Privacy Policy

Last updated: December 2025

1. Data Controller

OSINTCHECKBOX
Robyn Klesing
Krähenfeld 2
45479 Mülheim an der Ruhr
Germany

Email: privacy@osintcheckbox.com

2. Overview of Data Processing

We only process personal data to the extent necessary for providing our OSINT platform. This overview summarizes the types of data processed and their purposes.

2.1 Types of Data Processed

CategoryDataPurpose
Account DataEmail address, name, password (encrypted)User account & authentication
Search QueriesNames, emails, phone numbers, usernamesOSINT research on behalf of user
Search ResultsFound profiles, links, public informationDisplay & temporary storage
Technical DataIP address, browser type, timestampsSecurity & error diagnosis
Payment DataPayment token (via Stripe)Subscription billing

2.2 Data Subjects

3. Legal Basis for Processing

We process your data on the following legal bases under Art. 6 GDPR:

Legal BasisUse Case
Contract Performance
(Art. 6(1)(b))
Provision of OSINT service, account management, search queries
Legitimate Interest
(Art. 6(1)(f))
IT security, abuse prevention, server logs
Legal Obligation
(Art. 6(1)(c))
Retention of billing data (tax law)
Consent
(Art. 6(1)(a))
Newsletter, optional features (if applicable)

4. Data Processing Agreement

Processing on Behalf

OSINTCHECKBOX acts as a data processor under Art. 28 GDPR when conducting OSINT research. The user (controller) remains responsible for the lawfulness of processing.

The platform primarily serves to allow users to check their own digital presence to exercise their rights under Art. 17 GDPR (Right to Erasure).

5. Recipients and Third-Party Providers

We use the following third-party providers to deliver our services:

ServiceProviderPurposeLocation
AI AnalysisxAI Corp. (Grok)Intelligent analysis and summarization of search resultsUSA
HostingIONOS SEServer infrastructureGermany
PaymentStripe, Inc.Secure payment processingUSA (SCCs)

6. Data Transfers to Third Countries

Notice Regarding USA Transfers

When using the AI analysis function, search results are transmitted to xAI (Grok) in the USA. The transfer is based on:

Alternative for sensitive data: Government agencies and enterprise customers can use a local AI model where no data leaves their own infrastructure.

7. Use of Artificial Intelligence

In accordance with the EU AI Act, we inform you:

8. Storage Duration

Data TypeStorage Period
Account dataUntil account deletion
Search results30 days, immediately deletable upon request
Server logs7 days
Billing data10 years (legal retention requirement)

9. Cookies and Tracking

We only use technically necessary cookies:

CookiePurposeDuration
Session CookieAuthentication and login statusSession end / 30 days

No tracking: We do not use analytics or tracking tools like Google Analytics.

10. Your Rights

You have the following rights under GDPR:

To exercise your rights, contact us:

Email: privacy@osintcheckbox.com

We will process your request within 30 days.

11. Right to Complain

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:

State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia
Kavalleriestraße 2-4
40213 Düsseldorf, Germany
Phone: +49 211 38424-0
Email: poststelle@ldi.nrw.de
Web: www.ldi.nrw.de

12. Data Security

We implement technical and organizational measures under Art. 32 GDPR:

13. Changes to this Privacy Policy

We reserve the right to update this Privacy Policy to reflect changes in law or service modifications. The current version is always available on this page.