated 7 August 2026
The short version
ThreatLoops reads public sources and matches them against a list of technology you type in. It has no agent, no scanner, and no connection into your environment. The most sensitive thing we hold is your email address and the list of products you say you run.
What we collect
Account data:
- your email address, used to sign you in with a magic link and to send service notices
- your workspace mode (solo, team or MSP), role and organisation type from onboarding
- your interests and notification preferences
Product data you enter:
- the vendors, products and versions in your stack, and versions or end-of-support slugs where you provide them
- client workspace names and industries, if you use MSP mode
- team membership, if you invite colleagues
- which items you have saved, read, or added to a CVE watchlist
Technical data: standard server logs generated when your browser requests a page, including IP address and user agent, kept short-term for security and debugging.
Billing data: Paddle.com, our reseller and Merchant of Record, holds your payment details and billing address. We receive only a customer reference, your plan, its status and renewal date. We never see card numbers.
What we deliberately do not collect
- no network, endpoint, log or telemetry data from your environment
- no agent, connector or scanner installed anywhere
- no credentials for your SaaS or infrastructure vendors
- no customer or employee records belonging to you or your clients
A client workspace in MSP mode is a name, an industry and a list of products. Nothing about that client's actual systems reaches us.
Why we process it
To provide the service you asked for: authenticating you, matching advisories and vulnerabilities to your stack, showing vendor status, and producing your daily brief. To bill you for a subscription you chose. To keep the service secure and diagnose faults. To send service and billing notices, which you cannot opt out of while you hold an account.
We do not sell personal data, and we do not use your stack to target advertising.
Who processes data on our behalf
- our cloud hosting and managed database provider, which stores the account and product data described above
- Paddle.com Market Limited, acting as Merchant of Record for the sale of our subscriptions — payments, subscription management, tax compliance and invoicing
- our email delivery provider, for sign-in links and service notices
- an AI model provider, used to summarise public advisories (see the next section)
Each is bound by contract to process data only on our instructions. The current list is maintained on the security page.
AI processing
We use AI models to write the plain-English explanations attached to advisories and vulnerabilities. What is sent to the model is public source material — advisory text, CVE descriptions, headlines. Your email address, your stack, your client names and your team membership are not sent to the model, and nothing you enter is used to train it.
Cookies and analytics
We use a session cookie and browser local storage to keep you signed in and to remember interface preferences such as your workspace mode and dismissed tips. These are strictly necessary for the product to function.
We do not currently run third-party advertising or cross-site tracking. If we add product analytics we will update this section before turning it on.
How long we keep things
- account, stack, client and preference data: for as long as your account exists
- items you saved or marked read: kept while your account exists, and exempt from the routine cleanup below
- unsaved intelligence in the shared catalogue: articles are cleared after about 30 days, vendor status history after about 90 days, and lower-severity vulnerability records after two years — known exploited vulnerabilities are kept indefinitely
- server logs: short-term, for security and debugging
- billing records: retained by Paddle as long as tax law requires
After you close your account we delete your personal data within 30 days.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, or stop processing it. Email support@threatloops.com and we will respond within 30 days. Depending on where you live you may also have the right to complain to your data protection authority.
Most of it is self-serve already: your stack, clients, preferences and saved items are editable in the app, and closing your account removes them.
US state privacy rights
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have never done either, so there is nothing for you to opt out of.
If you live in California, Virginia, Colorado, Connecticut, Utah, Texas or another state with a comprehensive privacy law, you can ask us to:
- confirm whether we process your personal information and give you a copy of it
- correct inaccurate personal information
- delete your personal information
- opt out of any sale, sharing, or targeted advertising — none of which we do
Email support@threatloops.com from the address on the account with "Privacy request" in the subject. We verify the request by confirming control of that mailbox and respond within 45 days. You may use an authorised agent. We will never deny service, change prices, or degrade the product because you exercised a privacy right.
We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects. The matching and scoring in the product ranks public advisories against a stack you typed in; it makes no decision about you.
International transfers and children
Our infrastructure providers may process data in the United States and the European Union. Transfers rely on the standard contractual protections offered by those providers.
ThreatLoops is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children.
Changes and contact
If this policy changes materially we will tell you by email or in-app before the change takes effect.
Privacy questions and requests: support@threatloops.com.