Privacy
What this site and the ThreatLens Lookup browser extension do with what you give them. Last changed 2 October 2026.
In short
- Nothing here is sold, and there is no advertising and no tracking of what you do on other sites.
- What you look up is sent to outside threat intelligence sources, because that is how the answers are found.
- What you keep in an account stays in it until you remove it.
The browser extension
The extension adds entries to the right-click menu. It does nothing until you choose one of them. When you do, it opens this site with what you chose in the address: the text you selected, the link you right-clicked, or the name of the site you are on. That is all it sends, and it sends it only here.
It does not read the pages you visit, keep your browsing history, or run in the background collecting anything. The only thing it stores is the address of the ThreatLens site you set in its options, which your browser may sync between your own devices.
Lookups
- An address, domain, link, file hash, email address or vulnerability that you look up is sent to outside sources such as VirusTotal, AbuseIPDB, Cisco Talos and AlienVault OTX. Each source has its own privacy terms. Addresses inside a private network are never sent to anyone.
- A page you open in the sandbox, or a file you upload for analysis, is sent to the scanning services, which may keep it and show it to their other users. Do not upload anything confidential.
- The site records when an indicator was looked up and the verdict it had, to show how that verdict changes over time. The indicator is stored as a one-way hash and the record does not say who looked. Email addresses and leak checks are left out of this record.
- To limit how many lookups one visitor makes, the site counts them against a one-way hash of the visitor's network address, which is dropped within a day.
Accounts
An account holds your name, your email address and a salted hash of your password; the password itself is never stored. It also holds what you put in it: your lookup history, cases and their notes, your watchlist, and your teams with their messages and shared files. Stored encrypted or as hashes: sign-in sessions, API keys, authenticator secrets, the addresses alerts are posted to, and your own keys for the sources.
People in a team with you can see your name and email address, the cases shared with the team, and what you write and share in its chat.
Voice and video calls go directly between the browsers of the people in the call, or through a relay that cannot read them. They are not recorded or stored. The site only passes along the short messages the browsers need to find each other, and deletes them within a minute.
The site emails you a code when you sign up or reset your password, and writes to you when something on your watchlist changes, when you are invited to a team, or when someone mentions you in a team's chat. It sends nothing else.
Cookies
One cookie keeps you signed in. There are no advertising or analytics cookies.
Who else handles the data
The companies that host the site, its database and its outgoing email process the data on the operator's behalf, and the hosting company keeps its own access logs. Beyond them and the sources named above, nothing is shared with anyone.
Removing your data
You can remove lookups, cases, watchlist entries, messages, files, keys and alert channels yourself, in the workspace. To have your whole account deleted, reply to any email this site has sent you and ask.