Legal
Privacy Notice & Policy
This notice summarises the OSINTA.AI privacy posture: why data is processed, how it is protected, and how GDPR rights requests are handled.
Last updated: 18 June 2026
Data Controller and Contact
- Data Controller
- OSINTA LTD
- Address
- 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
- info@osinta.ai
The data controller responsible for the personal data described in this notice is OSINTA LTD, a company registered in England and Wales under company number 17263144.
Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. The company holds ICO registration reference ZC174082. For any privacy or data protection matter you can contact us at info@osinta.ai.
Legal inquiries: support@osinta.ai
1) Service scope
OSINTA helps each person see and understand their OWN public digital footprint — drawn from public sources and the inputs they choose to connect. Never anyone else's.
This notice explains the personal data processed in the course of providing the service, processing purposes, transfer and retention principles, and your rights under GDPR and applicable data protection laws.
How we collect information. OSINTA works on a self-only basis: it helps each person see and understand their own public digital footprint. We collect personal data in two ways.
Publicly available information. With your instruction, OSINTA searches openly available, public sources to assemble a view of your own footprint. We do not use these searches to build profiles of anyone other than you.
Information you choose to provide or import. This includes the details you give us directly (such as your name and email when you create an account, and an optional phone number for sign-in verification). In future, it will also include information you actively choose to share with us by importing your own account data from third-party platforms — for example, a copy of your own data exported from another service under your right to data portability (Article 20 of the UK GDPR). These portability integrations are not yet available; when they are, any such import will be initiated by you, will cover only your own data, and will be governed by the retention and use terms set out below.
2) Categories of personal data processed
To provide and securely operate the service, the following categories may be processed:
- Identity information: name, surname (in account/contact context).
- Contact information: email, optional phone number.
- Account and transaction security: IP address, session/login-logout records, security logs; passwords are stored only in hashed form.
- Payment/subscription: transaction/subscription identifiers produced by your payment provider (card information is not stored by us).
- Usage data: platform transaction history, outputs, and support requests (as applicable).
3) Processing purposes and legal basis
Your personal data may be processed for the following purposes under GDPR Art.6 and applicable data protection laws:
- Contract formation and performance: account creation, authentication, service delivery, reporting, and support.
- Legal obligation compliance: statutory record-keeping/reporting obligations and billing processes.
- Legitimate interest: service security, abuse prevention, performance/quality improvements, and product reliability.
- Explicit consent (where applicable): product updates, marketing communications, and optional communications.
4) Data transfers (domestic / international)
We share personal data with a limited set of service providers (“sub-processors”) who process it on our behalf and under contract, only to deliver the service — such as cloud hosting, email and communications, error tracking, website analytics for our public marketing site, sign-in verification, and payment infrastructure. We do not sell your data, and we do not share it with any third party for advertising or marketing. The named list is set out in section 8 below.
If a lawful request is received from authorised public authorities, sharing may occur within the scope of legal obligations.
If transfer outside the EEA is required, appropriate safeguards (e.g., Standard Contractual Clauses) are applied and transfer scope is kept to a minimum.
5) Retention periods
We keep personal data only for as long as needed for the purpose for which it was collected, and to meet our legal obligations. Account data is retained while your account is active; when you delete your data, we remove it from active systems, subject to any retention we are legally required to maintain.
Data you import from third-party services. Where you choose to import your own account data from a third-party platform (for example, under your right to data portability), we process that imported data to produce your results and then delete it within 30 days of the import being completed. We do not retain imported third-party archives beyond this period.
6) Your rights and requests
Under GDPR Art.15-22 and applicable data protection laws, you have rights including access, rectification, erasure, restriction of processing, objection, and (where applicable) data portability.
You may submit requests via email. Identity verification may be required.
To exercise any of the rights above, email us at info@osinta.ai or use the data-request route on this site. Tell us which right you wish to exercise and enough detail for us to locate your data.
To protect your data, we may need to verify your identity before we act. Under the UK GDPR we will respond without undue delay and within one month of receiving your request; if a request is especially complex we may extend this and will tell you why.
7) Updates
This notice may be updated from time to time. Significant changes will be communicated through reasonable means.
8) Service providers we use
We rely on a small set of service providers (sub-processors) to operate the service. Each is used only for the purpose described, under appropriate data processing terms:
- Google Cloud — hosting and infrastructure for the OSINTA service (EU region).
- Vercel — hosting and content delivery for this website.
- SendGrid — email for this website: waitlist confirmations and contact enquiries.
- Plausible Analytics — cookieless analytics for our public marketing website only; it holds no personal data. The OSINTA app itself carries no analytics or advertising tracking SDKs — the only components embedded in the app are crash reporting and sign-in.
- Anthropic (Claude) and OpenAI — the AI services that generate OSINTA AI assistant replies and analysis, under data processing agreements; Anthropic does not use your data to train its models.
- SerpApi and Exa — open-web search connectors used to locate publicly available information about you; the search terms are drawn from your own details.
- LeakCheck — data-breach lookups, queried using hashed values rather than raw identifiers.
- Twilio — one-time passcodes, by SMS and email, for sign-in verification.
- Apple — Sign in with Apple, and push notifications.
- Google — Sign in with Google.
- Sentry — crash and error reporting (EU region).
- Internet-infrastructure check providers — to check public records for domains or IP addresses associated with you.
- We keep this list current. A full, named list of our sub-processors is available on request.
9) Your right to complain
If you are not satisfied with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority, at ico.org.uk. We would, however, welcome the chance to address your concerns first — please contact us at info@osinta.ai.
10) Uses we rule out
We use your personal data only for the purposes set out above — providing, securing and supporting the service, meeting our legal obligations, and, where you have consented, sending optional communications. To be explicit about what we do not do:
- We do not sell, rent or trade your data.
- We do not share your data with advertisers or data brokers, and we do not use it for advertising or marketing profiling.
- We do not use your data to research or build profiles of other people. OSINTA is self-only: it works on your own footprint.
- Your findings are yours.
11) How we protect your data
We apply technical and organisational measures designed to protect your personal data, including the safeguards below. Passwords are stored only in hashed form. For more detail, see the Security page on this site: osinta.ai/en/security.
- Hosting in the EU. Your data is hosted on Google Cloud in the European Union region.
- Encryption. Data is encrypted in transit (TLS), and encrypted at rest through Google Cloud's infrastructure-level encryption.
- Minimised findings at rest. Where possible, findings about your footprint are stored in hashed or masked form rather than as raw values.
- Self-only access, enforced by the system. Access to footprint data is scoped to the account it belongs to and enforced server-side, so a user can only ever access their own data — never anyone else's. Internal access is limited to support and operations when genuinely needed.
- Minimal embedded components. The app carries no analytics or advertising trackers; only crash reporting and sign-in components are embedded.
Review our compliance approach
Use the Trust Center and documentation for policy-level review; contact us about your own privacy requests.