Privacy Policy

Last updated: June 3, 2026

1. Introduction

OSINT Library ("we," "us," or "our") operates the website osintlibrary.com (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our Service. We are committed to protecting your privacy and handling your data in an open and transparent manner.

OSINT Library ("we") is the controller responsible for the personal data processed through the Service. For any privacy question, or to exercise your data-protection rights, contact us at privacy@osintlibrary.com.

This policy explains our practices so you can make informed choices. Where the law requires your consent for a specific purpose — for example, non-essential analytics cookies — we ask for it separately through the cookie banner rather than treating your use of the Service as consent, and you can withdraw it at any time. If you do not agree with this policy, please do not use the Service.

2. Information We Collect

2.1 Account Information

When you create an account, we collect your email address and a hashed password. We never store passwords in plaintext. If you enable two-factor authentication (TOTP), the TOTP secret is encrypted at rest.

2.2 User-Generated Content

When you interact with the Service, we may collect data you voluntarily provide, including:

  • Tool suggestions (tool name, URL, description)
  • Reviews and ratings of tools
  • Votes on tools
  • Bookmarked tools
  • Tool reports and feedback

2.3 API Keys

If you generate API keys to access our public API, we store a hashed version of each key along with metadata such as the key name, creation date, and usage statistics. The full API key is shown to you only once at creation time.

2.4 Usage Data

We automatically collect certain information when you visit the Service, including your IP address (which may be hashed for anonymization in reports and rate limiting), browser type, operating system, referring URLs, pages visited, and timestamps. This data helps us understand how the Service is used and improve it.

For aggregate usage measurement we use Vercel Web Analytics, Cloudflare Web Analytics, and Ahrefs Web Analytics (all cookieless and privacy-first), and — only with your consent — Google Analytics 4 and Microsoft Clarity. Clarity records anonymized interaction signals (clicks, scrolls, pointer movement) to build heatmaps and session replays that show how the Service is used; it masks text and form input by default. We do not use any of these tools to build advertising profiles or track you across other sites.

2.5 Cookies and Local Storage

We use minimal cookies and browser storage to operate the Service:

  • Session cookie (essential) — maintains your authenticated session
  • Theme preference (functional) — remembers your light/dark mode choice
  • Cookie consent (functional) — remembers your cookie preference
  • Google Analytics (analytics, optional) — _ga / _ga_* cookies, set only after you accept in the cookie banner. Used for aggregate, anonymized usage measurement. Withdrawing consent removes them.
  • Microsoft Clarity (analytics, optional) — _clck / _clsk cookies, set only after you accept in the cookie banner. Used for anonymized heatmaps and session replay. Withdrawing consent removes them.

We use no advertising or cross-site tracking cookies. Privacy- friendly, cookieless analytics (Vercel Web Analytics, Cloudflare Web Analytics, and Ahrefs Web Analytics) store nothing on your device and run without consent.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service
  • Authenticate your identity and manage your account
  • Process tool suggestions and user contributions
  • Enforce rate limits and prevent abuse (using hashed IP addresses)
  • Improve the Service based on aggregated, anonymized usage patterns
  • Respond to your comments, questions, and support requests
  • Send important notices about changes to the Service or this policy

Legal bases (where GDPR or similar laws apply). We rely on: performance of a contract to operate your account and provide the Service; our legitimate interests to keep the Service secure, prevent abuse, and improve it through aggregated metrics; your consent for non-essential analytics; and compliance with our legal obligations. You may object to processing based on legitimate interests at any time.

4. Information Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share information only in the following circumstances:

  • Service providers (processors) — We use vetted providers strictly to run the Service: hosting and content delivery (Vercel), database (Neon), transactional email (Resend), image storage and bot protection (Cloudflare), and error monitoring (Sentry, configured not to capture IP addresses or personal data by default). They process data only on our instructions and only as needed to perform their function.
  • Legal requirements — We may disclose information if required by law, court order, or governmental regulation.
  • Protection of rights — We may disclose information to protect the safety, rights, or property of our users or the public.

International transfers.Some of these providers process data on servers outside your country, including in the United States. Where data leaves the European Economic Area, the transfer is covered by the provider's Standard Contractual Clauses or an equivalent safeguard. Our database (Neon) and transactional email (Resend) are hosted in the European Union.

5. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • Passwords are hashed using bcrypt
  • TOTP secrets are encrypted at rest
  • API keys are stored as hashes
  • All data is transmitted over HTTPS
  • Rate limiting and IP hashing protect against brute-force attacks
  • Parameterized database queries prevent injection attacks

While we strive to use commercially acceptable means to protect your data, no method of transmission over the Internet or method of electronic storage is 100% secure.

6. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes described in this policy. Account data is retained while your account is active. To close your account or have your personal data erased, contact privacy@osintlibrary.com; we will action the request within 30 days, except where we are required to retain certain data for legal or security purposes.

Anonymized, aggregated data (such as usage statistics) may be retained indefinitely as it cannot be used to identify you.

7. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access — Request a copy of the personal data we hold about you
  • Rectification — Request correction of inaccurate or incomplete data
  • Erasure— Request deletion of your personal data ("right to be forgotten")
  • Data portability — Request your data in a structured, machine-readable format
  • Objection — Object to the processing of your personal data
  • Withdrawal of consent — Withdraw your consent at any time where processing is based on consent

To exercise any of these rights, please contact us at the email address below.

8. Children's Privacy

The Service is not intended for individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without parental consent, we will take steps to delete that information.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. You are advised to review this page periodically for any changes.

10. Contact Us

If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us at:

Contact

Email: privacy@osintlibrary.com