At a glance.
Limited collection: what we need to run, secure, bill and improve the Services, plus analytics only with your consent.
Searches: results go to your browser and are not kept in your Account unless you save them. The searched term is kept for up to 90 days for security, then anonymized.
No selling: we never sell or rent personal data.
Your rights: access, correction, deletion, portability, restriction, objection and withdrawal of consent. Account deletion is available in Settings.
If you may appear in results: Section 12 explains how we permanently suppress an identifier on request.
Contact: [email protected]
1. Who we are
The website rocksosint.com and the related Services are provided under the Rocksosint brand ("Rocksosint", "we", "us"), an open-source intelligence (OSINT) platform. We are the controller of the personal data described in this policy, meaning we decide how and why it is used. Privacy questions and requests: [email protected].
We process personal data in line with the EU General Data Protection Regulation and the UK GDPR ("GDPR") for people in the European Economic Area and the United Kingdom, the California Consumer Privacy Act as amended (CCPA) and other US state privacy laws where they apply, and the privacy laws of other places where we offer the Services. This policy covers the Website, the Platform, the API, our e-mails and our forms. It does not cover third-party websites we link to.
2. Who this policy covers
- Visitors of the Website;
- Users who create an Account, on the free or paid plans;
- Institutional contacts who fill in a form or ask for a proposal;
- Newsletter subscribers;
- People who may appear in the results of a search run by a user (Section 12).
3. Data we collect
What we collect depends on how you use the Services. Where data is required to provide a Service, not providing it means we cannot provide that Service.
| Category | What it includes |
|---|---|
| Identification and Account | E-mail address; name and profile picture (if you sign in with Google or GitHub); the identifier issued by the social-login provider; password (stored only as an Argon2id hash); plan; preferences and onboarding answers; Account creation date. |
| Billing | Card payments are processed by Stripe. We keep the customer and subscription identifiers Stripe issues, the plan, the payment status and the transaction history needed for accounting. We never store full card numbers. |
| Usage and security | IP address, date and time, browser and device information, approximate city and country of each session; Credits used; type of search, number of results and module telemetry (which sources answered, latency, errors); security events; error reports. |
| Searched term | The identifier you submit (for example an e-mail address or username), kept for up to 90 days for security and abuse prevention, restricted to administration, then anonymized. See Section 6. |
| Content you save | Investigations (results you chose to save, connections, notes), stored in your Account under your control, and AI-generated analyses, kept for 90 days. |
| Late-arriving results | When a slow source is still delivering a result, a snapshot of that search is held for up to 30 days so the late result can be attached and you can be notified. |
| Uploaded files | Images or files you upload for analysis, processed only for the requested function. See Section 6. |
| Marketing and attribution | Campaign identifiers (utm parameters, click identifiers such as gclid), the referral source you tell us, and marketing preferences; analytics and advertising data only with your consent (Section 9). |
| Communications | Support requests and replies; satisfaction surveys and feedback; cancellation reason; institutional forms (name, role, organization, e-mail, phone, city and country, number of users). |
We do not intentionally collect sensitive personal data (such as health, religion, sexual orientation, biometric or genetic data) about our users. We do not offer facial recognition or biometric identification.
4. How we collect it
- From you, when you register, sign in, subscribe, search, save content, upload a file, contact us, answer a survey or fill in a form.
- Automatically, through your use of the Website and Platform: server logs, session records and, with your consent, cookies and similar technologies (Section 9).
- From third parties: the social-login provider you choose; Stripe, which confirms the status of a payment; and anti-bot and security services that assess a request before it reaches us.
5. Purposes and legal bases
We process personal data only when we have a proper reason. Where the GDPR applies, the legal basis is shown below. Where we rely on legitimate interests, we have checked that our interest is not overridden by your rights; you can ask for a summary of that assessment.
| Purpose | GDPR legal basis |
|---|---|
| Creating, authenticating and managing your Account; applying plan limits | Contract, Art. 6(1)(b) |
| Running the searches you request and delivering results, Investigations and notifications | Contract, Art. 6(1)(b) |
| Payments, subscriptions, refunds and accounting records | Contract, Art. 6(1)(b); legal obligation, Art. 6(1)(c) |
| Security, fraud and abuse prevention, rate limiting, incident investigation, keeping the searched term for 90 days | Legitimate interests, Art. 6(1)(f); legal obligation, Art. 6(1)(c) |
| Monitoring errors and performance; aggregated statistics to improve the Services | Legitimate interests, Art. 6(1)(f) |
| Service messages (verification codes, receipts, changes to terms, security notices) | Contract, Art. 6(1)(b); legitimate interests, Art. 6(1)(f) |
| Marketing e-mail to existing and former customers, with opt-out | Legitimate interests, Art. 6(1)(f) |
| Newsletter and promotional messages to people who are not customers | Consent, Art. 6(1)(a) |
| Analytics, session replay and advertising measurement through cookies | Consent, Art. 6(1)(a) and ePrivacy rules |
| Generating an AI analysis you request | Contract, Art. 6(1)(b) |
| Answering requests from people who may appear in results, including keeping a suppression list | Legal obligation, Art. 6(1)(c); legitimate interests, Art. 6(1)(f) |
| Complying with law, court orders and requests from authorities | Legal obligation, Art. 6(1)(c) |
| Establishing, exercising or defending legal claims | Legitimate interests, Art. 6(1)(f) |
| Sharing with a successor in a merger, acquisition or restructuring, anonymized where possible | Legitimate interests, Art. 6(1)(f) |
6. Searches: what happens to the term and the results
Real-time processing. When you run a search, the identifier you submit is used to consult open, public and commercially available sources through our own modules and through the collection providers in Section 10, which act only while the query runs. Results are correlated and delivered to your browser.
Results are not kept in your Account, except when: (a) you save a result to an Investigation; (b) you request an AI analysis, in which case the evidence sent to the model and the resulting text are stored in your Account for 90 days; or (c) a slow source is still delivering a late result, in which case a snapshot of the search is held for up to 30 days and deleted automatically.
Searched term. For security, abuse prevention, usage limits and operational metrics, we log each search's metadata (time, type, number of results, Credits) and the searched term. The term is restricted to administration, kept for up to 90 days and then anonymized.
Technical cache. To avoid re-querying sources for an identical query, a short-lived in-memory cache may keep a result for 24 hours to 7 days depending on the type of search. The cache key is a cryptographic hash of the query, is not linked to your Account, and entries expire automatically.
Uploaded files. Files you upload are processed only for the requested function. For reverse image search, the photo is made available for a few minutes at a temporary, unlisted address so the search service (Google Lens, via Scrapingdog) can read it; it is held in memory only, discarded when the query ends, and never written to disk or backup. We do not create biometric templates.
Your role. For the personal data of people you search, you are the controller and Rocksosint acts as processor, under the Data Processing Addendum in the Terms of Service. You need a lawful basis for that processing. Information being public is not, by itself, a lawful basis.
7. AI-generated analysis
If you request an AI analysis, a compressed version of the results of that search is sent to our AI provider (Anthropic) only to generate the text. The provider processes it under contract, does not use it to train models, and does not keep it longer than needed to return the response. The evidence and the analysis stay in your Account for 90 days; then their content is removed and only a masked reference, the status and the date remain. This produces content at your request; it is not a decision about you or about the person searched.
8. Marketing
Service messages (verification codes, receipts, security alerts, changes to terms, late-result notices) are part of the Service and cannot be switched off while you have an Account.
Customer marketing. If you are or were a customer, we may e-mail you about your plan, credits, features, offers and tips. You can opt out at any time through the unsubscribe link in each message; this does not affect service messages.
Newsletter. Sent only to people who subscribed; every issue has an unsubscribe link.
Advertising measurement. If you accept marketing cookies and arrive through an ad, we may report the conversion (sign-up or purchase) to the ad platform with the click identifier it issued. We do not upload your name or e-mail to ad platforms for this.
We never sell, rent or share personal data with third parties for their own marketing.
9. Cookies and similar technologies
- Essential (always on): authentication session (HttpOnly), protection against request forgery, your cookie choices, and security cookies from our content-delivery and anti-bot provider (Cloudflare, including the Turnstile challenge on sign-up and login). They are needed for the Services to work.
- Analytics (with consent): Google Analytics and Microsoft Clarity, to understand how the Website and Platform are used (pages, session duration, interactions, heatmaps and session replays with form inputs masked).
- Marketing (with consent): Google Ads, to measure campaigns and conversions.
You choose analytics and marketing cookies in the consent banner and can change your choice at any time from the banner or your browser. We honor Global Privacy Control signals as an opt-out of marketing cookies where the law requires it.
10. Who we share personal data with
We share personal data only with providers that help us operate the Services, under written contracts that limit them to processing on our instructions with appropriate security, and with the other recipients below.
| Provider | Function | Location |
|---|---|---|
| Stripe | Card payments and subscription management | United States / Ireland |
| Neon | Managed database for Account data | United States |
| Akamai / Linode | Server hosting | United States |
| Cloudflare | Content delivery, security, anti-bot (Turnstile) | United States (global network) |
| Resend / Brevo | Transactional e-mail, lifecycle e-mail and newsletter | United States / France (EU) |
| Social login; Analytics and Ads (with consent); reverse image search (Google Lens) | United States | |
| GitHub | Social login | United States |
| Microsoft Clarity | Analytics and session replay (with consent) | United States |
| Sentry | Error and performance monitoring | United States |
| Anthropic | AI analysis (only when you request it) | United States |
| Scrapingdog | Collection of publicly available data during a query | India |
| Bright Data | Collection of publicly available data during a query | Israel / United States |
We may also share personal data with professional advisers bound by confidentiality; with law-enforcement agencies, courts and regulators where required by law or to protect the rights, property or safety of Rocksosint, our users or others; and with a successor or prospective acquirer in a merger, acquisition or restructuring, anonymized where possible and under confidentiality. We update this list when we add or replace a material provider.
11. International transfers
Our providers are located in several countries, mainly the United States and the European Union. If you are in the European Economic Area or the United Kingdom, your personal data is transferred outside it to the providers in Section 10. These transfers rely on an adequacy decision where one exists, on the EU-U.S. Data Privacy Framework (and its UK Extension) for certified providers, or on standard contractual clauses. You can ask us for details of the safeguards used.
12. People who may appear in results
The Services consult open, public and commercially available sources at the moment a user runs a query. If you think your personal data may appear in a result, this is what we do.
What we do not do. We do not notify people that they were searched, we do not build profiles of searched people for our own purposes, and we do not keep results in a user's Account unless the user saves them (Section 6).
What you can ask. You can exercise the rights in Section 15, including objection and erasure. On a verified request we will:
- add the identifiers you indicate (such as e-mail addresses, usernames or phone numbers) to a suppression list, so they are no longer accepted as search terms or returned as results. The list stores only a cryptographic hash of each identifier and stays in effect permanently, even if a source republishes the data;
- remove any copy of the identifier in our own records within the retention periods in Section 13, except where the law requires us to keep it;
- tell you which kinds of sources the information usually comes from and how to request removal at the original source, which stops it being found by anyone, including through other tools;
- confirm the actions taken in writing, with the date.
Who searched you. Search records are the personal data of the user who ran the search. We do not disclose that user's identity to the person searched, except under a court order or where the law requires it. We act on your request regardless of who ran the search. Requests are free.
13. Retention
We keep personal data only as long as needed for its purpose.
| Data | Retention |
|---|---|
| Account data | While the Account is active. Deleted when you close the Account; copies in routine backups are overwritten in the ordinary course. |
| Record of a closed Account (e-mail, payment and subscription identifiers, plan) | 180 days after closure, to reconcile billing, prevent fraud and honor a subscription if you return; then deleted. |
| Searched term | Up to 90 days, then anonymized. |
| Search metadata without the term | While the Account is active, for billing history and abuse prevention. |
| Access records (IP address, date and time, session) | 6 months, for security; longer only under a legal order. |
| Server and security logs | Up to 90 days, with automatic redaction of personal data. |
| Module telemetry | 90 days; then archived in pseudonymized form (no searched term, no IP address). |
| Investigations and notes | While the Account is active. When a paid plan ends they become read-only and are deleted 180 days later unless you resubscribe or delete them sooner. |
| Late-arriving results | Up to 30 days, then deleted. |
| AI analyses | 90 days; then the evidence and text are removed. |
| Technical result cache | 24 hours to 7 days; not linked to the Account. |
| Uploaded files | Discarded when the function completes. |
| Billing and tax records | As long as tax and accounting law requires, up to 7 years. |
| Support, surveys and feedback | Up to 5 years; feedback is anonymized after 24 months. |
| Institutional forms | 24 months after the last contact. |
| Newsletter subscription | Until you unsubscribe; the unsubscribe record is kept to honor your choice. |
| Suppression list (hashes only) | Permanently, because its purpose is to prevent future processing. |
14. Security
- encryption in transit (TLS) on all connections and encryption at rest for stored Account data;
- passwords stored only as Argon2id hashes; authentication tokens in HttpOnly cookies; session review and revocation;
- per-Account isolation of Investigations, analyses and notifications, enforced on the server;
- rate limiting, anti-bot challenges and monitoring against brute-force and automated abuse;
- automatic redaction of personal data in logs; administrative access limited to those who need it;
- monitoring, vulnerability management and access-restricted backups;
- an incident-response procedure. We notify affected people and the competent authority of a security incident within the periods the law requires, including the 72-hour notification under the GDPR where it applies.
No system is completely secure. Keep your credentials confidential and your devices secure.
15. Your rights
You can exercise these rights free of charge by writing to [email protected], or directly in your Account settings where shown:
| Right | What it means |
|---|---|
| Access | To know whether we process your data and get a copy of it. |
| Correction | To have inaccurate or incomplete data corrected. |
| Deletion | To have your data deleted, including deleting your Account with all its content in Settings. |
| Portability | To receive the data you gave us in a structured, machine-readable format (Settings → Export my data). |
| Restriction | To have processing restricted while a dispute about accuracy or lawfulness is resolved. |
| Objection | To object to processing based on legitimate interests, including direct marketing, which we then stop unless we have compelling grounds. |
| Withdraw consent | At any time (cookie banner, unsubscribe links or by contacting us), without affecting earlier processing. |
| Human review | To ask for human review of a decision made solely by automated means that affects you (Section 17). |
Timelines. We answer within one month where the GDPR applies (extendable by two months for complex requests, with notice), within 45 days where US state laws apply, and otherwise within the period the applicable law sets. We may ask for information needed to verify your identity or an authorized agent's authority.
Limits. We may refuse or limit a request where the law allows, for example to comply with a legal obligation or defend legal claims, or when a request is manifestly unfounded or excessive; we will explain why.
16. US state privacy rights
If you live in California or another US state with a comprehensive privacy law, you have the right to know what personal information we collect, use and disclose, to access it, to correct it, to delete it, and to opt out of the sale or sharing of personal information for cross-context behavioral advertising. We do not sell personal information. Advertising cookies load only with your consent and can be declined or withdrawn in the cookie banner; we also honor Global Privacy Control signals. We do not use sensitive personal information to infer characteristics about you, and we will not discriminate against you for exercising these rights. You can make a request, or appoint an authorized agent, by writing to [email protected].
17. Automated decisions
We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you. Automated systems apply usage limits, detect abuse and block automated traffic; if one blocks your access or a payment, you can ask for human review by contacting us. The AI analysis is content produced at your request, not a decision.
18. Children
The Services are for people aged 18 or over and are not directed at children. We do not knowingly collect personal data from minors; if we learn that we have, we delete it. The Terms prohibit using the Services to search for, locate or monitor minors.
19. Changes to this policy
We may update this policy to reflect changes in law, the Services or our providers. We publish the new version with its effective date and, for significant changes, tell you by e-mail or in the Platform. The provider list in Section 10 is updated in place.
20. Complaints and contact
Please contact us first at [email protected] with any question or concern; we aim to resolve every issue directly.
You also have the right to complain to a supervisory authority: in the European Economic Area, the data-protection authority of the country where you live or work; in the United Kingdom, the Information Commissioner's Office (ICO); in California, the California Privacy Protection Agency; elsewhere, the authority competent in your place of residence.
If you need this policy in another format for accessibility reasons, contact us and we will provide it.