What we collect

Your name, email address, and role — used solely for attribution within your threat models. The content of your threat models: data declarations, journey answers, discovery responses, assumptions, and evidence references.

What we don't collect

No analytics. No tracking. No third-party scripts. No advertising identifiers. No behavioural profiling. No cookies beyond session authentication.

Where it's stored

All data is stored on infrastructure operated by us. Your threat model data is never shared with third parties, never used for training, never sold.

Who can see it

Only you and the people you explicitly delegate questions to. Each user's data is isolated. Delegated access is scoped to the specific questions invited.

Browser-only mode

Without an account, all data stays in your browser's session storage. Nothing is sent to our servers. When you close the tab, it's gone.

Deletion

You can delete any system and all its associated data at any time. Deletion is permanent and immediate from primary storage.

Contact

threatmodel.online is a splinters.io project. For privacy enquiries, contact us at [email protected].