Privacy Policy

Effective Date: June 28, 2026

1. Scope and Commitment to Privacy

UserScanner ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy details the types of personal data we collect, process, and store when you use our website, OSINT scanning dashboard, and payment frameworks.

By accessing our Service, you consent to the data collection and processing methods outlined in this policy. We prioritize data minimization, security, and user transparency.

2. Data We Collect & Processing Methods

We collect the minimum possible data required to operate the Service and prevent fraudulent misuse of our scanning engine.

  • Account & Authentication Information: All user authentication, sign-ups, logins, and session data are managed securely via Supabase Auth (utilizing Google OAuth or email credentials).
  • Target Identifiers (Scan Queries): To execute OSINT scans, you input target identifiers (usernames or email addresses). These inputs are processed in real-time by our backend engine via Server-Sent Events (SSE).
  • Scan History Logs: For registered accounts, we store past scan target history and metadata securely to allow you to review results in your history dashboard. Anonymous guest scan history is saved locally on your device or cleared after session expiry.
  • Anti-Fraud & Security Metadata: Strictly for anti-abuse and rate-limiting enforcement, we store metadata in the Supabase database (`app_metadata`) under service-role restrictions. This includes device fingerprints, IP hashes, and allocated account credits.

3. Real-Time OSINT Data Aggregation

UserScanner acts as a real-time OSINT aggregator. The results yielded (e.g. platform registration status, public bio, public profile URL, avatar links) are parsed dynamically from publicly accessible endpoints across third-party websites.

We do not scan private data, bypass platform paywalls, or retrieve non-public database tables. We do not store third-party profile data on our databases permanently; results are cached strictly in temporary Redis instances for up to 24 hours to prevent redundant scans, conserve credits, and optimize API speeds.

4. Third-Party Service Providers

We partner with reliable third-party infrastructure providers to run our Service. These providers adhere to strict data security standards.

  • Supabase (PostgreSQL): Handles account database services, row-level security (RLS) policies, and user preference storage.
  • Razorpay: Securely processes billing and credit purchase transactions. We do not receive, store, or process your credit card or financial data.
  • Upstash / Redis: Temporarily caches scan outputs (TTL of 24 hours) for performance and rate limit optimization.

5. Data Retention & Account Deletion

We retain your information only as long as necessary to provide the Service. You hold full ownership of your data.

You can delete your active session or clear history logs from the dashboard. If you wish to delete your entire registered account and wipe all associated scan logs from our Supabase tables, please email us directly. Wiped data is deleted permanently and cannot be recovered.

6. Cookies and Local Storage

We use local storage on your browser to store basic visual state configurations (e.g., your selected theme, selected fonts) and to cache scan parameters temporarily. Supabase Auth utilizes standard security cookies for maintaining active login sessions. We do not use advertising cookies, behavior-tracking cookies, or sell your data to ad networks.

7. Information Security

We implement administrative, technical, and physical security measures (including row-level database controls, TLS encryption, and API secrets) to protect your personal information from unauthorized access, loss, or manipulation. However, no internet-based service can be guaranteed 100% secure.

8. Contact Information & Data Protection Requests

For data protection queries, requests to exercise your privacy rights, or request account deletions, please contact us at:
support@user-scanner.in