Themis Privacy Notice
This notice explains what data Themis ("Themis", "we", "us") collects when you use themislabs.ai and the Themis API, why we collect it, who we share it with, and the choices you have. Themis is operated by Themis Security Labs Limited, The L. Plaza, 367 - 375 Queen's Road Central, Sheung Wan, Hong Kong.
If anything here is unclear, or you want to exercise any right described below, email us at [email protected].
1. Scope
This notice covers:
- the public website at themislabs.ai: company and product pages (AI Agent Security Assessment, RedSwarm, Themis Agent Intelligence, Continuous Agent Validation, Web3 Security), research publications, and the Web3 tools (scan tool, approvals checker, dashboard)
- the forms on those pages: contact and inquiry forms, the AI agent support check, Agent Intelligence pilot requests, protocol workspace inquiries, and the monitoring waitlist
- the Themis API that powers those pages
- email correspondence with [email protected], including RedSwarm assessment requests, which are made by email
It does not cover third-party sites we link to (block explorers such as Etherscan, social profiles, GitHub). Those sites have their own privacy policies.
It also does not cover data handled during a commissioned security engagement (for example an AI Agent Security Assessment, RedSwarm testing, Continuous Agent Validation, an Agent Intelligence pilot, or a Web3 audit). Access to, retention of, and handling of customer data in an engagement are defined in the engagement documents.
2. What we collect
We only collect data you give us, data that is technically necessary to run and protect the service, and a small set of first-party product-usage events described below. We do not run third-party analytics, advertising trackers, or session-recording tools.
2.1 Data you submit
| Where | What we collect |
|---|---|
| Contact / lead forms (including Agent Intelligence pilot requests) | Name, email address, role, protocol or project name, and your free-text message |
| AI agent support check | Name, company, work email, agent description, tool-calling method, test-environment availability, and approximate number of tools or integrations |
| Protocol workspace inquiry | Name, email, Telegram or X handle, protocol name, website URL, chain, contract address, project stage, notes, tier of interest, and (optionally) a wallet address you verify by signature |
| Monitoring waitlist | Email address, the protocol address and chain you want monitored, and your selected alert event classes |
| Scan search | The protocol name or contract address you type into the scan box |
| Approvals checker | The wallet address you enter (yours or any address you choose to look up) |
Free-text fields are stored as you write them: please do not include sensitive personal information (health, financial account numbers, government IDs) in messages or notes.
2.2 Wallet and blockchain data
If you connect a wallet, we collect your wallet address and a one-time cryptographic signature used to prove you control it. We never receive or store your private key or seed phrase, and connecting never triggers a transaction.
Your wallet address is a persistent pseudonymous identifier. While connected, it is linked to your scan history, saved reports, purchases, subscription status, and product analytics events.
If you pay for a service on-chain, the transaction (wallet address, transaction hash, amount, chain) is recorded both in our database and permanently on the public blockchain. We cannot alter or delete blockchain records.
2.3 Data collected automatically
- IP address: used to rate-limit free scans and protect the service from abuse. We do not store your raw IP address in our application database. It is used transiently in memory, and where a record is kept (trial scans, product analytics events, workspace inquiries) we store only a salted, daily-rotating one-way hash of it, which we cannot reverse back into your IP. Workspace inquiries also record your browser's user-agent string.
- Server and edge logs: our web server and our CDN provider (Cloudflare) keep standard access logs (IP address, user-agent, requested URL, referrer, timestamp) for security and debugging. These are short-lived and rotated automatically.
- First-party product analytics: we record a small set of in-product events (for example "monitoring interest clicked", "report exported"), together with the related scan ID, your wallet address if connected, and a hashed form of your IP address. These events go only to our own servers.
2.4 Cookies and local storage
We do not set cookies for tracking or advertising. Our CDN provider (Cloudflare) may set strictly necessary security cookies (such as __cf_bm) to distinguish humans from bots.
We use your browser's local storage for functionality only:
| Key | Purpose | Lifetime |
|---|---|---|
themis_token | Keeps you signed in after wallet authentication (a token valid for 24 hours) | Until sign-out, token expiry, or you clear browser data |
themis_scan_email | Pre-fills the email you entered for monitoring alerts | Until you clear browser data |
themis_approvals_wallet | Remembers the last wallet address you checked in the approvals tool | Until you clear browser data |
You can remove these at any time via your browser's site-data settings.
3. Why we process your data (legal bases)
We process personal data in accordance with the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO"): we collect it for the lawful purposes described in this notice, by fair means, and we use it only for those purposes or directly related ones unless you consent otherwise.
Where the EU/UK GDPR applies to you, we rely on the following legal bases:
| Purpose | Data | Legal basis |
|---|---|---|
| Providing scans, reports, dashboards, and wallet-authenticated features | Wallet address, scan inputs, report history | Performance of a contract (or steps prior to a contract) |
| Responding to contact-form and inquiry submissions | Name, email, handles, message content | Performance of a contract / legitimate interest in responding to you |
| Reviewing AI agent support-check submissions and replying with a support determination | Name, company, work email, agent description, and technical qualification answers | Steps requested before entering a contract / legitimate interest in responding to your request |
| Notifying you when monitoring launches | Waitlist email | Consent (you can withdraw at any time) |
| Rate limiting, abuse prevention, and security | IP address, user-agent, access logs | Legitimate interest in protecting the service |
| Understanding product usage (first-party analytics) | Event type, scan ID, wallet, hashed IP | Legitimate interest in improving the service |
| Processing and evidencing payments | Wallet, transaction hash, amount | Performance of a contract; legal obligation (accounting and tax records) |
We do not use your data for automated decision-making with legal or similarly significant effects.
4. What we do NOT do
- We do not sell or rent personal information, and we have not done so in the preceding 12 months.
- We do not "share" personal information for cross-context behavioral advertising (as defined by the California CPRA).
- We do not run third-party analytics, advertising pixels, or session recording.
- We do not send your form submissions or scan inputs to AI/LLM providers.
- We do not send marketing email. Waitlist emails are used only to tell you the feature you asked about is available.
- Contract details, audit material, and free-text messages you share with us stay confidential: we do not publish or sell them.
5. Who receives your data
We use a small set of infrastructure providers ("processors" and independent services) to run Themis:
| Recipient | Role | Data involved |
|---|---|---|
| Cloudflare, Inc. | CDN, TLS, DDoS protection, edge security | IP address, user-agent, request metadata |
| Blockchain node (RPC) providers | Reading public on-chain state | Contract and wallet addresses we look up on-chain, including a wallet address you submit to the approvals checker |
| Public block-explorer APIs | On-chain data enrichment | Contract and wallet addresses we look up, including approvals-checker addresses |
| Token and protocol metadata APIs | Resolving token and protocol names | Protocol search terms; no account data |
| Google Workspace (Google LLC) | Email hosting for [email protected] | The content of email you send us |
Blockchain addresses you look up are queried against public blockchain data; the lookups above tell those providers which addresses were queried, not who you are. Providers reachable only from our servers are described by category; we will identify them on legitimate request (for example under a data-processing agreement).
We may also disclose data if required by law, to enforce our terms, or to protect the rights, safety, or property of Themis or others. If Themis is involved in a merger, acquisition, or asset sale, personal data may transfer as part of that transaction; this notice will continue to apply to it.
6. The approvals checker and third-party addresses
The approvals checker accepts any wallet address, including addresses that are not yours. It reads only public blockchain data (token approvals and related transactions) and displays it. Displayed results are temporary and expire after roughly 30 minutes; we retain the underlying approval records (address, token, spender, transaction hashes) for up to 12 months to speed up repeat scans. We process such lookups under our legitimate interest in providing security tooling over already-public on-chain data.
7. Retention
We keep personal data only as long as needed for the purposes above:
| Data | Retention |
|---|---|
| Contact-form and inquiry submissions | Up to 24 months after our last interaction, then deleted |
| AI agent support-check submissions | Up to 24 months after our last interaction, then deleted |
| Monitoring waitlist emails | Until we notify you of launch or you ask us to remove you, at most 24 months |
| Trial scan records and first-party analytics events | Kept up to 12 months; IP addresses are stored only as salted one-way hashes, never raw |
| Approvals-checker results | Displayed results expire after roughly 30 minutes; underlying approval records kept up to 12 months |
| Authentication tokens | 24 hours (sign-in nonces expire after 5 minutes) |
| Payment and order records | At least 7 years, as required by Hong Kong tax and company law |
| Server and edge logs | Up to 30 days |
Data recorded on public blockchains (payment transactions, on-chain approvals) is outside our control and cannot be deleted by us or anyone.
8. Security
Traffic is encrypted in transit (TLS). The service is fronted by Cloudflare; administrative interfaces are network-restricted and require cryptographic wallet-signature authentication. We never handle your private keys. No system is perfectly secure, so we cannot guarantee absolute security, but if a breach affects your personal data we will notify you and the relevant authorities where the law requires it.
9. International transfers
Our infrastructure providers (including Cloudflare, Google, and our blockchain data providers) are based in or process data in the United States and other countries. Where the GDPR applies to a transfer, we rely on safeguards such as the EU-U.S. Data Privacy Framework or Standard Contractual Clauses implemented by those providers.
10. Your rights
Under the Hong Kong PDPO, you have the right to request access to your personal data and to request correction of inaccurate data. Depending on where you live, you may additionally have the right to:
- access a copy of the personal data we hold about you
- correct inaccurate data
- delete your data ("right to be forgotten")
- restrict or object to processing based on legitimate interest
- receive your data in a portable format
- withdraw consent (for example, leave the monitoring waitlist) without affecting prior processing
- not be discriminated against for exercising these rights (California)
- appeal a refusal and complain to your data-protection authority (Hong Kong: the Office of the Privacy Commissioner for Personal Data (PCPD); EU: your local supervisory authority; UK: the ICO)
To exercise any of these, email [email protected] from the address (or, for wallet-linked data, with a signature from the wallet) the data relates to. We verify requests to protect your data and respond within the time required by applicable law (for Hong Kong access and correction requests, 40 days).
Two practical limits: (1) we cannot erase data recorded on public blockchains, and (2) if you interact with us only through a wallet address, we may be unable to link a deletion request to you without a signature proving control of that address.
We do not sell personal information, so opt-out-of-sale requests and Global Privacy Control signals have no additional effect, but we honor them where applicable.
11. Children
Themis is a professional security tool. It is not directed at children, and we do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us data, contact us and we will delete it.
12. Do Not Track
We do not track visitors across third-party websites, so there is nothing for a Do Not Track signal to disable.
13. Changes to this notice
We may update this notice as the service evolves. We will post the new version here with an updated "last updated" date, and for material changes we will provide more prominent notice (for example a banner or, where we have your email, a message). Prior versions are available on request.
14. Contact
Themis Security Labs Limited
The L. Plaza, 367 - 375 Queen's Road Central, Sheung Wan, Hong Kong
[email protected]
If you believe we have not resolved your concern, you may lodge a complaint with the Office of the Privacy Commissioner for Personal Data, Hong Kong (pcpd.org.hk) or, if you are in the EU/UK, with your local supervisory authority.