04 — Privacy

What we keep, and why.

Short, because there is not much to say. We hold what the desk needs to work, and nothing we could sell.

Last updated: 2026-09-24

01

What we collect

Three things, and nothing else:

  • Your account. Your email address and display name, passed to us by After Dark Systems single sign-on (Authentik) when you sign in. We never see or store your password.
  • Your case data. Whatever you put on the desk — indicators, files, SBOMs, notes, assets, and the cases that hold them.
  • Usage logs. Request timestamps, route, tenant, and outcome. We keep them to run the service, investigate abuse, and answer “what happened” when something breaks.

02

Where it goes

Billing is handled by the After Dark billing platform at billing.afterdarksys.com, which uses Stripe as its payment processor. ThreatDefense never stores your card details; it stores only whether your plan is active.

When you ask the AI analyst a question, the case context needed to answer it is sent to the model provider configured for the deployment. Threat lookups are resolved against DarkAPI. We do not sell your data, we do not share it with advertisers, and we do not use your case data to train models.

03

How long we keep it

Case data, assets, and archives are retained for as long as your plan is active, under the retention limits of that plan. Cancel and your data stays available through the end of the paid period; after that it is deleted on our normal deletion cycle. Ask us to delete it sooner and we will. Usage logs are kept on a shorter, rolling window.

04

Your say

Write to support@afterdarksys.com to see what we hold about you, correct it, export it, or have it deleted. One address, a real person reads it.

05

Governing law

ThreatDefense.ai is operated by After Dark Systems LLC. This policy is governed by the laws of the State of New York.