Privacy policy

Last updated September 21, 2026

Overview

ThreatLens is a free security tool built by Saad Mahmud for scanning URLs and files for potential malware and phishing threats. This policy explains what data is collected, how it is used, and how it is stored.

Data we collect

When you submit a URL or file, we store the submitted URL or filename, the risk result (safe, suspicious, or dangerous), detection counts from VirusTotal, any matched YARA rule names, and the scan timestamp. We do not store the contents of uploaded files - files are only used to compute a SHA-256 hash and run the local YARA rule check, both in memory during the request.

Third-party services

Scans are checked against VirusTotal (virustotal.com) for URL and file hash reputation, and Google Safe Browsing for phishing and malware URL detection. Submitted URLs and file hashes may be sent to these services - review their respective privacy policies for details. YARA rule matching runs entirely within this application and is not sent anywhere.

Scan history

All scans are stored in a shared database and are not tied to an individual account. Scan history is visible to anyone using the application. Do not submit sensitive or private URLs or files.

Cookies

ThreatLens does not use cookies or any tracking technologies.

Data retention

Scan records are deleted automatically every 24 hours. Data is not sold or shared with third parties beyond the scanning services listed above.

Contact

Questions about this policy can be sent through saadmahmud.dev.