Plain language. No dark patterns. Here’s exactly how we handle your data and what we both agree to.
The short version: We collect only what we need to monitor your accounts and deliver our service. We never sell your data. We never store your passwords. You can delete your account and all associated data at any time. If we file takedowns for you, we verify your identity first, and your ID photo is deleted as soon as we no longer need it for your case.
Thuros Security ("Thuros," "we," "us," or "our") is committed to protecting your personal information. This Privacy Policy explains what data we collect, how we use it, and the rights you have over it when you use our website at thurossecurity.com and our social media monitoring service (collectively, the "Service").
To provide the Service, we ask for your social media usernames on the platforms you want monitored. Defend and Managed scan Instagram, TikTok, Facebook, and YouTube daily; Watch scans weekly. We use these to:
We use the information we collect to:
Impersonators steal photos as often as they steal names, so part of deciding whether an account is pretending to be you is comparing the photo it uses against a photo of you. Because that involves faces, here is exactly what we do and do not do.
A similarity score is one signal among several, never the whole judgement — profile photos are small and often ambiguous, so a match is reviewed by a person before it reaches you or a platform.
We work with a limited number of vendors to operate the Service. This is the complete list of the ones that handle data on our behalf:
Each of these providers publishes data processing terms that govern our use of their service, restrict them to processing data on our instructions, and set out their own security obligations and subprocessors. We do not permit any of them to use your data for their own purposes, and we do not sell or share your data with anyone outside this list except where the law requires it.
To tell you whether your email address has turned up in a known data breach, we look it up against Have I Been Pwned, the breach-notification service operated by Superlative Enterprises Pty Ltd in Queensland, Australia. We check once when you sign up and once a day while your plan is active.
It sits outside the list above because it is not working on our behalf: it answers a question against a database it built and maintains for its own purposes, on its own terms, in the way a reference service does. Per its published privacy policy, a search “only ever retrieves the data from storage then returns it in the response” and the result “is not explicitly stored anywhere” — so your address is used to answer the question, not kept by them as a record that you were looked up.
Your email address is the only thing sent for this check, and Australia is the only place it goes. Nothing else about your account — your handles, your case, your identity document — is included.
We retain your account data for as long as your account is active. If you cancel, we delete your personal data within 30 days of your request, except where we are required to retain records by law (e.g., billing records for up to 7 years under tax law). Anonymized, aggregated analytics are retained indefinitely.
Identity verification photos follow a stricter rule. For a one-time removal, we delete the photo when your case closes. For monitoring subscriptions, including Watch customers who verify to unlock the takedown kit, we keep it while your subscription is active because reports we file require it, and we delete it when you cancel. We also delete it promptly if verification is declined or on your request at any time (a deletion request pauses filing until you re-verify). Only the verification outcome, its date, and our reviewer's brief note are retained after deletion.
The short version: Your government ID photo is the most sensitive thing we ever hold, so it gets the strictest handling of anything in the Service. And if we ever suffer a breach that exposes your information, we will tell you — promptly, in plain language, and whether or not the law requires it in your particular case.
Thuros is based in New York State, so our security obligations are set by New York’s Stop Hacks and Improve Electronic Data Security (SHIELD) Act, alongside the other privacy laws described on this page. We maintain administrative, technical, and physical safeguards appropriate to our size and to the sensitivity of what we hold. In practice that means:
When we file takedowns for you, platforms require proof that you are the person being impersonated, which is why we ask for one photo of you holding your government ID. It is handled apart from everything else in the Service:
No safeguard is perfect, so here is our commitment if one fails. If we discover a breach affecting your personal information, we will notify you without unreasonable delay after confirming what happened — by email to the address on your account, and by posting notice here if we cannot reach you. That notice will tell you what happened and when, what categories of information were involved, whether your identity document was among them, what we have done in response, and what we recommend you do.
We will also make the notifications the law requires of us — including to the New York State Attorney General, Department of State, and State Police under the SHIELD Act, to other state regulators where their law applies, and, for people protected by the GDPR, to the relevant supervisory authority within 72 hours of becoming aware of a qualifying breach. We will not delay telling you in order to finish an investigation; if we know something incomplete but important, you will hear the incomplete version first.
To report a vulnerability or a suspected breach to us, email team@thurossecurity.com with “Security” in the subject line. We read those first, and we will not pursue anyone who reports a genuine vulnerability to us in good faith.
Depending on where you live, you may have the following rights regarding your personal data:
To exercise any of these rights, email us at team@thurossecurity.com. We will respond within 30 days. We will never charge you for exercising your privacy rights.
This does not need an email. The button below switches our analytics off for this browser straight away: the analytics script stops loading, any Google analytics cookie already set is deleted, and the first-touch record of how you found us is cleared. It is remembered per browser, so if you use another browser or clear your site data you will need to set it again.
Analytics is currently on for this browser.
California residents have additional rights under the California Consumer Privacy Act, including the right to know what categories of personal information we collect and the right to opt out of sale (note: we do not sell personal information). To submit a CCPA request, use the contact information above.
If you are located in the European Economic Area, our legal basis for processing your data is the performance of our contract with you (to provide the Service), our legitimate interests (security monitoring and fraud prevention), and your explicit consent where required. You also have the right to lodge a complaint with your local supervisory authority.
These Terms of Service ("Terms") govern your use of Thuros Security's website and monitoring service. By creating an account or using the Service, you agree to these Terms. If you do not agree, please do not use the Service.
Thuros provides social media account monitoring, threat detection, and human-assisted account recovery. Every plan scans Instagram, TikTok, Facebook, and YouTube — weekly on the Watch plan, daily on the Defend and Managed plans; plans also differ by how takedowns get filed. Thuros also offers a one-time Impersonator Removal service, described below. The specific features available to you depend on the plan or service you purchase. We reserve the right to change, improve, or discontinue features with reasonable notice.
Scan cadence is the schedule we work to, not a guarantee. Monitoring depends on the platforms themselves and on third-party data providers we do not control, so a scan can be delayed, incomplete, or unavailable when those sources are down, rate-limited, or change how they work. When a scan is incomplete we treat the result as inconclusive and say so — we do not report a partial scan as clear.
By subscribing to the Defend or Managed plan and granting takedown authorization at signup, or by purchasing the one-time Impersonator Removal service and granting takedown authorization at intake, you grant Thuros Security the following authorization.
1. Appointment. I appoint Thuros Security and its authorized representatives as my authorized agent and attorney-in-fact for the limited purposes set out in section 2 only, in respect of reports made to Instagram, TikTok, Facebook and YouTube.
2. Purposes. This authorization permits Thuros Security, on my behalf:
(a) to report accounts that impersonate me, misuse my identity, or target my audience with scams, and to submit, manage and follow up on those reports;
(b) where a reported account uses photographs or other content I own without my permission, to prepare, sign and submit intellectual-property (copyright) reports and notices, including notices under the Digital Millennium Copyright Act, and to make on my behalf the statements such notices require, including the statement that the sender is authorized to act for the copyright owner;
(c) to respond to, withdraw, or decline to contest any counter-notice, appeal or dispute raised against a report submitted under this authorization;
(d) to appeal, escalate and re-submit any report a platform rejects, and to correspond with platform support about it;
(e) where I own a brand name, logo or other mark, to submit trademark reports against accounts misusing it; and
(f) to submit privacy, likeness and personal-image reports where an account uses my image or personal information without my permission.
Platforms may send correspondence about these reports to Thuros Security, and Thuros Security may receive and act on it for the purposes above.
3. Limits. This authorization does not grant Thuros Security access to, or control of, my accounts, passwords or content; does not authorize any payment, contract or settlement on my behalf; and does not authorize the commencement or conduct of any lawsuit, arbitration or other legal proceeding. Thuros Security is not a law firm, does not provide legal advice, and this authorization does not create an attorney-client relationship.
4. Ownership. I confirm that I created, or hold the rights to, the content I identify as mine under this authorization, and that I have not given the reported accounts permission to use it.
5. Term. This authorization takes effect on the date signed below and remains in effect until I withdraw it in writing to team@thurossecurity.com.
Where you grant this authorization on or after 30 August 2026, you do so by typing your full legal name as an electronic signature. We keep that signature together with the date, time, and network address it was submitted from, and can produce it as a signed Limited Power of Attorney when a platform requires documentary proof that we act for you. Your network address is retained as evidence of the signing and is never included in any document filed with a platform.
Thuros is a monitoring and takedown service, not a law firm. We act as your authorized representative in reporting accounts to platforms — the role a manager or agent plays when filing on a client’s behalf — using each platform’s own reporting process. We do not provide legal advice, we do not represent you in any legal proceeding, and nothing we send you is legal advice or creates an attorney-client relationship. If your situation may need a lawyer — you are considering suing an impersonator, or someone has threatened or served you with something — please speak to one.
The Impersonator Removal service is a one-time engagement at a flat price, with no subscription or account required. It includes: (a) a scan of Instagram, TikTok, Facebook, and YouTube for accounts impersonating the identity you provide at intake; (b) takedown reports, with supporting evidence, filed on every impersonating account we confirm; and (c) an emailed report of what we found and the reports we filed. Work typically begins within 1–2 business days of payment.
Before we file any takedown report, we verify that you own the impersonated identity. We ask for a photo of you holding your government ID, which the platforms themselves require for reports filed by a representative, and a signed authorization to file on your behalf. If we cannot verify ownership, we do not file; on a one-time removal we refund the purchase in full.
We file and follow up on takedown reports diligently, but the decision to remove a reported account — and how quickly — rests solely with each platform. Because we cannot force a platform's hand, we back the service with the guarantee below so that the risk sits with us, not with you.
The guarantee. Every impersonating account we confirm and file takedown reports on is tracked to resolution. If a confirmed account has not been verified down within 30 days of the date we file the first takedown report on that account, we will refund that account's share of your fee — the flat fee divided by the number of confirmed accounts we filed on. Example: we file on 5 accounts and 4 are removed — you receive one fifth of your fee back. If no accounts are removed, you receive a full refund. "Verified down" means any of the following: the account has been removed, disabled, suspended, or made permanently inaccessible by the platform; or the account no longer impersonates you — for example, the impersonating name, profile photo, bio, posts, or other identifying content have been removed or changed so that the account no longer presents itself as you. This applies even if the account or its username remains registered: platforms do not remove accounts that are no longer violating their rules, so an account that has stopped impersonating you is a successful resolution of the takedown and is treated as verified down under this guarantee. Whether an account still impersonates you is assessed on the account as it appears at the time of review. This 30-days-from-filing clock applies to orders placed on or after September 14, 2026. On orders placed before that date, the 30 days run from the date of purchase.
How it works. We review each account once its 30 days have run. If anything is still up, we contact you with the choice: take that account's share of your fee back, or have us continue working those accounts at no additional charge. Refunds go to your original payment method and are processed within 5 business days.
60-day re-impersonation watch. When an account on your order is resolved because it stopped impersonating you (rather than being removed outright), we keep that username under watch for 60 days from the date we mark it resolved. If the same account resumes impersonating the identity covered by your order within that window, we will file new takedown reports against it at no additional charge. This watch covers re-filing only — it does not restart the 30-day guarantee or its refund terms, and it applies to the specific accounts resolved on your order, not to new accounts created elsewhere (our monitoring plans cover those).
Other refunds. You may cancel your order for a full refund at any time before we begin work. If our scan finds no impersonating accounts to report, we will say so in your report and, on request, refund your payment less a $50 search fee. That fee covers the specialist search itself, which is substantially deeper than our free scan: it checks 55 look-alike spellings of your handle on each of the four platforms — more than 200 profile checks — searches for your real name on all four, and compares the display name, profile photo and bio of every candidate it surfaces against your real account, with a person reviewing each one by hand. That work is performed whether or not it finds anything. The guarantee does not apply to accounts where you revoke takedown authorization or ask us to stop work before resolution. To cancel or ask any refund question, email team@thurossecurity.com.
Automatic renewal — please read this part. Watch, Defend and Managed are automatic-renewal subscriptions. Once any free trial ends, your payment method is charged the plan price for the billing interval you chose — $25, $50 or $100 per month, or $225, $450 or $900 per year — and it is charged again automatically at the start of every following interval at the same rate, plus tax where applicable, until you cancel. You can cancel at any time, online, in a few clicks, from the billing section of your dashboard — no phone call and no email required. Cancelling stops all future charges.
New subscriptions include a 14-day free trial, and you are not charged during it. Unless you cancel before the trial ends, the trial converts automatically into a paid subscription at the price and interval you selected, and renews automatically after that as described in section 3. You may cancel at any time during the trial, from your dashboard, at no cost and for any reason.
If you are not satisfied after your first paid charge, contact us at team@thurossecurity.com within 14 days of that charge for a full refund. Refunds are processed within 5 business days of your request.
Thuros provides monitoring, takedown filing, and recovery assistance. Except for what these Terms expressly promise — above all the 30-Day Removal Guarantee, which we stand behind — the Service is provided "as is" and "as available," and we disclaim all other warranties, express or implied, including any implied warranty of merchantability, fitness for a particular purpose, title, and non-infringement.
We cannot guarantee detection. Impersonation monitoring searches public information on platforms we do not control. We do not guarantee that we will find every account impersonating you, and a scan that reports nothing is not proof that nothing exists. Platforms limit and change what is publicly searchable, impersonators actively work to avoid detection, and our data providers can be unavailable or incomplete. A scan is a record of what we found, not a certification of what is out there.
We cannot guarantee outcomes. We cannot guarantee that every breach will be prevented, every reported account removed, or every account recovered. Social media platforms make the final decision about whether and when to remove or restore an account — our role is to advocate on your behalf as effectively as possible, and the 30-Day Removal Guarantee exists precisely so that the risk of a platform declining to act sits with us rather than with you.
Availability. The Service depends on third-party platforms and data providers. Scanning, alerting, and filing may be delayed or interrupted when those services are down, rate-limited, or change how they work, and we may suspend the Service for maintenance. We are not liable for those interruptions — but they do not relieve us of the guarantee above.
To the maximum extent permitted by law, Thuros's total liability to you for all claims arising from these Terms or the Service shall not exceed the greater of (a) the amount you paid us in the 12 months preceding the event giving rise to the claim, or (b) $100.
We are not liable for indirect, incidental, special, consequential, or punitive damages, including lost profits, lost business, reputational harm, or loss of data, even if we have been advised of the possibility of such damages.
Nothing in these Terms limits or excludes any liability that cannot lawfully be limited or excluded — including liability for fraud or fraudulent misrepresentation, for gross negligence, or under consumer protection laws that cannot be waived. Some jurisdictions do not allow certain exclusions, so parts of this section may not apply to you.
You agree to defend, indemnify, and hold harmless Thuros Security and the people who work on it from any third-party claim, demand, loss, liability, or expense (including reasonable legal fees) arising out of:
Why this is here, plainly: we act on your instruction. When you tell us an account is impersonating you, or that a photograph is yours, we file reports — and, for copyright, sworn notices — with platforms on that basis. Knowingly misrepresenting that a use of content is infringing carries liability under United States copyright law, including Section 512(f) of the Digital Millennium Copyright Act, and that liability belongs to the person who made the misrepresentation. We may take over the defence of any claim covered by this section, and you agree to cooperate with us if we do. We will not settle a claim in a way that imposes an obligation on you without your consent.
The Thuros name, logo, website, and all content and software are owned by Thuros Security and protected by copyright, trademark, and other laws. You may not copy, reproduce, or distribute any part of the Service without our express written permission.
We may suspend or terminate your account if you violate these Terms, engage in fraudulent activity, or use the Service in a way that damages us or others. You may terminate your account at any time from your dashboard. Upon termination, your right to use the Service ends immediately. Sections 5, 6, 7, 10, 11 and 12 survive termination, along with any payment obligation already incurred.
Talk to us first. Almost everything is faster to fix by email than any other way. Before either of us files a formal claim, that person agrees to send a written description of the dispute and the outcome they want — to team@thurossecurity.com if it is you — and to allow 30 days to resolve it. This is a real requirement, not a formality. It does not stop either of us from seeking an injunction, or from filing in small claims court, at any time.
Small claims. Either of us may bring a qualifying individual claim in small claims court instead of the courts named in section 11.
Time limit. Any claim arising out of these Terms or the Service must be brought within one year after it arises, or it is permanently barred — unless applicable law does not permit a shortened period, in which case the shortest period the law does permit applies.
Individual claims. To the extent permitted by law, claims must be brought in an individual capacity and not as a plaintiff or class member in any class or representative action.
These Terms are governed by the laws of the State of New York, without regard to conflict of law principles. Any dispute arising from these Terms or the Service shall be brought exclusively in the state courts located in Onondaga County, New York, or in the United States District Court for the Northern District of New York, and you and Thuros each consent to the personal jurisdiction and venue of those courts.
We may update these Terms from time to time. We will notify you by email and by posting the new Terms on this page at least 14 days before changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the new Terms.
If you have any questions, concerns, or requests related to your privacy or these Terms, please reach out directly. We are a small team and we read every email.
Thuros Security is an American-owned and operated company. Our services are provided from the United States.