Privacy Policy
Effective date: September 4, 2026 · Replaces the version of June 4, 2026
This is a courtesy translation. The Portuguese version is the legally binding document.
Privacy at a glance. This summary gives a quick overview; the full policy below contains the complete terms.
- Limited collection. We collect what is needed to provide, secure, bill and improve the Services: your e-mail, account and authentication data, billing identifiers, usage and security data, and analytics with your consent.
- Searches. Results are delivered to your browser and are not retained as part of your Account unless you save them. The searched term is kept for up to 90 days for security, restricted to administration, then anonymized.
- No selling. We never sell or rent personal data. We share only with providers who help us operate, under contract, and with authorities when the law requires.
- Retention. Account data while the Account is active; deletion on request; specific periods for each category in Section 13.
- Your rights. Access, correction, deletion, portability, restriction, objection, withdrawal of consent and review of automated decisions, under the LGPD and, where applicable, the GDPR.
- If you may appear in results. Section 12 explains what we do with a verified request, including permanent suppression of the identifier as a search term.
- Contact. Data Protection Officer: help@espectrosint.com.
- Who we are and which laws apply
- Who this policy applies to
- Personal data we collect
- How we collect it
- Purposes and legal bases
- Searches: what happens to the term and the results
- AI-generated analysis
- Marketing and communications
- Cookies and similar technologies
- Who we share personal data with
- International transfers
- People who may appear in results
- How long we keep personal data
- Security
- Your rights
- Automated decisions
- Children and adolescents
- Changes to this policy
- How to complain and how to contact us
1. Who we are and which laws apply
The website espectrosint.com and the related Services are provided by Espectrosint ("we", "us"), an open-source intelligence (OSINT) platform established in Brazil. We are the controller of the personal data described in this policy, meaning we decide how and why it is used. Our Data Protection Officer (DPO / "Encarregado") can be reached at help@espectrosint.com.
We process personal data under the Brazilian General Data Protection Law (Law No. 13.709/2018, "LGPD") and the Marco Civil da Internet (Law No. 12.965/2014). Where we offer Services to individuals in the European Economic Area or the United Kingdom, or monitor their behavior there, we also comply with the EU General Data Protection Regulation and the UK GDPR ("GDPR") in relation to that processing, and this policy explains the additional rights available to those individuals.
This policy covers the Website, the Platform, the API, our e-mails and forms. It does not cover third-party websites we link to, which have their own privacy policies.
2. Who this policy applies to
- Visitors of the Website and blog;
- Users who create an Account, on the free or paid plans;
- Institutional contacts who fill in a form or request a proposal;
- Newsletter subscribers;
- People who may appear in results of a search performed by a user (Section 12).
3. Personal data we collect
The personal data we collect depends on how you interact with us. Where a category is required to provide a Service, declining to provide it means we cannot provide that Service.
| Category | What it includes |
|---|---|
| Identification and Account | E-mail address; name and profile picture (when you sign in with Google); the identifier issued by the social-login provider; password (stored only as an Argon2id hash); plan; preferences and onboarding answers; Account creation date. |
| Billing | Payments are processed by Stripe (cards) and Mercado Pago (Pix). We keep the customer and subscription identifiers issued by them, the plan, the payment status and the transaction history needed for accounting. We do not store full card numbers. |
| Usage and security | IP address, date and time, browser and device information, approximate city and country of each session; Credits consumed; type of search, number of results and module telemetry (which sources answered, latency, errors); security events; error reports. |
| Searched term | The identifier you submit (for example an e-mail address or username), kept for up to 90 days for security and abuse prevention, restricted to administration, then anonymized. Details in Section 6. |
| Content you save | Investigations (snapshots of results you chose to save, connections, notes), stored in your Account under your control, and AI-generated analyses, whose content is kept for 90 days. |
| Late-arriving results | When a search has a result still being delivered by a slow source, a snapshot of that search is held for up to 30 days so the late result can be attached and notified to you. |
| Uploaded files | Images or files you upload for analysis, processed transiently for the requested function only. Details in Section 6. |
| Marketing and attribution | Campaign identifiers (utm parameters, click identifiers such as gclid), referral source you tell us, and marketing preferences; analytics and advertising data only with your consent (Section 9). |
| Communications | Support requests and replies; satisfaction surveys (NPS) and free-text feedback; cancellation reason; institutional forms (name, role, organization, e-mail, telephone, city/state, number of users). |
We do not intentionally collect sensitive personal data (such as health, religion, sexual orientation, biometric or genetic data) about our users. We do not offer facial recognition or biometric identification.
4. How we collect it
- Directly from you, when you register, sign in, subscribe, run a search, save content, upload a file, contact us, answer a survey or fill in a form.
- Automatically, through your use of the Website and Platform: server logs, session records and, with your consent, cookies and similar technologies (Section 9).
- From third parties: the social-login provider (Google) when you choose to sign in with it; payment providers, who confirm the status of a payment; and anti-bot and security services that assess a request before it reaches us.
5. Purposes and legal bases
We only process personal data when we have a proper reason. The table shows what we use it for and the legal basis under the LGPD and, where the GDPR applies, under the GDPR. Where we rely on legitimate interests, we have assessed that our interest is not overridden by your rights; you may request a summary of that assessment.
| Purpose | LGPD basis | GDPR basis |
|---|---|---|
| Creating, authenticating and managing your Account; applying plan limits | Performance of a contract (Art. 7, V) | Art. 6(1)(b) contract |
| Executing the searches you request and delivering results, Investigations and notifications | Performance of a contract (Art. 7, V) | Art. 6(1)(b) contract |
| Processing payments, subscriptions, refunds and accounting records | Contract (Art. 7, V); legal obligation (Art. 7, II) | Art. 6(1)(b); Art. 6(1)(c) |
| Security, fraud and abuse prevention, rate limiting, incident investigation, keeping the searched term for 90 days | Legitimate interest (Art. 7, IX); legal obligation for access logs (Art. 7, II; Marco Civil Art. 15) | Art. 6(1)(f) legitimate interest; Art. 6(1)(c) |
| Monitoring errors and performance; aggregated statistics to improve the Services | Legitimate interest (Art. 7, IX) | Art. 6(1)(f) |
| Service communications (verification codes, receipts, changes to terms, security notices) | Contract (Art. 7, V); legitimate interest (Art. 7, IX) | Art. 6(1)(b); Art. 6(1)(f) |
| Marketing communications to existing and former customers (with opt-out) | Legitimate interest (Art. 7, IX) | Art. 6(1)(f) |
| Newsletter and promotional messages to people who are not customers | Consent (Art. 7, I) | Art. 6(1)(a) consent |
| Analytics, session replay and advertising measurement through cookies | Consent (Art. 7, I) | Art. 6(1)(a); ePrivacy rules |
| Generating an AI-narrated analysis you request | Contract (Art. 7, V) | Art. 6(1)(b) |
| Responding to requests from people who may appear in results, including keeping a suppression list | Legal obligation (Art. 7, II); legitimate interest (Art. 7, IX) | Art. 6(1)(c); Art. 6(1)(f) |
| Complying with legal and regulatory obligations, court orders and requests from authorities | Legal obligation (Art. 7, II) | Art. 6(1)(c) |
| Establishing, exercising or defending legal claims | Regular exercise of rights (Art. 7, VI) | Art. 6(1)(f) |
| Sharing with a successor in a merger, acquisition or restructuring, anonymized where possible | Legitimate interest (Art. 7, IX) | Art. 6(1)(f) |
6. Searches: what happens to the term and the results
Real-time processing. When you run a search, the identifier you submit is used to consult open, public and commercially available sources through our own modules and through the collection providers listed in Section 10, which act only while the query is running. The results are correlated and delivered to your browser.
Results are not kept as part of your Account, except in three situations that you control or that we disclose here: (a) you save a result to an Investigation; (b) you request an AI-generated analysis, in which case the evidence sent to the model and the resulting text are stored in your Account for 90 days; (c) a slow source is still delivering a late result, in which case a snapshot of the search is held for up to 30 days and deleted automatically.
Searched term. For security, abuse prevention, enforcement of usage limits and operational metrics, we log each search's metadata (timestamp, type of search, number of results, Credits) and the searched term. The term is restricted to administration, kept for up to 90 days and then anonymized (removed from the record). Metadata without the term is kept as described in Section 13.
Technical cache. To avoid re-querying sources for an identical query, a short-lived cache held in the server's memory may keep a query's result for a period that depends on the type of search (24 hours for e-mail, username and telephone; 48 hours for name and tax identifiers; 7 days for domain). The cache key is a cryptographic hash of the normalized query, is not linked to your Account, and entries expire automatically and are lost on restart.
Uploaded files. Images or files you upload are processed only for the requested function and are not retained beyond what that function requires. When you use reverse image search, the photo is made available for a few minutes at a temporary, unlisted address so the search service (Google Lens, via Scrapingdog) can read it; it is held in memory only, discarded as soon as the query finishes, and never written to disk or backup. We do not create biometric templates from images.
Leak Sonar. If you are on a paid plan and turn on Leak Sonar, we keep the emails, domains and usernames you add so we can compare them with leaked data that circulates on public sources and forums and that reaches our database after you added them. To add an email or a domain you must prove it is yours with a code we send to that email or, for a domain, to an administrative address at it (such as admin@ or postmaster@), because domain alerts show other people's accounts; usernames cannot be proven and their alerts never show any part of a password. When something new matches, we keep a masked record of it (the identifier, the site involved and, for emails and domains, only the first 2 characters of passwords that have at least 8) and send you an email through Brevo (Section 10). The legal basis is the performance of the contract you asked for (Art. 7, V LGPD / Art. 6(1)(b) GDPR), and we ask for your specific authorization the first time you turn it on. We delete an item and its records when you remove it, or 90 days after your paid plan ends; while the plan is inactive nothing is checked and no alert is sent.
Your role. For the personal data of third parties you search, you are the controller and Espectrosint acts as processor, under the Data Processing Addendum in the Terms of Use. You must have a lawful basis for that processing. Public availability of information is not, by itself, a lawful basis.
7. AI-generated analysis
If you request the AI-narrated analysis (dossier), a compressed and normalized version of the results of that search is sent to our AI provider (Anthropic) solely to generate the text. The provider processes it under contract, does not use it to train models, and does not retain it beyond what is needed to return the response. The evidence and the resulting analysis are kept in your Account for 90 days, after which their content is removed automatically and only a masked reference, the status and the date remain. This is automated processing that produces content, not a decision about you or about the person searched; Section 16 explains your rights.
8. Marketing and communications
Service messages (verification codes, receipts, security alerts, changes to terms, notices that a late result is ready) are part of the Service and cannot be opted out of while you keep an Account.
Customer marketing. If you are or were a customer, we may send you e-mails about your plan, credits, new features, offers and tips for using the Platform (including onboarding and win-back sequences), on the basis of our legitimate interest in promoting our Services to our own customers. You can opt out at any time through the unsubscribe link in each message or by writing to us; opting out does not affect service messages.
Newsletter. The newsletter is sent only to people who subscribed, and every issue carries an unsubscribe link.
Advertising measurement. When you consent to marketing cookies and arrive through an advertisement, we may report the conversion (registration or purchase) to the advertising platform together with the click identifier it issued, so that campaigns are measured. We do not upload your name or e-mail to advertising platforms for this purpose.
We never sell, rent or share personal data with third parties for their own marketing.
9. Cookies and similar technologies
A cookie is a small text file placed on your device. We use:
- Essential cookies (always on): authentication session (HttpOnly), protection against request forgery, your cookie choices, your language and region preference, and security cookies set by our content-delivery and anti-bot provider (Cloudflare, including the Turnstile challenge on registration and login). These are necessary for the Services to work and do not require consent.
- Analytics cookies (with your consent): Google Analytics and Microsoft Clarity, to understand how the Website and Platform are used (pages visited, session duration, interactions, heatmaps and session replays with form inputs masked).
- Marketing cookies (with your consent): Google Ads, to measure campaigns and conversions.
You choose analytics and marketing cookies in the consent banner and can change your choice at any time in the banner or your browser settings. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
10. Who we share personal data with
We share personal data only with providers that help us operate the Services (our processors and subprocessors), under written contracts that limit them to processing on our instructions with appropriate security, and with the other recipients listed below.
| Provider | Function | Location |
|---|---|---|
| Stripe | Card payment processing and subscription management | United States / Ireland |
| Mercado Pago | Pix payment processing | Brazil |
| Neon | Managed storage of Account data | United States |
| Akamai / Linode | Server hosting | United States |
| Cloudflare | Content delivery, security, anti-bot (Turnstile) | United States (global network) |
| Brevo | Transactional e-mail, lifecycle e-mail and newsletter | France (EU) |
| Social login; Analytics and Ads (with consent); reverse image search (Google Lens) | United States | |
| Microsoft Clarity | Analytics and session replay (with consent) | United States |
| Sentry | Error and performance monitoring | United States |
| Anthropic | Generation of the AI-narrated analysis (only when requested) | United States |
| Scrapingdog | Collection of publicly available data from open sources during a query | India |
| Bright Data | Collection of publicly available data from open sources during a query | Israel / United States |
We may also share personal data with: our professional advisers (lawyers, accountants, auditors) bound by confidentiality; law-enforcement agencies, courts, regulators and authorities where required by law or to protect the rights, property or safety of Espectrosint, our users or others; and a successor or prospective acquirer of our business in connection with a merger, acquisition, restructuring or insolvency, in which case information is anonymized where possible and the recipient is bound by confidentiality.
We will update this list when we add or replace a material provider. Users acting as controllers of their own searches receive notice of such changes through this policy, as provided in the Data Processing Addendum.
11. International transfers
We are established in Brazil and some of our providers are located in other countries, notably the United States and the European Union. When personal data leaves Brazil, we rely on the mechanisms of Art. 33 of the LGPD: providers located in countries recognized as adequate, standard contractual clauses approved by the National Data Protection Authority (ANPD), or another mechanism permitted by law, and we require our providers to apply data-protection standards equivalent to ours.
If you are in the European Economic Area or the United Kingdom, your personal data is transferred to Brazil, where we operate, and onward to the providers listed in Section 10. Brazil does not currently benefit from an adequacy decision; these transfers are made on the basis of the safeguards of Chapter V of the GDPR, including standard contractual clauses with our providers and, where a provider is certified under the EU-U.S. Data Privacy Framework or the UK Extension, that certification. You can request more information about the safeguards we rely on.
12. People who may appear in results
The Services consult open, public and commercially available sources at the moment a user runs a query, and correlate what those sources return. If you believe your personal data may appear in a result, this section explains what we do.
What we do not do. We do not notify people that they were searched, we do not build profiles of people who were searched for our own purposes, and we do not retain results as part of a user's Account unless the user saves them (Section 6).
What you can ask. You may exercise the rights in Section 15, including objection and erasure. On a verified request, we will:
- add the identifiers you indicate (for example e-mail addresses, usernames or telephone numbers) to a suppression list, so that they are no longer accepted as search terms and are not returned as results. The list stores only a cryptographic hash of each identifier, never the identifier itself, and remains in effect permanently, including if a source republishes the data;
- remove any copy of the identifier that exists in our own records within the applicable retention periods (Section 13), except where the law requires us to keep it;
- tell you which categories of sources the information typically comes from and guide you on requesting removal at the original source, since removal there prevents the information from being found by anyone, including through other tools;
- confirm the actions taken in writing, with the date.
Who searched you. Search records belong to the personal data of the user who performed the search. We do not disclose the identity of a user to the person searched, except under a court order or as required by law. We will, however, act on your request regardless of who ran the search.
Timelines and verification. We respond within the periods in Section 15. We may ask for information reasonably necessary to confirm that the request comes from the person concerned or from someone authorized to act for them, and we use it only for that purpose. Requests are free of charge.
Where a user is the controller. Where your request relates solely to the purposes of a user who searched you, we may also forward you to that user, without prejudice to the actions above.
13. How long we keep personal data
We do not keep personal data for longer than needed for the purpose for which it is used. The main periods are:
| Data | Retention |
|---|---|
| Account data (identification, plan, preferences) | While the Account is active. Deleted when you close the Account, immediately on our systems; copies in routine backups are overwritten in the ordinary course. |
| Record of a closed Account (e-mail, payment and subscription identifiers, plan) | 180 days after closure, to reconcile billing, prevent fraud and honor a subscription if you return; then deleted. |
| Searched term | Up to 90 days, then anonymized. |
| Search metadata without the term (date, type, count, Credits) | While the Account is active, for billing history and abuse prevention. |
| Access records (IP address, date and time, session) | 6 months, as required by Art. 15 of the Marco Civil da Internet; longer only under a legal order. |
| Server and security logs | Up to 90 days, with automatic redaction of personal data. |
| Module telemetry (which sources answered, latency, errors) | 90 days online; then archived in pseudonymized form (no searched term, no IP address) for historical analysis. |
| Investigations and notes | While the Account is active. When a paid plan ends, they become read-only and are deleted 180 days later unless you resubscribe or delete them earlier. |
| Late-arriving results (search snapshot) | Up to 30 days, then deleted automatically. |
| AI-generated analyses | 90 days; then the evidence and the text are removed and only a masked reference, status and date remain. |
| Technical result cache | 24 hours to 7 days depending on the type of search; not linked to the Account. |
| Uploaded files | Transient; discarded when the function completes. |
| Billing and tax records | 5 years after the transaction, as required by Brazilian tax and accounting law. |
| Support communications, surveys, feedback | Up to 5 years, to handle follow-ups and claims; feedback is anonymized after 24 months. |
| Institutional forms | 24 months after the last contact. |
| Newsletter subscription | Until you unsubscribe; the unsubscribe record is kept to honor your choice. |
| Suppression list (hashes only) | Permanently, because its purpose is to prevent future processing. |
| Cookies | As set out by each tool; you can delete them in your browser at any time. |
After the applicable period, we delete or anonymize the data. Where we must keep data to comply with a legal obligation or to establish, exercise or defend legal claims, we keep only what is needed, with restricted access, for as long as that need exists.
14. Security
We apply technical and organizational measures designed to protect personal data against loss, misuse, unauthorized access, alteration or disclosure, proportionate to the risks, including:
- encryption in transit (TLS) on all connections and encryption at rest for stored Account data;
- passwords stored only as Argon2id hashes; authentication tokens in HttpOnly cookies; session management with device review and revocation;
- per-Account isolation of Investigations, analyses and notifications, enforced on the server;
- rate limiting, anti-bot challenge (Turnstile) and monitoring against brute-force and automated abuse;
- automatic redaction of personal data in logs; access to administrative data restricted to those with a genuine need;
- continuous availability and security monitoring, vulnerability management, and backups with restricted access;
- an incident-response procedure. We will notify affected persons and the competent authority (ANPD, or the EU/UK authority where the GDPR applies) of a security incident that may cause relevant risk or harm, within the periods required by Art. 48 of the LGPD and Art. 33 of the GDPR.
No system is completely secure. You are responsible for keeping your credentials confidential and for the security of the devices you use.
15. Your rights
You may exercise the following rights free of charge by writing to our DPO at help@espectrosint.com, or directly in your Account settings where indicated:
| Right | What it means |
|---|---|
| Confirmation and access | To know whether we process your data and to receive a copy of it. |
| Correction | To have incomplete, inaccurate or outdated data corrected. |
| Anonymization, blocking or deletion | Of data that is unnecessary, excessive or processed in breach of the law; and deletion of your Account with all its content, available directly in your Account settings. |
| Portability | To receive the data you provided in a structured, machine-readable format. |
| Information on sharing | To know the public and private entities with which we shared your data (Section 10). |
| Information on consent and withdrawal | To know the consequences of refusing consent, and to withdraw consent at any time (cookie banner, unsubscribe links, or by contacting us), without affecting prior processing. |
| Objection | To object to processing based on legitimate interests, including direct marketing, which we will stop unless we have compelling legitimate grounds. |
| Restriction (GDPR) | To require us to restrict processing while a dispute about accuracy or lawfulness is resolved. |
| Review of automated decisions | To request human review of a decision made solely by automated means that affects your interests (Section 16). |
Timelines. Under the LGPD, we confirm the existence of processing and provide access in simplified form immediately or in full within 15 days, and answer other requests within a reasonable period, normally the same 15 days. Where the GDPR applies, we respond within one month, extendable by two further months for complex requests, in which case we will tell you. We may ask for information reasonably necessary to verify your identity.
Limits. We may refuse or limit a request where the law allows, for example when data must be kept to comply with a legal obligation or to exercise rights in legal proceedings, or when a request is manifestly unfounded or excessive; in that case we will explain the reasons and your options.
16. Automated decisions
We do not make decisions based solely on automated processing that produce legal effects on you or similarly significantly affect you. Automated systems apply usage limits, detect abuse and block automated traffic; if an automated measure blocks your access or a payment, you may request human review by contacting us, in accordance with Art. 20 of the LGPD and Art. 22 of the GDPR. The AI-generated analysis is content produced at your request, not a decision.
17. Children and adolescents
The Services are intended for people aged 18 or over and are not directed at children or adolescents. We do not knowingly collect personal data from minors; if we learn that we have, we delete it. The Terms of Use prohibit using the Services to search for, locate or monitor minors.
18. Changes to this policy
We may update this policy to reflect changes in law, in the Services or in our providers. We publish the updated version with its effective date at the top of this page and, for significant changes, notify you by e-mail or in the Platform. The list of providers in Section 10 is updated in place when a provider is added or replaced.
19. How to complain and how to contact us
Please contact our DPO first at help@espectrosint.com if you have questions or concerns about how we use your personal data; we aim to resolve every issue directly.
You also have the right to lodge a complaint with a supervisory authority: in Brazil, the Autoridade Nacional de Proteção de Dados (ANPD) at gov.br/anpd; in the European Economic Area, the data-protection authority of the country where you live or work; in the United Kingdom, the Information Commissioner's Office. Consumers in Brazil may also use consumidor.gov.br.
If you need this policy in another format for accessibility reasons, contact us and we will provide it.