Last updated: September 26, 2026
ThreatWire collects the following information to provide network security monitoring services:
ML identifiers are protected with HMAC-SHA256; security telemetry may retain raw IP addresses for investigation and threat detection. Connections to ThreatWire use encryption in transit. Database access is restricted and monitored.
DNS queries are pruned after 7 days. ML observations without a user ID are pruned after 24 hours; observations associated with a user ID, alerts, and notifications are pruned after 30 days. API usage and audit logs are pruned after 90 days. Cleanup runs periodically, so deletion may not be immediate. Account data is retained until you delete your account.
You have the right to access, export, or delete your data at any time through the Settings page or by contacting us.
For privacy-related questions, reach out to us at privacy@threatwire.app