Privacy Policy
Effective date: 1 May 2025
This Privacy Policy explains how Grepsi Security (“we”, “us”, “our”) processes information when you use the Grepsi Security Threat Modelling tool at grepsi-sec.com/threat-model.
1. Who We Are
Grepsi Security operates the threat modelling tool available at grepsi-sec.com. For any privacy-related enquiries please contact: info@grepsi-sec.com
2. What Data We Collect — and What We Don’t
We do not collect, store, or transmit your threat model data. The tool runs entirely in your browser. All threat model content you create — application names, components, threats, mitigations, and requirements — is stored exclusively in your browser’s local storage and never sent to any server.
What we do not collect:
- Threat model content of any kind
- Account credentials (there are no accounts)
- Personal details entered into the tool
- Behavioural analytics or usage telemetry
What Cloudflare may process on our behalf: When you visit grepsi-sec.com, our hosting provider Cloudflare, Inc. processes your IP address and standard HTTP request metadata (browser type, referring URL, timestamp) to serve pages and provide DDoS protection. This processing occurs under Cloudflare’s own privacy policy and data processing agreement. Cloudflare acts as a data processor under GDPR.
For Cloudflare’s privacy policy see: https://www.cloudflare.com/privacypolicy/
3. Browser Local Storage
The tool uses your browser’s local storage to save your threat models between sessions. Local storage is a browser feature similar to cookies but limited to your device:
- Data stays on your device only
- We have no access to your local storage
- Data is not encrypted at rest — do not store highly sensitive information without an additional layer of protection
- Data persists until you clear your browser storage or use the tool’s export and delete functions
Local storage is not a cookie and does not require consent under UK/EU cookie law. However, we disclose its use in the interest of full transparency.
4. Cookies
This site does not set any cookies. The theme preference (light/dark mode) is stored in local storage on your device, not as a cookie.
5. Legal Basis for Processing (GDPR)
For visitors from the UK and European Economic Area (EEA), Cloudflare’s processing of connection metadata is based on legitimate interests (GDPR Article 6(1)(f)) — specifically, the legitimate interest in providing a secure, reliable hosting service and protecting against abuse.
We do not process any personal data beyond what Cloudflare processes as our hosting provider.
6. Data Retention
We do not retain personal data. Cloudflare retains connection logs for a limited period in accordance with their data retention policy. Threat model data in your browser’s local storage is retained until you delete it.
7. Your Rights (UK GDPR / EU GDPR)
If you are based in the UK or EEA, you have the right to:
- Access — request a copy of any personal data we hold about you
- Erasure — request deletion of your personal data
- Restriction — request that we restrict processing of your personal data
- Portability — receive your personal data in a structured format
- Object — object to processing based on legitimate interests
Because we hold no personal data beyond Cloudflare connection logs (which we do not control), most rights requests are best directed to Cloudflare. For any queries, contact us at info@grepsi-sec.com.
UK residents may also contact the Information Commissioner’s Office (ICO): https://ico.org.uk
EU residents may contact their national supervisory authority.
8. Third-Party Sub-processors
| Sub-processor | Purpose | Location | Privacy Policy |
|---|---|---|---|
| Cloudflare, Inc. | Hosting, CDN, DDoS protection | USA (EU adequacy via SCC) | cloudflare.com/privacypolicy |
| jsDelivr (Fondation du Logiciel Libre) | KaTeX maths rendering library | CDN (global) | jsdelivr.com/terms/privacy-policy-jsdelivr-net |
9. International Transfers
Cloudflare operates globally. Transfers of connection data outside the UK/EEA are covered by Cloudflare’s Standard Contractual Clauses (SCCs) with the European Commission.
10. Changes to This Policy
We may update this policy periodically. Material changes will be reflected in a new effective date at the top of this page.
11. Contact
For any privacy questions: info@grepsi-sec.com