Privacy Policy
Last updated: 2025-12-20
IOC.FYI is a public web application operated from the United States. This Privacy Policy describes what information is collected when you use the service and how it is used.
What We Collect
Request Metadata
We collect limited technical metadata for operational purposes, including:
- IP address
- Request timestamps
- User-Agent string
- Basic request and performance metrics
This data is used for monitoring, reliability, and abuse prevention.
IOC Search Queries
Indicators of Compromise (IOCs) submitted to IOC.FYI may be stored and analyzed for:
- Service analytics
- Research and trend analysis
- Improving signal quality and false-positive identification
Search queries are not associated with user accounts, identities, or profiles.
Analytics
IOC.FYI uses Google Analytics to understand aggregate usage patterns such as page views and feature usage. Data collected by Google Analytics is subject to Google's own privacy practices.
Cookies
IOC.FYI does not intentionally set cookies for tracking, advertising, or user profiling. Any cookies used by third-party services are governed by those providers' policies.
How We Use Data
Collected information is used solely to:
- Operate and maintain the service
- Monitor performance and reliability
- Prevent abuse and excessive automated usage
- Conduct internal research related to IOC trends
We do not sell, rent, or trade data.
Data Sharing
Data may be processed or stored by infrastructure providers strictly for service operation (e.g., cloud hosting and analytics platforms). Data is not shared for marketing or advertising purposes.
Data Retention
IOC.FYI does not currently maintain a fixed data retention schedule. Logs and analytics data may be retained as reasonably necessary for operational, analytical, or research purposes.
Data Security
Reasonable administrative and technical safeguards are used to protect collected information. No system can be guaranteed to be completely secure.
Intended Audience
IOC.FYI is intended for use by security analysts, security engineers, and defenders. It is not designed for general consumer use.
Changes
This Privacy Policy may be updated from time to time. Updates will be reflected on this page with a revised date.