Privacy by Design

OSINTScan Privacy Policy

Last updated: September 2026. We believe digital footprint auditing should never compromise your own privacy.

1. What Data We Process & Ephemeral Storage

When you enter an identifier into OSINTScan (username, email, or phone number), that query is sent to our scanning engine solely to perform parallel checks against public profile endpoints and OSINT datasets.

No Permanent Search Logs: Anonymous scan queries are processed in server memory (RAM) and are not stored in a persistent database.

Scan Job Lifespan: In-memory scan sessions and their associated results are automatically wiped from server memory within 30 minutes after completion.

2. What We Never Do

  • We do not attempt to access private or password-protected accounts.
  • We do not bypass CAPTCHAs, bot walls, or access control systems.
  • We do not collect passwords, cookies, or authorization tokens.
  • We do not sell, rent, or trade your queries to advertisers or data brokers.
  • We do not create public, indexable search pages of searched usernames.

3. IP Addresses & Rate Limiting

To prevent automated abuse, denial of service, and spam, our backend maintains an in-memory sliding-window counter of requests per IP address. These counters expire automatically after 5 minutes and are never linked to personal identity.

4. Analytics & Telemetry

If site analytics are enabled, telemetry is strictly anonymized. We never send search queries, usernames, or scan result URLs to third-party analytics providers.

5. Contact Us

For privacy inquiries or technical questions, contact the maintainers at privacy@whatsmyname.app.