Privacy Policy
1. Introduction
This Privacy Policy explains how Theron ("we," "us," or "our"), operated at theronai.io, collects, uses, stores, and shares information when you use our Service. By using the Service, you agree to the practices described in this policy.
2. Information We Collect
2.1 Information You Provide Directly
- Account information: display name, email address, password (stored as a bcrypt hash — we never store your plain-text password)
- Profile information: experience level, SIEM/EDR environment details, organization name, timezone, escalation style preferences, interaction style preferences
- Investigation content: messages, alert descriptions, log snippets, and other content you submit during AI coaching sessions
- Shared organization content: escalation reports, shift handoff notes, false positive library entries, query library entries, SOP library entries
- Training activity: scenario attempts, responses, and IR debrief content
2.2 Information Collected Automatically
- Session data: login timestamps, session duration, inactivity tracking for automatic timeout
- Usage data: features accessed, pages visited, metrics related to analyst activity (investigations opened, escalations drafted, etc.)
- Error logs: application errors logged for debugging and service improvement
- IOC lookup activity: indicators of compromise submitted for lookup via integrated threat intelligence services
2.3 Information We Do Not Collect
We do not collect payment information directly (any future billing will be handled by a third-party payment processor). We do not collect classified information, and our Terms of Service prohibit submission of sensitive regulated data such as PII, PHI, or payment card data.
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service
- Authenticate your identity and manage your account and session
- Personalize the AI coaching experience based on your profile, environment, and preferences
- Enable organization and team collaboration features
- Track analyst metrics and provide performance insights
- Respond to support requests and communicate with you about your account
- Monitor for abuse, security incidents, and Terms of Service violations
- Improve and develop the Service based on usage patterns and feedback
- Comply with legal obligations
4. How We Share Your Information
We do not sell your personal information. We share information only in the following circumstances:
4.1 Within Your Organization
Content submitted to shared organization resources (escalation reports, handoff notes, shared libraries) is visible to other members of your organization on Theron. Your display name and experience level are visible to your organization's Manager(s).
4.2 Third-Party Service Providers
We use the following third-party services to operate the platform:
- Anthropic — AI model provider. Investigation messages and coaching content are sent to Anthropic's API to generate responses. Anthropic's privacy policy applies to data processed through their API.
- Render — Cloud hosting provider. Your data is stored on servers managed by Render.
- PostgreSQL (via Render) — Database hosting for all stored user and organization data.
- SendGrid — Email delivery for account verification and transactional emails.
- VirusTotal — IOC lookup for IP addresses, domains, URLs, and file hashes you submit for analysis.
- AbuseIPDB — IOC lookup for IP address reputation checks.
- URLScan.io — IOC lookup for URL and domain analysis.
- MalwareBazaar — IOC lookup for file hash analysis.
When you submit an indicator of compromise for lookup, that indicator is sent to the relevant third-party service. Do not submit sensitive or confidential indicators that you are not authorized to share with external services.
4.3 Legal Requirements
We may disclose information if required to do so by law, court order, or governmental authority, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
4.4 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change via email or a prominent notice on the Service.
5. Data Retention
We retain your account and profile data for as long as your account is active. Investigation content, chat history, and shared organization data are retained to provide the Service and may be retained for a reasonable period after account termination for backup and legal compliance purposes.
You may request deletion of your account and associated data by contacting us at support@theronai.io.
6. Data Security
We implement reasonable technical and organizational security measures to protect your data, including:
- Passwords hashed using bcrypt
- HTTPS enforced for all connections
- CSRF protection on all mutating operations
- Session management with inactivity timeouts
- Rate limiting on authentication endpoints
- Regular security audits
No method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security but are committed to maintaining appropriate safeguards.
7. Demo Mode
Theron offers a demo mode accessible at theronai.io/demo. The demo uses a shared demo account with pre-seeded sample data. Do not submit real, sensitive, or confidential information in demo mode. Demo sessions are isolated and limited to 10 messages. Data submitted in demo mode may be reset at any time.
8. Children's Privacy
The Service is not directed at children under the age of 18. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal information, contact us at support@theronai.io and we will take steps to delete it.
9. Your Rights and Choices
Depending on your location, you may have certain rights regarding your personal information, including the right to:
- Access the personal information we hold about you
- Correct inaccurate information in your account (via the Settings page)
- Request deletion of your account and associated data
- Object to certain processing of your data
To exercise any of these rights, contact us at support@theronai.io. We will respond within a reasonable timeframe.
10. Cookies and Local Storage
The Service uses session cookies for authentication and maintaining your logged-in state. We do not use third-party tracking cookies or advertising cookies. We do not use browser local storage for persistent data.
11. Third-Party Links
The Service may contain links to external resources such as MITRE ATT&CK, CISA KEV, and threat intelligence feeds. This Privacy Policy does not apply to those external sites. We encourage you to review the privacy policies of any third-party sites you visit.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or a prominent notice on the Service. The "Last Updated" date at the top of this policy reflects the most recent revision. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.
13. Governing Law
This Privacy Policy is governed by the laws of the State of North Carolina, USA.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy, contact us at:
Email: support@theronai.io
Website: theronai.io