Skip to content

Instantly share code, notes, and snippets.

@denniskeefe
Created July 18, 2026 17:18
Show Gist options
  • Select an option

  • Save denniskeefe/a1ef31dc6a143f903691067480991383 to your computer and use it in GitHub Desktop.

Select an option

Save denniskeefe/a1ef31dc6a143f903691067480991383 to your computer and use it in GitHub Desktop.
OSINT Lens — Privacy Policy

Privacy Policy — OSINT Lens

Last updated: 18 July 2026

OSINT Lens is a browser extension that performs open-source intelligence (OSINT) lookups on an identifier you select (a name, username, email address, or phone number). This policy explains what the extension does and does not do with data.

Contact: denniskeefe@pm.me

Summary

  • We do not collect, store, or transmit your browsing history or page content to us.
  • We do not run analytics or tracking in the extension.
  • We do not sell or share your data.
  • The only data the extension sends to us is your premium license key, and only to validate it.
  • Everything else stays on your device or goes directly to the third-party public source you choose to query.

What the extension handles, and where it goes

Identifiers you look up (names, usernames, emails, phone numbers). When you start a lookup or run a page scan, the selected identifier is sent directly from your browser to the relevant third-party OSINT provider to perform that lookup — for example GitHub, GitLab, Reddit, Google Public DNS (DoH), Gravatar, and, if you supply a key, Have I Been Pwned or Numverify (apilayer). These requests are initiated by your action. We do not receive, log, or store these identifiers. Phone number validation and formatting happen entirely on your device.

Your settings and watchlist. Your preferences and watchlist terms are stored using the browser's extension storage. Settings and the watchlist are synced across your signed-in browser profile by your browser vendor (e.g. Chrome Sync) so they follow you across your own devices. We have no access to this data.

Your API keys (optional, bring-your-own). If you add a Have I Been Pwned or Numverify key, it is stored locally on your device only and is sent only to that provider when you use the corresponding check. It is never synced and never sent to us.

Your premium license. When you activate or re-check a premium license, your license key is sent to our licensing backend (hosted on Supabase) to confirm it is valid. We store the license record associated with your purchase (license key, plan, status, and the email address captured by our payment processor at checkout). We use this solely to issue and validate licenses and to provide support.

Payments. Purchases are processed by Stripe. We do not receive or store your full card details. Stripe processes your payment and the email address you provide at checkout under Stripe's own privacy policy (https://stripe.com/privacy).

Third parties

The extension may send your user-initiated queries to these providers, each governed by its own privacy policy: GitHub, GitLab, Reddit, Google (Public DNS), Gravatar/Automattic, Have I Been Pwned, and apilayer/Numverify. Our licensing backend runs on Supabase, and payments are handled by Stripe. We do not sell or share your information with any party for advertising.

Data retention

Settings, watchlist, and API keys persist until you remove them or uninstall the extension. License records are retained for as long as needed to provide and support your license and to meet legal/accounting obligations. To request deletion of your license record, contact us at the address above.

Security

License data is stored in a database that is not publicly readable; access is limited to our backend functions. API keys and license tokens on your device are held in browser extension storage.

Children

OSINT Lens is intended for professional and adult research use and is not directed to children under 13 (or the equivalent minimum age in your jurisdiction).

Responsible use

OSINT Lens queries public data sources for legitimate research, journalism, and security work. You are responsible for complying with each source's terms of service and with applicable law. Do not use it to harass, stalk, or profile people without a lawful basis.

Changes

We may update this policy; material changes will be reflected by the "Last updated" date above.

Contact

Questions or data requests: denniskeefe@pm.me

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment