Privacy policy

View the most recent archived version.

Version 6.0 — Updated February 19th, 2026

Recorded Future is the world’s most comprehensive and independent threat intelligence cloud platform. It enables organizations to identify and mitigate threats across cyber, supply-chain, physical, and fraud domains. It is trusted by organizations to provide real-time, unbiased and actionable intelligence.

Recorded Future is committed to protecting and respecting your privacy. This Privacy Policy explains your privacy rights and how we collect, use, share, retain, and transfer personal information (collectively referred to as “processing” or “process”).

I. POLICY APPLICATION

This Privacy Policy applies to personal information we process on or through our websites, our mobile application, our platform (the “Sites”), and other offerings (collectively, the “Services”) and explains our processing practices, including the personal information we may collect, our use of such personal information, and your privacy rights, including the rights of data subjects that may differ based on location. For example, European Union individuals under the General Data Protection Regulation or California residents pursuant to the California Consumer Privacy Act and California Privacy Rights Act.

This Privacy Policy applies to all of Recorded Future’s US Entities and Subsidiaries, listed herein:

This Privacy Policy does not apply to personal information we collect:

When you access or use the Services, we process personal information as described in this Privacy Policy, our Terms of Use, and/or other agreements as may be executed between us and you or your organization.

II. PERSONAL INFORMATION WE COLLECT – SOURCES AND CATEGORIES

Our business focuses on collecting threat intelligence data from, or about, threats for security purposes. Generally, this data is not intended to relate to, or be used to identify an individual or household.

We collect personal information when you visit our Sites and through your interactions with us. For example, when you request information about our Services, when you use our Services (such as submitting queries, performing analysis, or annotating results), subscribe to or read our published content through the Sites, listen to or subscribe to our podcast, indicate your interest in receiving marketing or other materials through our Sites, use our mobile application, provide us with your information to register for, or while at, a conference, event, or webinar, participate in our Community of Practice, when you request product support, or when you voluntarily provide information to us through our Sites or via email or telephone. We also collect personal information from our LinkedIn page and our other social media presences, from third-party commercial sources of personal information, and from publicly available sources including the dark web and open source intelligence.

The categories of personal information we may collect include the following:

Additional information: We may collect additional categories of personal information that threat actors, and others, have collected and posted to the dark web or other publicly available sources. We collect such data through our threat intelligence tools. The categories of such personal information may vary depending on the content made publicly available by third parties and the nature of the threat intelligence activity being performed.

In limited circumstances, such information may relate to individuals where it appears in publicly available or otherwise lawfully accessible sources and is relevant to documented threat intelligence purposes.

Information Included in Queries: Recorded Future offers both free-text search, and sandbox submission functionality, so any personal information included by you in such searches or sandbox submissions may be processed by Recorded Future.

A sandbox end user may upload a file that contains personal information, to include a broader range of personal information than those listed above, however the malware analysis processes the personal information in a manner incidental to the analysis of the file. Where users choose to use the public sandbox option, analyzed files may be made available to other public sandbox users in accordance with the functionality of the Services.

Cookies and Other Technologies

We collect the above information partly through our use of cookies, which allow Recorded Future to provide customers and site visitors a better and more secure experience. While the exact names and parameters of cookies used by Recorded Future may periodically change, they are generally used for authentication, security, performance, or analytics. These cookies can be deleted at any time. For detailed information on how we use cookies, please click here.

Additionally, we use Google Analytics to evaluate the use of our Sites. Google Analytics uses cookies and other identifiers to collect information, such as how often users visit a website, what pages they visit when they do so, and what other websites they visited prior to visiting a website. To learn more about how Google Analytics collects personal information, review Google’s Privacy Policy.

III. HOW WE USE YOUR INFORMATION

Recorded Future processes personal information in a way that is compatible with and relevant to the purpose for which it was collected or authorized. As a general matter, for the categories of personal information described in Section II above, we may use your personal information to:

To populate our Intelligence Cloud, Recorded Future processes the intelligence referenced above for certain legitimate business purposes, which may include the following:

When we process personal information for our legitimate interests, we make sure to consider and balance any potential impact on potential data subjects and their rights under data protection laws.

Where required under applicable data protection laws, Recorded Future processes personal information only where a valid legal basis applies, which may include performance of a contract, compliance with a legal obligation, or legitimate interests, subject to applicable legal requirements and safeguards

IV. COLLECTIVE INSIGHTS AND QUERY DATA

Generally, Recorded Future uses query data in one of two ways -

i) Recorded Future uses this data to provide our services to our customers, this includes everything from returning the query results to providing the search history feature and sending out alerts as configured by users; and

ii) Recorded Future uses unattributed Customer Data to develop & improve our offerings. These improvements may include providing a signal to our teams regarding what type of data to improve, what research to pursue, insight into trends, data enrichment, and potential feature improvements.

Additionally, there may be limited circumstances in which access to this data is required to respond to a valid legal request, address an investigation of a security, safety, or related issue, or enforce of the Terms of Use.

Further, Recorded Future may index metadata from security events generated through Collective Insights integrations to create correlations. When used on the Recorded Future Platform, this metadata is processed in a manner designed to avoid attribution to their original sources.

Recorded Future may share certain parts of this unattributable data with third parties for defined and permissible business purposes.

V. DISCLOSING YOUR INFORMATION FOR BUSINESS PURPOSES

The categories of personal information and the corresponding business purpose that we disclose to third parties are:

Additionally, we may also share personal information:

VI. DATA SUBJECT PRIVACY RIGHTS

Depending on your location, you may have certain privacy rights under the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), or other applicable laws.

These rights may include, where applicable, the right to access, delete, correct or restrict the processing of personal information, as well as other rights provided under applicable data protection laws.

Right to Know (where applicable)

At your request, to the extent required under applicable law, we will disclose the following, limited to what we have collected (to the extent we are able to identify):

The Right to Delete

At your request, to the extent required under applicable law, we will delete the personal information we have collected about you, unless such applicable laws authorizes or requires us to retain specific information.

The law may authorize us to retain such information:

Applicable law may also permit us to retain specific information for our exclusive internal use, but only in ways that are compatible with the context in which you provided the information to us or that are reasonably aligned with your expectations based on your relationship with us. We will act on your deletion request within the timeframes required by applicable law.

Right to Opt out of Sale or Sharing

You may direct us not to sell your personal information by submitting an opt-out request to privacy [at] recordedfuture [dot] com. We will act on your request within the timeframes set forth under applicable law.

Right to Correct

To the extent required under applicable law, you may request that we correct inaccurate information that we have about you.

Right to Limit Use/Disclosure of Sensitive Information

To the extent required under applicable law, you may request that we only use your sensitive personal information for limited purposes, such as providing you with the Services you requested.

Authorized Agents

To the extent permitted under applicable law, you may designate an agent to submit requests on your behalf.

If you would like to designate an agent to act on your behalf, you and the agent will need to comply with our verification process.

This subsection does not apply when an agent is authorized to act on your behalf pursuant to a valid power of attorney.

Note: Under CCPA, the agent must be a natural person or a business entity that is registered with the California Secretary of State.

How to Exercise Your Rights and How We Will Respond

To exercise any of the rights above contact us at +1-888-914-9661 or privacy [at] recordedfuture [dot] com

Generally, except to the extent otherwise required under applicable law, we will within 10 business days acknowledge receipt of requests for access to or deletion of data. We will respond within 45 days from when we receive your request, although we may be allowed to take longer to process your request under certain circumstances.

If we expect your request is going to take us longer than normal to fulfill, we will let you know.

We respond to requests free of charge, but we may charge a reasonable fee for administrative costs in certain situations. In some cases, the law allows us to refuse certain requests.

Non-Discrimination Assurance

You will not be denied or charged different prices or rates for goods or services, or provided a different level or quality of goods or services than others if you exercise rights under this Privacy Policy.

Verification of Identity – Access or Deletion Requests

We will ask you for identifying information and attempt to match it to information that we maintain about you.

If we are unable to verify your identity, we will not respond to your request other than to notify you that we could not verify your identity.

Under certain circumstances, California and EU/UK/Swiss residents may be permitted to submit aforementioned privacy requests through designated third-party agents. Those third-party agents must still abide by Recorded Future’s identity verification process.

IX. INTERNATIONAL DATA TRANSFERS

Some of our Services are hosted in the United States. Therefore, when you disclose personal information to us, we may transfer personal information to the US.

If you are located in the EEA/UK, we may, for the purposes listed in Section III, transfer your personal information to recipients listed in Section V, that may be located in countries outside the EEA/UK, including the US. If the European Commission and/or the United Kingdom has determined that a recipient country does not provide an adequate level of data protection, we will take steps to protect the personal information and rely on a valid transfer solution, including by entering into Standard Contractual Clauses with the recipient parties or, where applicable, relying on a derogation for the transfer (e.g., where the transfer is necessary for the defense of legal claims).

Self-Certification to the Data Privacy Framework (DPF)

Recorded Future complies with the EU-US DPF, the UK Extension to the EU-US DPF, and the Swiss-US DPF as set forth by the US Department of Commerce. Recorded Future has certified to the US Department of Commerce that it adheres to the EU-US Data Privacy Framework Principles (EU-US DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-US DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-US DPF.

Recorded Future has also certified to the US Department of Commerce that it adheres to the Swiss-US Data Privacy Framework Principles (Swiss-US DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-US DPF. If there is any conflict between the terms in this Privacy Policy and the EU-US DPF Principles and/or the Swiss-US DPF Principles, the DPF Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/.

In compliance with the EU-US DPF, the UK Extension to the EU-US DPF, and the Swiss-US DPF (together, the “DPFs”), Recorded Future commits to resolve DPF Principles-related complaints about our collection and use of your personal information. EU, UK, and Swiss individuals with inquiries or complaints regarding our handling of personal information received in reliance on the DPFs should first contact us by emailing privacy [at] RecordedFuture [dot] com or via mail to: Recorded Future, 363 Highland Avenue Somerville, MA, 02144, USA, Attn: Data Protection Officer. Except as otherwise required under applicable law, we will respond to your inquiry within 30 days of receipt and verification of your identity.

In compliance with the DPFs, Recorded Future commits to refer unresolved complaints concerning our handling of personal information received in reliance on the DPFs to JAMS, an alternative dispute resolution provider based in the United States.

If you do not receive timely acknowledgment of your DPF Principles-related complaint from us, or if we have not addressed your DPF Principles-related complaint to your satisfaction, please visit https://www.jamsadr.com/dpf-dispute-resolution for more information or to file a complaint. The services of JAMS are provided at no cost to you.

You have the possibility, under certain conditions, to invoke binding arbitration for complaints regarding DPF compliance not resolved by any of the other mechanisms set out in this DPF Notice or our Privacy Policy. For more information, please see Annex 1 of the DPF Principles, available here.

The Federal Trade Commission has jurisdiction over Recorded Future’s compliance with the EU-US Data Privacy Framework (EU-US DPF) and the UK Extension to the EU-US DPF, and the Swiss-US Data Privacy Framework (Swiss-US DPF). We may be required to disclose personal information we receive under the EU-US DPF, the UK Extension to the EU-US DPF, and the Swiss-US DPF in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.

Recorded Future is liable for the processing of personal information it receives under the DPF Principles and subsequently transfers to a third party acting as an agent on its behalf. Recorded Future shall remain liable under the DPF Principles if its agent processes such personal information in a manner inconsistent with the DPF Principles, unless Recorded Future proves that it is not responsible for the event giving rise to the damage.

XI. DATA RETENTION

We retain personal information for as long as necessary to fulfill the purposes for which we collected it, including for satisfying any legal, cybersecurity, accounting or reporting requirements. To determine the appropriate retention period, we consider the amount, nature and sensitivity of the personal information together with the necessity and purposes for the processing (including, whether such purposes can be achieved through other means) and the potential risk of harm from unauthorized use or disclosure of the personal information.

For more information about applicable retention periods, please review the Security FAQ Page.

XII. SECURITY OF YOUR INFORMATION

The security of personal information is important to Recorded Future. We are committed to protecting the personal information we process in connection with the Services.

We maintain appropriate administrative, technical, and organizational safeguards designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the nature of the personal information, the context and purposes of the processing, and the risks associated with such processing. While we implement such measures, please note that no security system is entirely infallible.

XIII. CHILDREN’S INFORMATION

The Services are not directed to children, as defined under applicable law (e.g., under 13 years of age in certain jurisdictions), and except to the extent authorized by applicable law, we do not knowingly collect or sell personal information from children. If you learn that your child has provided us with personal information without your consent, you may contact us as set forth below.

XIV. OTHER PROVISIONS

Changes to Our Privacy Policy

We may update this Privacy Policy from time to time. If we make changes that materially affect our uses of personal information or your privacy rights, we will provide notice through our Sites and/or by email, as required under applicable law.

Third-Party Websites

Our Sites may contain social media buttons or links to third-party websites, which may have privacy policies that differ from our own. We are not responsible for the activities and practices that take place on those social media platforms or third-party websites. We recommend that you review the privacy policies posted on any platform or website that you may access through our Sites.

Accessibility

We are committed to ensuring that our communications are accessible to people with disabilities. To make accessibility-related requests or report barriers, please contact us at notices [at] recordedfuture [dot] com.

Mobile App Users

All information obtained through Recorded Future’s mobile application is treated consistently with this Privacy Policy.

As with the website, when you interact with the mobile app, we collect information about your use of the app and other information about your device. When you download the mobile app from an app store, you may also be sharing information with the app store provider subject to the provider’s own privacy policies.

In addition, Recorded Future may collects crash data. If your app suffers a crash, it may send telemetry data back to Recorded Future through third-party services (for example, application performance or crash-reporting providers) and through the app store you used when you downloaded the app.

If you have any questions regarding the information collected through the mobile app, please contact privacy [at] recordedfuture.com.

CONTACT US

If you have any questions about our privacy practices or this Privacy Policy, or if you wish to submit a request to exercise your rights as detailed in this Privacy Policy, please contact us at:

Recorded Future/Privacy Policy

Attn: Data Privacy Officer

363 Highland Avenue

Somerville, MA 02144 USA