GreyNoise Privacy Policy

Last modified: July 28, 2026

1. Introduction

1.1 About us

GreyNoise Intelligence, Inc. ("GreyNoise" or "we") is a company organized under the laws of Delaware in the United States that provides threat intelligence services through our proprietary Platform (defined in our End User License Agreement or "EULA"). We respect your privacy and are committed to protecting it through our compliance with this Privacy Policy. Any capitalized terms used in this Privacy Policy not defined here have the meaning given to them in our End User License Agreement.

This Privacy Policy together with our EULA describes the types of information we may collect from both visitors of our website at greynoise.io ("Site") and subscribers to our Platform ("Customers"), and our practices for collecting, using, maintaining, protecting, and disclosing that information, including Personal Data. "Personal Data" means information by which you may be personally identified, which includes but is not limited to your name, mailing address, email address, telephone number, job title, employer, username, and billing/payment details.

This Privacy Policy addresses two distinct categories of data. First, it addresses the Personal Data we collect from and about visitors to our Site and Customers of our Platform — the people and organizations who interact with us — as described in Sections 2 and 3. Second, it addresses Threat Intelligence Data: the data our own global sensor network collects about systems on the internet that scan, probe, or attack internet-connected infrastructure, as described in Section 4. Threat Intelligence Data is data we collect through our own sensors as part of our security research and threat intelligence services; it is generally not about our visitors or Customers, is not data you provide to us, and is not treated as customer data. Except where Section 4 provides otherwise, the remainder of this Privacy Policy concerns the Personal Data described in the first category.

If you have subscribed to our Platform through a Data License Agreement and this Privacy Policy, then the terms of your Data License Agreement will take priority. This Privacy Policy applies to information we collect on our Site, through your access to the Platform, in email, text, and other electronic messages between you and us, whether through the Platform or otherwise, and through offline communication such as phone calls.

Please read this Privacy Policy carefully to understand our policies and practices regarding your information and how we will treat it. If you do not agree with our policies and practices, your choice is not to use our Site or access the Platform. By using the Site and/or accessing the Platform, you accept and consent to this Privacy Policy. You may choose not to submit requested information online or may choose to restrict the use of cookies (see Section 6 Cookies below for more information) but that may limit the Platform and content we can provide to you.

1.2 Children

Our Site and Platform are not intended for children under 16 years of age. No one under age 16 may provide any Personal Data to GreyNoise. We do not knowingly collect Personal Data from children under 16. If you are under 16, do not use or provide any information on the Site, register for a subscription to the Platform, or provide any information about yourself to us, including your name, address, telephone number, email address, or any screen name or username you may use. If we learn we have collected or received Personal Data from a child under 16 without verification of parental consent, we will delete that information. If you believe we might have any information from or about a child under 16, please contact us at [email protected].

2. Visitors

2.1 What we collect/process

2.1.1 Data you provide us

We may ask you to provide Personal Data voluntarily when you access certain parts of our Site, including when you submit an inquiry through our Contact feature or report a problem with the Site. If you choose to communicate with us, we may also collect additional data you provide, including copies of your communications and the method of communication you used. The Personal Data we may collect includes:

  • Your Name
  • Email Address
  • Phone Number

2.1.2 Data from third parties

We may collect information about you from certain parties with whom we have a relationship, including social media websites like LinkedIn, analytics providers like Google Analytics, marketing partners like HubSpot, and other third-party service providers.

2.1.3 Aggregated data

As you navigate through and interact with our Site, we may use automatic data collection technologies, including cookies (see Section 6 Cookies below for more details) to collect certain information about your equipment, browsing actions, and patterns, including:

  • Details of your visits to our Site, including traffic data, location data, logs, and other communication data and the resources that you access and use on the Site
  • Information about your computer and internet connection, including your IP address, operating system, browser ID and type, browsing activity (such as the website from which you arrived at our Site or navigated to after our Site, for example)

2.1.4 Usage data

If you use our data visualizer located at https://viz.greynoise.io, we will collect Usage Data (defined in the EULA at https://www.greynoise.io/terms) from your queries the same as we do for Customers who subscribe to the Platform.

2.2 Purpose for collection/processing

We collect and process Personal Data of visitors on one or more legal bases related to the particular information at issue and the context in which we collect it. Generally speaking, our bases for obtaining and using your Personal Data is our legitimate interest in providing, maintaining, and improving our Site and Platform, based on your consent, or any combination of these bases. If required by law, we will only process your Personal Data after receiving your consent to do so. Please see Your Data Rights below for more details on withdrawing consent.

3. Customers

3.1 What we collect/process

We may collect the same data from Customers that we do for visitors as described in Section 2 above, depending on the context of your interactions with us.

3.1.1 Data you provide us

To enjoy full use of our Platform, you must become a Customer by registering an account and subscribing to the Platform. Customers are required to provide certain Personal Data at the time of registration, including:

  • Organization name (if applicable)
  • Contact Name
  • Contact Title
  • Mailing Address
  • Email Address
  • Phone Number
  • Username
  • Password
  • Payment Method Details

3.1.2 Data from third parties

In addition to the third-party data that we collect from all Site visitors listed above in Section 2.1, we may collect information as you access the Platform from certain third-party partners integrated with our Platform, such as SIEMs, TIPs, and SOAR cybersecurity platforms.

3.1.3 Aggregated data

We collect the same type of Aggregated Data from Customers that we do from visitors, as described above in Section 2.1.3. Our rights concerning Usage Data are set out in the EULA.

3.2 Purpose for collection/processing

In addition to the uses pertaining to information of visitors of our Platform described in Section 2.2, we also use Personal Data collected from Customers:

  • to provide you with information, products, or services that you request from us
  • to provide you with notices about your account
  • to carry out our obligations and enforce our rights arising from any contracts entered into between you and us (such as our End User License Agreement or Data License Agreement), including for billing and collection
  • to notify you about changes to our Platform or any products or services we offer or provide
  • to provide you with our newsletter if you have signed up for it
  • in any other way we may describe when you provide the information
  • for any other purpose with your consent

4. Threat Intelligence and Network-Observed Data

This section describes Threat Intelligence Data, which is a distinct category of data from the Personal Data we collect from visitors and Customers described elsewhere in this Privacy Policy. GreyNoise operates a global network of sensors that passively observe unsolicited network traffic sent to them by systems across the internet. In providing our threat intelligence services, we collect and process technical data about the systems that generate this traffic ("Threat Intelligence Data"), which may include IP addresses, network ports and protocols, timestamps, approximate geolocation, autonomous system (ASN) information, and metadata about the contents of the observed traffic.

This data concerns systems that are scanning, probing, or attacking internet-connected infrastructure. In most cases we have no relationship with the operator of the system and do not collect any name, contact details, or account information about them. Where this data constitutes personal data under applicable law (for example, an IP address under the European Union General Data Protection Regulation ("GDPR")), we process it on the basis of our legitimate interests in ensuring network and information security and in detecting, investigating, and preventing malicious activity (see GDPR Article 6(1)(f) and Recital 49), balanced against the rights and freedoms of the individuals concerned.

We apply data minimization measures to the traffic our sensors observe, and we do not use this data to identify or target individuals or to make automated decisions that produce legal or similarly significant effects concerning them. Threat Intelligence Data is collected and owned by GreyNoise as part of our threat intelligence services; it is not associated with any Customer account and is not treated as customer data. If you operate a network and have questions about data associated with an IP address you control, you may contact us at [email protected].

5. Disclosure

We may disclose Personal Data that we collect as described in this Privacy Policy:

  • to our subsidiaries and affiliates
  • to contractors, service providers, and other third parties (our "sub-processors") that we use to support our business and that are bound by contractual obligations to keep Personal Data confidential and use it only for the purposes for which we disclose it to them. The sub-processors and third-party services we currently use to process Personal Data include: 
    • Amazon Web Services (cloud hosting, infrastructure, and transactional email via Amazon SES); 
    • Snowflake (data warehousing and analytics); 
    • Auth0 by Okta (Platform authentication); 
    • Stripe (payment processing); 
    • Stigg (subscription and entitlement management); 
    • Datadog (application monitoring); 
    • Webflow (marketing website hosting); 
    • Google (Google Analytics and Google Workspace); 
    • HubSpot (customer relationship management and marketing). 

We may update this list from time to time as our service providers change.

  • to a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which Personal Data held by us about our Customers is among the assets transferred
  • to comply with any court order, law, or legal process, including to respond to any government or regulatory request
  • if we believe disclosure is necessary or appropriate to protect the rights, property, or safety of GreyNoise, our Customers, or others
  • for any other purpose disclosed by us when you provide the Personal Data
  • with your consent

6. Cookies

We use cookies and similar tracking technologies to collect information about you, as described in Section 2.1.3, when you visit the Site or access the Platform. We use the following categories of cookies and similar technologies:

  • Strictly necessary cookies: required for the Site and Platform to function, including for authentication and account management.
  • Performance and analytics cookies: help us understand how the Site is used (for example, Google Analytics).
  • Functionality cookies: remember your preferences, such as language and timezone.

Where required by law (for example, for visitors located in the EEA or the UK), we obtain your consent before placing non-essential cookies, and you may accept or reject non-essential cookies through our cookie banner and manage your preferences at any time. You can also control cookies through your browser settings.

7. Links

On occasion we include links to third parties on the Site. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Where we provide a link, it does not mean that we endorse or approve that website's policy towards visitor privacy. You should review their privacy policy before sending them any Personal Data.

8. International Data Transfers

GreyNoise is headquartered in the United States and hosts its Platform on cloud infrastructure located in the United States. If you access our Site or Platform from outside the United States, your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction. Where we transfer personal data of individuals located in the European Economic Area, the United Kingdom, or Switzerland to the United States, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and, for transfers from the United Kingdom, the UK International Data Transfer Addendum.

9. Your data rights

9.1 All users

You have the right to:

  • Request access to, correct or delete any Personal Data that you have provided to us. We may not accommodate a request to change information if we believe the change would violate any law or legal requirement or cause the information to be incorrect.
  • As a Customer, review and change your Personal Data by logging into the Platform and visiting your account profile.
  • Remove and/or reject cookies from our Site with your browser settings. If you remove or reject our cookies, it could affect how the Site and our Platform perform for you.
  • Object to the processing of your Personal Data, request us to restrict processing of your Personal Data, or request to have your Personal Data in a portable format.
  • Make a complaint at any time to the data protection authority in your jurisdiction. We would, however, appreciate the chance to deal with your concerns before you approach such authority so please contact us in the first instance.

To exercise any of these rights, send us an email at [email protected].

9.2 EEA and UK residents

If you are located in the European Economic Area or the United Kingdom, you have the rights described above and, in addition, the right to withdraw consent at any time where we rely on your consent to process your Personal Data, and the right to object to processing where we rely on our legitimate interests. We will respond to requests within the timeframes required by applicable law. You may lodge a complaint with your local supervisory authority.

In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours where required, and affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

Data protection contact: [email protected].

9.3 California residents

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), provides you with specific rights. In the preceding 12 months, we have collected the following categories of personal information: identifiers (such as name, email address, telephone number, and IP address); commercial information (such as billing details); internet or other network activity information; and professional or employment-related information (such as job title and employer). We collect this information directly from you, automatically through your use of the Site and Platform, and from third parties such as analytics providers, marketing platforms, and integrated security platforms.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA.

California residents have the right to know and access the personal information we collect, to request deletion or correction of that information, and to not be treated in a discriminatory manner for exercising these rights. To exercise these rights, email [email protected].

10. Data, security, and retention

10.1 Security

We have implemented measures designed to secure your Personal Data from accidental loss and from unauthorized access, use, alteration, and disclosure. Any payment transactions are encrypted in accordance with the policies of our third-party payment processor. In the event of a breach of Personal Data, we will notify affected individuals and the applicable authorities as required by law.

The safety and security of your information also depends on you. Where we have given you (or where you have chosen) a password and/or API key for access to the Platform, you are responsible for keeping this information confidential.

Unfortunately, the transmission of information via the internet is not completely secure. Although we do our best to protect your Personal Data, we cannot guarantee the security of your Personal Data transmitted to us. Any transmission of Personal Data is at your own risk. We are not responsible for circumvention of any privacy settings or security measures contained on the Platform.

10.2 Retention

We will only retain your Personal Data for as long as necessary to fulfill the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period for Personal Data, we consider the amount, nature, and sensitivity of the Personal Data, the potential risk of harm from unauthorized use or disclosure of your Personal Data, the purposes for which we process your Personal Data and whether we can achieve those purposes through other means, and the applicable legal requirements.

In general, we retain data as follows:

  • Threat Intelligence Data (network-observed): As described in Section 4, the Threat Intelligence Data our own sensor network collects about systems that scan, probe, or attack internet-connected infrastructure — including connection metadata and full-packet captures — is data we collect ourselves and is not customer data or Personal Data that you provide to us. We retain this data indefinitely as part of our historical threat intelligence dataset. Our Platform and API provide a rolling lookback window of up to 90 days for querying this data, and the lookback period available to you may depend on your subscription tier.
  • Customer account and usage data: This is the account and product-usage data associated with your subscription (the data you provide to us and the record of your use of the Platform), and is separate from the Threat Intelligence Data described above. We retain it for as long as you maintain a relationship with us, and thereafter unless and until you request its deletion (see Your Data Rights above). Backups are retained for up to 14 days.
  • Website visitor and analytics data: we use analytics and marketing providers, including Google Analytics and HubSpot, and this data is retained in accordance with those providers' data-retention settings and policies.
  • Operational and security logs: generally retained for up to 30 days.

11. Changes to our Privacy Policy

It is our policy to post any changes we make to our Privacy Policy on this page. If we make material changes to how we treat our Customer's Personal Data, we will notify you by email to the email address specified in your account. The date the Privacy Policy was last revised is identified at the top of the page. You are responsible for ensuring we have an up-to-date active and deliverable email address for you, and for periodically visiting our Site and this Privacy Policy to check for any changes. Your continued use of this Platform after we make changes is deemed to be acceptance of those changes.

12. Contact information

To ask questions or comment about this Privacy Policy and our privacy practices, or to exercise any of your rights, contact us at:

GreyNoise Intelligence, Inc.

1015 15th St NW, Ste 600

Washington, DC 20005

Email: [email protected]

Phone: +1 202-417-6189

Cut through the noise