Legal
Privacy Policy
What we store, what we log, and what we deliberately do not collect.
What we do not collect
We do not ask for your email address and we do not store a password. Registration issues a generated access key, and only a SHA-256 hash of that key is stored.
What we do not log
We do not keep a searchable record of the identifiers you look up. A submitted identifier is passed to the sources being queried in order to answer the request, and is not written to a search history that you or we can browse later.
We do not keep a copy of your result sets. Export what you need before your session ends.
What we store
The hash and a short display prefix of your access key.
Your plan, credit balance, and an append only ledger of credit movements with a reason for each entry.
An operational query record limited to the lookup type, a record count, a timestamp and the key prefix, kept for abuse prevention and rate limiting. It does not contain the identifier you submitted.
A salted, one way hash of the network address a request arrives from, kept only to cap free lookups and account creation per connection. The address itself is not stored, and the hash is deleted on a rolling window.
Where you add a passkey, the public key material needed to verify it. Never a private key.
What we send to third parties
The identifier you submit is forwarded to the external data sources queried in order to return your result. It is not sent to advertising or analytics vendors.
We do not sell or rent query data.
Retention
Result sets are held for the duration of your session and are not retained after export. Operational query records are retained for abuse prevention on a rolling window.
Payment records are kept as required for accounting, alongside the transaction identifier issued by the payment processor.
Your rights
Because we do not collect an email address, we cannot identify you from an inbox. Requests about your own account are handled against the account key, and requests about a record concerning you as a data subject are handled through the reporting and removal process.
Who is responsible
The operator of OSINT Pro is OSINT Pro, a Delaware, United States entity, and it is the controller of the small amount of personal data described on this page.
Where you are the subject of a record returned from a third party source, that source is a separate controller of the underlying data. We cannot exercise its rights or its obligations for it.
Why we are allowed to hold it
We rely on the performance of our agreement with you in order to hold your key hash, plan, and credit ledger, because without them the service cannot function.
We rely on our legitimate interest in preventing abuse in order to hold the operational query record, which is limited to the lookup type, a record count, a timestamp, and the key prefix. We keep that to the minimum needed to rate limit and to stop bulk extraction.
We rely on a legal obligation in order to keep payment and tax records for the period the law requires.
International transfers
Some of the sources we query and some of the providers who host the service are located outside your country. Where an identifier you submit is forwarded to a source elsewhere, that transfer happens in order to answer your request.
We do not transfer your account data for advertising purposes, and we do not sell it.
Security
Traffic is served over TLS. An access key is stored only as a SHA-256 hash, so a copy of the database alone does not yield a working key. Passkeys are verified against public key material; we never hold a private key.
No system is perfectly secure. If we become aware of a breach affecting account data, we will notify affected accounts through the service and, where the law requires it, notify the relevant authority.
Children
The service is not intended for anyone under 18, we do not knowingly hold account data for a minor, and identifiers belonging to minors are out of scope for searching, as set out in the Acceptable Use policy.
Complaints
If you are unhappy with how we have handled your data, contact us first at support@osintpro.dev so we can try to resolve it.
You also have the right to complain to a data protection authority in the country where you live, where you work, or where the issue occurred.
Changes to this policy
The current version always appears on this page with its effective date. A material change to what we collect will be notified in the service before it takes effect.
Contact
Privacy questions and data subject requests go to support@osintpro.dev, or through the contact form.