Who is responsible
QuizNoir and ThreatNoir Academy are run by Marcus Lenngren in Sweden, trading as ThreatNoir (organisation number available on request). Write to academy@threatnoir.com with any question about your data.
- For the public quiz, the Academy pilot form and this website, ThreatNoir is the controller of your personal data.
- If your organisation enrolled you in ThreatNoir Academy, your organisation is the controller of your training record, and ThreatNoir processes it on its behalf under our data processing agreement. Questions about how your organisation uses the record go to your employer, and we help them answer.
Playing the quiz
You can play without an account.
- Player token: when you start your first quiz, your browser stores a random player token that ties your results and your streak together. Nothing is stored before you start.
- Display name and results: the name you choose appears with your score and time on that quiz's leaderboard and on any share card you create. We keep each answer you give, to show your result and to publish anonymous statistics such as how many players missed a question.
- Challenges: if you start a challenge, we store its name and code.
- Fair-play limits: we store a keyed hash of your IP address with each attempt, to cap attempts per network per day, and remove it after 30 days.
Visit statistics
Each page view, and a few quiz events such as starting or finishing a quiz, send us the page path, the website that sent you and any campaign tags, together with your player token if you already have one. Paths never include invitation or unsubscribe tokens. No cookies are involved, and no third-party analytics service. If your browser sends Global Privacy Control or Do Not Track, it sends none of this. We keep these events for 24 months.
What we store in your browser
We set no advertising or analytics cookies, which is why there is no cookie banner. The site's framework saves one display setting (dark mode) in your browser, with no identifier in it. Everything else is stored only when you use a feature that needs it:
- Playing: your player token and display name when you start a quiz, and which quizzes you have finished.
- A quiz in progress: a checkpoint, so reloading the page doesn't lose your place. It is cleared when you finish or close the tab.
- Signing in to the Academy: cookies that keep you signed in, removed when you sign out.
You can clear all of these in your browser settings at any time.
ThreatNoir Academy
If your organisation enrolled you, we process on its behalf:
- your work email address, a display name if one is set, your role, and whether you belong to the management body;
- when you were invited, joined or removed;
- for each exercise: whether you completed it, when, and your score.
What your administrators see: completion, time and score per person, and which questions were missed most across the organisation once at least five people have answered. They never see which answers you got wrong.
We email you the invitation, sign-in links, one message when each week's exercise is published, and any quiz your organisation sends you. Every message has an unsubscribe link. When you sign in, any quiz history from this browser is linked to your account.
If you administer an organisation, we also process your email address and what you do in the service, such as invitations, exports and Studio drafts, and send you a weekly digest of your organisation's completion. The brief and material you give Studio are screened for personal data and then sent to our AI provider to draft questions, which you review before anything is published.
Academy pilot requests
If you ask for a pilot, we store your company, work email address, headcount band, message and a keyed hash of your IP address, and email the request to ourselves. We use it to reply and set up the pilot, and delete it after 12 months.
Emails
We send email through Resend, from signin@ and academy@threatnoir.com. Our emails contain no tracking pixels, and their links are not rewritten to track clicks. To limit how often an address is emailed, our send log keeps a keyed hash of the address, not the address itself.
Why we use your data
- The quiz, leaderboards, share cards and challenges: to provide the quiz you chose to play (GDPR Article 6(1)(b)).
- Statistics and fair-play limits: our legitimate interest in a working, fair and secure service (Article 6(1)(f)), using hashed data wherever we can.
- Pilot requests: to take the steps you asked for before a contract (Article 6(1)(b)).
- Academy records: processed for your organisation, on its legal basis, for example its obligation to train staff under NIS2 or DORA. We act only on its instructions.
We do not sell personal data, use it for advertising or make automated decisions about you.
Who helps us
These providers handle personal data for us, only to run the service:
| Provider | What they do | Where |
|---|---|---|
| Supabase | Database and sign-in | EU (Ireland) |
| Vercel | Hosting the website | EU (Stockholm) for the site's server code, plus a global delivery network. Vercel Inc. is based in the USA. |
| Resend | Sending email | USA |
| Anthropic | Studio only: drafting questions from an administrator's brief and material, after the personal-data screen | USA |
| Google Workspace | Our email inbox: messages to academy@threatnoir.com | Google's data centres in the EU and the USA |
The weekly quiz is written with AI from public news reporting. Apart from Studio material, your personal data is not sent to AI services. When a provider handles personal data outside the EU/EEA, the transfer is covered by the EU-US Data Privacy Framework or by the European Commission's standard contractual clauses.
How long we keep data
- Quiz results, display names and streaks: for as long as the quiz archive exists. Ask us and we remove a display name or your results.
- Keyed IP hashes: 30 days.
- Visit statistics and quiz events: 24 months.
- Pilot requests: 12 months.
- Academy records: while you are a member and for 24 months after you leave, unless your organisation sets a shorter period. After that your name and email address are erased, and the training register shows you as "Former member". When an organisation's subscription ends, we delete its data within 30 days, and backups expire within a further 30 days.
- Studio drafts: kept with the organisation's quizzes and deleted with its data.
Your rights
You can ask for a copy of your data, have it corrected or deleted, restrict or object to how we use it, and get it in a portable format. For an Academy record you can ask your organisation or us, and we will work with your organisation on the answer. Write to academy@threatnoir.com and we will answer within a month. Every email has a one-click unsubscribe link.
If you think we handle your data wrongly, you can complain to the Swedish Authority for Privacy Protection (IMY) or to the data protection authority where you live.
Security
All traffic is encrypted. The database denies all direct access: every read and write goes through our server, which checks which organisation a request belongs to. Sign-in uses single-use links, so there are no passwords to steal. Invitation and API tokens are stored only as hashes, and IP and email addresses in our logs only as keyed hashes. Automated tests cover the separation between organisations and the lockout of anonymous database access.
Children
QuizNoir is not aimed at children under 16, and we don't knowingly collect their data.
Changes to this notice
We change the date at the top whenever this notice changes, and tell Academy administrators by email about significant changes.