1. Introduction
OsintCat ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. We are committed to transparency and giving you control over your personal data.
This Privacy Policy complies with the General Data Protection Regulation (GDPR) and other applicable data protection laws. By using our Service, you consent to the data practices described in this policy.
2. Information We Collect
2.1 Account Information
When you register for an account, we collect:
- Email Address: Required for account creation, authentication, password resets, and important service communications
- Username: Optional display name for your account
- Account Credentials: Passwords are hashed and never stored in plain text. We cannot retrieve your password.
- IP Addresses: Logged during registration and while using the platform to prevent abuse and enforce our Terms of Service.
2.2 Payment Information
For paid subscriptions, we collect:
- Abrechnungsinformationen: Sicher verarbeitet über Drittanbieter-Zahlungsdienstleister: Stripe (Kreditkarten, Google Pay, Apple Pay), PayPal und OxaPay (Kryptowährungen)
- Zahlungstoken: Wir erhalten Zahlungstoken und Transaktions-IDs von den Zahlungsdienstleistern. Wir erhalten oder speichern niemals Ihre vollständige Kartennummer, CVV oder Anmeldedaten von Google Pay / Apple Pay.
- Rechnungsunterlagen: Wir bewahren Aufzeichnungen über Transaktionen für Buchhaltungs- und Kundendienstzwecke auf
Important: We do not store complete credit card numbers, CVV codes, or full payment card details on our servers. All payment processing is handled by PCI-DSS compliant third-party processors.
2.3 Usage and Technical Information
To provide and secure our Service, we automatically collect:
- Suchanfragen: Wir protokollieren Suchanfragen, um die Plattformnutzung zu analysieren, Missbrauch zu verhindern und illegale Aktivitäten zu erkennen, einschließlich Suchen im Zusammenhang mit Kindesmissbrauch (CSAM). Wir speichern nicht die Ergebnisse dieser Suchen.
2.4 Authentication and Security Data
For account security, we may collect:
- Two-Factor Authentication (2FA) Secrets: Encrypted and stored if you enable 2FA
- Login History: IP addresses and timestamps of account access
- Security Events: Records of suspicious activities, failed login attempts, and security violations
2.5 Support and Communication Data
When you contact us or use support features:
- Support Tickets: Messages, attachments, and related communications
- Email Communications: Correspondence between you and our support team
3. Was wir NICHT sammeln
Wir glauben an Datenminimierung. Zum Schutz Ihrer Privatsphäre haben wir strenge No-Log-Richtlinien für sensible Aktivitäten implementiert:
- Suchergebnisse: Wir protokollieren oder speichern NICHT die aus Ihren Suchen zurückgegebenen Ergebnisse
- Ermittlungsdaten: Wir verfolgen NICHT, welche Daten Sie untersuchen oder warum
- Daten von Drittanbietern: Wir speichern KEINE Daten von Drittanbietern über das für die Echtzeitverarbeitung erforderliche Maß hinaus
Ihre Ermittlungsaktivitäten werden im Arbeitsspeicher verarbeitet und niemals auf permanente Speicher oder in Logdateien geschrieben. Wir protokollieren jedoch Suchanfragen (ohne deren Ergebnisse), um Plattformmissbrauch zu verhindern und illegale Aktivitäten wie Suchen im Zusammenhang mit Kindesmissbrauch (CSAM) zu erkennen. Dieser Privacy-First-Ansatz stellt sicher, dass Ihre Forschung vertraulich bleibt, während er es uns ermöglicht, rechtliche und ethische Standards einzuhalten.
4. How We Use Your Information
4.1 Service Provision
We use your information to:
- Create and manage your account
- Process payments and manage subscriptions
- Provide access to OSINT tools and API endpoints
- Enforce usage limits and rate restrictions based on your subscription plan
- Deliver search results and intelligence data
4.2 Security and Abuse Prevention
We use your information to:
- Detect and prevent account sharing, API key sharing, license key sharing, and unauthorized access (ZERO TOLERANCE POLICY)
- Monitor IP addresses, usage patterns, and access locations to identify account and key sharing violations
- Identify and block malicious activities, abuse, and security threats
- Monitor for suspicious patterns that may indicate fraud, account sharing, or Terms of Service violations
- Enforce IP whitelisting and access controls
- Investigate security incidents and policy violations
- Take immediate enforcement action against detected violations, including permanent account suspension
We actively monitor and log IP addresses, access patterns, and usage data specifically to detect and prevent account sharing and key sharing. Any detected violation will result in immediate and permanent account termination without refund.
4.3 Communication
We use your email address to:
- Send account verification codes and authentication emails
- Notify you of important service updates, security alerts, and policy changes
- Respond to support requests and inquiries
- Send transactional emails (invoices, payment confirmations, etc.)
You can opt out of marketing communications at any time, but you cannot opt out of essential service communications.
4.4 Service Improvement
We may use aggregated, anonymized data to:
- Analyze usage patterns and improve service performance
- Develop new features and enhance existing functionality
- Monitor system health and optimize infrastructure
5. Legal Basis for Processing (GDPR)
Under GDPR, we process your personal data based on the following legal grounds:
- Contractual Necessity: Processing necessary to fulfill our contract with you (providing the Service)
- Legitimate Interests: Processing for security, fraud prevention, and service improvement
- Legal Obligations: Compliance with applicable laws and regulations
- Consent: Where you have provided explicit consent for specific processing activities
6. Data Sharing and Disclosure
6.1 Third-Party Service Providers
We may share your information with trusted third-party service providers who assist us in operating our Service:
- Stripe (USA): Zahlungsabwicklung für Kartenzahlungen, Google Pay und Apple Pay. Stripe ist nach PCI-DSS Level 1 zertifiziert. Datenübermittlung erfolgt auf Grundlage der Standardvertragsklauseln. Datenschutzerklärung: stripe.com/privacy
- PayPal (USA/Luxemburg): Zahlungsabwicklung für PayPal-Transaktionen. Datenschutzerklärung: paypal.com/privacy
- OxaPay (Cyprus): Cryptocurrency payment processing. Privacy policy: oxapay.com/terms-privacy-policy
- Cloudflare (USA): Content Delivery Network (CDN), DDoS-Schutz und DNS-Dienste. Datenübermittlung erfolgt auf Grundlage der Standardvertragsklauseln. Datenschutzerklärung: cloudflare.com/privacypolicy
- Oracle Cloud Infrastructure (USA/EU): Hosting-, Compute- und Speicherinfrastruktur. Daten können in EU-Rechenzentren verarbeitet werden. AVV auf Anfrage erhältlich.
- E-Mail-Dienstleister: Verwendet für transaktionale E-Mails (Kontoverifizierung, Rechnungen, Sicherheitswarnungen). Es werden keine Marketingdaten weitergegeben.
All third-party service providers are contractually obligated to protect your information and use it only for the purposes we specify.
6.2 Legal Requirements
We may disclose your information if required by law, court order, or governmental authority, or if we believe disclosure is necessary to:
- Comply with legal obligations
- Protect our rights, property, or safety
- Prevent or investigate fraud or security issues
- Enforce our Terms of Service
6.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. We will notify you of any such change in ownership or control.
6.4 What We DO NOT Share
We DO NOT:
- Sell your personal data to third parties
- Share your search queries or investigation data
- Provide your information to advertisers or marketing companies
- Disclose your data except as described in this Privacy Policy
7. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy:
- Account Data: Retained while your account is active and for a reasonable period after account closure for legal and accounting purposes
- Payment Records: Retained as required by law (typically 7 years for tax and accounting purposes)
- Security Logs: Retained for up to 12 months for security analysis and incident investigation
- Support Communications: Retained for up to 3 years after ticket resolution
You may request deletion of your account data at any time, subject to legal retention requirements.
8. Your Rights (GDPR and Data Protection)
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Right to Access: Request a copy of the personal data we hold about you
- Right to Rectification: Request correction of inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data ("right to be forgotten")
- Right to Restrict Processing: Request limitation of how we process your data
- Right to Data Portability: Request transfer of your data to another service
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent where processing is based on consent
To exercise these rights, please contact us at [email protected]. We will respond to your request within 30 days, as required by GDPR.
9. Data Security
We implement industry-standard security measures to protect your information:
- Encryption: Data in transit is encrypted using TLS/SSL. Sensitive data at rest is encrypted
- Access Controls: Limited access to personal data on a need-to-know basis
- Secure Authentication: Support for two-factor authentication (2FA)
- Regular Security Audits: Ongoing monitoring and assessment of security practices
- Incident Response: Procedures for detecting, responding to, and notifying about security breaches
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
10. International Data Transfers
Ihre Informationen können in Ländern außerhalb des Europäischen Wirtschaftsraums (EWR) verarbeitet und gespeichert werden. Folgende Dienste umfassen internationale Datenübermittlungen: Stripe (USA: Zahlungsabwicklung), PayPal (USA: Zahlungsabwicklung), Cloudflare (USA: CDN und DDoS-Schutz). Bei internationalen Datenübermittlungen stellen wir geeignete Sicherheitsmaßnahmen sicher, wie etwa:
- Standard Contractual Clauses approved by the European Commission
- Adequacy decisions by the European Commission
- Other legally recognized transfer mechanisms
11. Children's Privacy
Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.
12. Cookies and Tracking Technologies
We use cookies and similar technologies to:
- Maintain your session and authentication state
- Remember your preferences and settings
- Analyze service usage (anonymized)
You can control cookies through your browser settings. However, disabling certain cookies may limit your ability to use some features of the Service.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:
- Posting the updated policy on this page with a new "Last Updated" date
- Sending an email notification to the address associated with your account
- Displaying a prominent notice on our platform
Your continued use of the Service after such changes constitutes your acceptance of the updated Privacy Policy.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Email: [email protected]
Legal Notice: View Legal Notice
Ein eigener Datenschutzbeauftragter (DSB) ist für ein Unternehmen unserer Größe gemäß Art. 37 DSGVO nicht erforderlich. Alle datenschutzrechtlichen Anfragen werden jedoch direkt von der Geschäftsleitung bearbeitet. Bei DSGVO-bezogenen Anfragen haben Sie zudem das Recht, eine Beschwerde bei der zuständigen Aufsichtsbehörde einzureichen. In Deutschland ist dies der Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI): www.bfdi.bund.de. Je nach Bundesland Ihres Wohnsitzes kann auch die zuständige Landesbehörde zuständig sein.
This Privacy Policy is effective as of January 7, 2026.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.