Legal

Acceptable Use

What you may and may not do with OSINT Pro, and the limits we enforce.

Last updated 2026-09-2412 sections
01

Permitted

Checking your own exposure across breached datasets.

Authorized security assessment of an organization you work for or have written authorization to test.

Investigative research where you have a lawful basis and the identifier is lawfully in scope.

Academic or journalistic research conducted with a documented lawful basis.

02

Not permitted

Locating, contacting, or surveilling an individual without a lawful basis.

Stalking, harassment, intimate partner monitoring, or doxxing.

Any use regulated by the Fair Credit Reporting Act, including employment, tenant, or credit eligibility screening.

Bulk automated extraction of result sets for the purpose of building or reselling a competing dataset.

Using the service to commit identity theft, account takeover, or fraud.

Querying identifiers belonging to minors.

03

Our enforcement

We keep an operational record of each query, limited to the lookup type, a record count, a timestamp and the key prefix. We do not retain the identifier you submitted beyond the request, and we do not retain result sets after your session.

We rate limit by account and by network origin. Where we identify a breach of this policy we suspend the account, and where the conduct is unlawful we may report it to the relevant authority.

04

Data subject requests

If you are the subject of a record returned by this service and want it corrected or removed, use the reporting and removal process rather than querying the service directly.

05

Scope of this policy

This policy explains what you may and may not do with the service. It forms part of the Terms of Service, and where the two conflict, the Terms of Service control.

It applies to everyone who runs a query, whether through the search interface or through an API.

06

Who may use the service

You may use the service only if you are at least 18 years old and legally able to enter into an agreement under the law that applies to you.

If you use the service for an organization, you must be authorized to bind that organization to this policy.

07

Identifiers that are out of scope

Identifiers belonging to a person under 18 are out of scope, and querying them is a breach of this policy.

Identifiers belonging to a person who is not you are in scope only where you hold a lawful basis to investigate them, and you must be able to state that basis if we ask.

08

Automated access and bulk queries

Automated access is permitted only through an API we have made available to you, within the limits of your plan. You must not scrape the interface, defeat a rate limit, or use multiple accounts to work around one.

You must not run bulk or sequential queries for the purpose of assembling, enriching, or reselling a dataset. A query volume consistent with extraction rather than investigation is treated as a breach, whether or not that was the intent.

09

Account key and credential rules

An account exists only for the person or organization it was created for. You must not share an access key, publish it, or resell access to the account.

You are responsible for activity carried out with your key. If you believe it has been disclosed, tell us so we can consider issuing a replacement.

10

Your responsibility under local law

You are responsible for your own compliance with the law where you are. That includes privacy and data protection law, do not call and electronic marketing rules, and any obligation you have to the person whose identifier you submit.

You must not use a Record to contact, solicit, or make a decision about a person where doing so would breach a law that applies to you.

11

Reporting a violation

If you believe another user of this service is breaching this policy, send what you have to support@osintpro.dev. Reports about harassment are treated as urgent.

12

Enforcement and referral

Where we find a breach we may mask results, throttle the account, suspend it, or close it, and we may refuse to serve the same person again.

Where conduct appears unlawful we may preserve the relevant account records and report it to law enforcement or to another authority with jurisdiction. We may also act on a lawful request from such an authority.