Themis Privacy Notice

This notice explains what data Themis ("Themis", "we", "us") collects when you use themislabs.ai and the Themis API, why we collect it, who we share it with, and the choices you have. Themis is operated by Themis Security Labs Limited, The L. Plaza, 367 - 375 Queen's Road Central, Sheung Wan, Hong Kong.

If anything here is unclear, or you want to exercise any right described below, email us at [email protected].

1. Scope

This notice covers:

  • the public website at themislabs.ai: company and product pages (AI Agent Security Assessment, RedSwarm, Themis Agent Intelligence, Continuous Agent Validation, Web3 Security), research publications, and the Web3 tools (scan tool, approvals checker, dashboard)
  • the forms on those pages: contact and inquiry forms, the AI agent support check, Agent Intelligence pilot requests, protocol workspace inquiries, and the monitoring waitlist
  • the Themis API that powers those pages
  • email correspondence with [email protected], including RedSwarm assessment requests, which are made by email

It does not cover third-party sites we link to (block explorers such as Etherscan, social profiles, GitHub). Those sites have their own privacy policies.

It also does not cover data handled during a commissioned security engagement (for example an AI Agent Security Assessment, RedSwarm testing, Continuous Agent Validation, an Agent Intelligence pilot, or a Web3 audit). Access to, retention of, and handling of customer data in an engagement are defined in the engagement documents.

2. What we collect

We only collect data you give us, data that is technically necessary to run and protect the service, and a small set of first-party product-usage events described below. We do not run third-party analytics, advertising trackers, or session-recording tools.

2.1 Data you submit

Free-text fields are stored as you write them: please do not include sensitive personal information (health, financial account numbers, government IDs) in messages or notes.

2.2 Wallet and blockchain data

If you connect a wallet, we collect your wallet address and a one-time cryptographic signature used to prove you control it. We never receive or store your private key or seed phrase, and connecting never triggers a transaction.

Your wallet address is a persistent pseudonymous identifier. While connected, it is linked to your scan history, saved reports, purchases, subscription status, and product analytics events.

If you pay for a service on-chain, the transaction (wallet address, transaction hash, amount, chain) is recorded both in our database and permanently on the public blockchain. We cannot alter or delete blockchain records.

2.3 Data collected automatically

  • IP address: used to rate-limit free scans and protect the service from abuse. We do not store your raw IP address in our application database. It is used transiently in memory, and where a record is kept (trial scans, product analytics events, workspace inquiries) we store only a salted, daily-rotating one-way hash of it, which we cannot reverse back into your IP. Workspace inquiries also record your browser's user-agent string.
  • Server and edge logs: our web server and our CDN provider (Cloudflare) keep standard access logs (IP address, user-agent, requested URL, referrer, timestamp) for security and debugging. These are short-lived and rotated automatically.
  • First-party product analytics: we record a small set of in-product events (for example "monitoring interest clicked", "report exported"), together with the related scan ID, your wallet address if connected, and a hashed form of your IP address. These events go only to our own servers.

2.4 Cookies and local storage

We do not set cookies for tracking or advertising. Our CDN provider (Cloudflare) may set strictly necessary security cookies (such as __cf_bm) to distinguish humans from bots.

We use your browser's local storage for functionality only:

You can remove these at any time via your browser's site-data settings.

3. Why we process your data (legal bases)

We process personal data in accordance with the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO"): we collect it for the lawful purposes described in this notice, by fair means, and we use it only for those purposes or directly related ones unless you consent otherwise.

Where the EU/UK GDPR applies to you, we rely on the following legal bases:

We do not use your data for automated decision-making with legal or similarly significant effects.

4. What we do NOT do

  • We do not sell or rent personal information, and we have not done so in the preceding 12 months.
  • We do not "share" personal information for cross-context behavioral advertising (as defined by the California CPRA).
  • We do not run third-party analytics, advertising pixels, or session recording.
  • We do not send your form submissions or scan inputs to AI/LLM providers.
  • We do not send marketing email. Waitlist emails are used only to tell you the feature you asked about is available.
  • Contract details, audit material, and free-text messages you share with us stay confidential: we do not publish or sell them.

5. Who receives your data

We use a small set of infrastructure providers ("processors" and independent services) to run Themis:

Blockchain addresses you look up are queried against public blockchain data; the lookups above tell those providers which addresses were queried, not who you are. Providers reachable only from our servers are described by category; we will identify them on legitimate request (for example under a data-processing agreement).

We may also disclose data if required by law, to enforce our terms, or to protect the rights, safety, or property of Themis or others. If Themis is involved in a merger, acquisition, or asset sale, personal data may transfer as part of that transaction; this notice will continue to apply to it.

6. The approvals checker and third-party addresses

The approvals checker accepts any wallet address, including addresses that are not yours. It reads only public blockchain data (token approvals and related transactions) and displays it. Displayed results are temporary and expire after roughly 30 minutes; we retain the underlying approval records (address, token, spender, transaction hashes) for up to 12 months to speed up repeat scans. We process such lookups under our legitimate interest in providing security tooling over already-public on-chain data.

7. Retention

We keep personal data only as long as needed for the purposes above:

Data recorded on public blockchains (payment transactions, on-chain approvals) is outside our control and cannot be deleted by us or anyone.

8. Security

Traffic is encrypted in transit (TLS). The service is fronted by Cloudflare; administrative interfaces are network-restricted and require cryptographic wallet-signature authentication. We never handle your private keys. No system is perfectly secure, so we cannot guarantee absolute security, but if a breach affects your personal data we will notify you and the relevant authorities where the law requires it.

9. International transfers

Our infrastructure providers (including Cloudflare, Google, and our blockchain data providers) are based in or process data in the United States and other countries. Where the GDPR applies to a transfer, we rely on safeguards such as the EU-U.S. Data Privacy Framework or Standard Contractual Clauses implemented by those providers.

10. Your rights

Under the Hong Kong PDPO, you have the right to request access to your personal data and to request correction of inaccurate data. Depending on where you live, you may additionally have the right to:

  • access a copy of the personal data we hold about you
  • correct inaccurate data
  • delete your data ("right to be forgotten")
  • restrict or object to processing based on legitimate interest
  • receive your data in a portable format
  • withdraw consent (for example, leave the monitoring waitlist) without affecting prior processing
  • not be discriminated against for exercising these rights (California)
  • appeal a refusal and complain to your data-protection authority (Hong Kong: the Office of the Privacy Commissioner for Personal Data (PCPD); EU: your local supervisory authority; UK: the ICO)

To exercise any of these, email [email protected] from the address (or, for wallet-linked data, with a signature from the wallet) the data relates to. We verify requests to protect your data and respond within the time required by applicable law (for Hong Kong access and correction requests, 40 days).

Two practical limits: (1) we cannot erase data recorded on public blockchains, and (2) if you interact with us only through a wallet address, we may be unable to link a deletion request to you without a signature proving control of that address.

We do not sell personal information, so opt-out-of-sale requests and Global Privacy Control signals have no additional effect, but we honor them where applicable.

11. Children

Themis is a professional security tool. It is not directed at children, and we do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us data, contact us and we will delete it.

12. Do Not Track

We do not track visitors across third-party websites, so there is nothing for a Do Not Track signal to disable.

13. Changes to this notice

We may update this notice as the service evolves. We will post the new version here with an updated "last updated" date, and for material changes we will provide more prominent notice (for example a banner or, where we have your email, a message). Prior versions are available on request.

14. Contact

Themis Security Labs Limited
The L. Plaza, 367 - 375 Queen's Road Central, Sheung Wan, Hong Kong
[email protected]

If you believe we have not resolved your concern, you may lodge a complaint with the Office of the Privacy Commissioner for Personal Data, Hong Kong (pcpd.org.hk) or, if you are in the EU/UK, with your local supervisory authority.