Data Retention & Deletion Policy

Last updated: November 29, 2025

1. Purpose

This Policy explains how long ThreatSpot AI keeps different types of data and how you can request deletion.

2. Retention Periods

  • Account data: while your account is active and for a limited period afterward, as required for legal and accounting purposes.
  • Scan logs and consent records: typically up to one (1) year, unless subject to forensic preservation or legal hold.
  • Billing data: as required by tax and financial record‑keeping laws.

3. Legal Holds & Forensic Preservation

We may preserve certain data beyond normal retention periods when needed for investigations, disputes, or legal requests.

4. User‑Initiated Deletion

You can request deletion of your personal data and scan history using the in‑product "Delete All Data" process or by contacting privacy@threatspot.ai. Some data may be kept where we are legally required to do so.

5. Aggregated & Anonymized Data

We may keep aggregated or anonymized data that no longer identifies you to help improve and operate the Services.