Skip to content
UsernameLookup

legal / privacy

Privacy policy

How the usernamelookup.com service handles personal data of account holders, visitors and people whose usernames are searched.

1. Who is responsible for your data

The controller of personal data processed through usernamelookup.com is the administrator of the usernamelookup.com service. You can reach the administrator about any privacy matter at [email protected].

2. What the service does

UsernameLookup checks whether a username has a public profile at the public address that each supported site uses for its members. It does not sign in to any platform, does not read content behind authentication and does not collect real names, email addresses, phone numbers or postal addresses of the people whose usernames are searched. Adult and explicit sites are excluded from the checks. More detail is on the security and privacy boundaries page.

3. Data we process about account holders

  • Account data. Email address, a name you choose to enter, a password stored only as a salted hash, and the one-time code used to confirm your email at signup.
  • Workspace data. Workspaces, team members and their roles, lookup history, results, monitors, case notes and evidence snapshots (URL, timestamp, HTTP status and page title of a public page).
  • API data. API keys, stored only as hashes, and usage counters used to enforce plan limits.
  • Billing data. Plan, subscription status, invoice references and the billing details you give the payment processor. Card numbers are entered on the payment processor's page and never reach our servers.
  • Technical data. IP address and request data in server logs, used for security and to enforce rate limits.

4. Data we process about visitors

A visitor without an account can run one demo lookup. To keep the demo one-time, we set an essential cookie with a random identifier and store a keyed hash of the IP address, which counts for 30 days. The raw IP address is not stored for this purpose.

5. Data about people whose usernames are searched

When a customer searches a username, the result contains public signals only: whether a public profile answers at an address, the link to it, the response time and, on some plans, simple comparisons of public profile elements such as the display name or avatar shown on that public page. We do not combine these results with data from other sources. Results are stored in the workspace of the customer who ran the lookup.

If you do not want your username to appear in results, use the opt-out page. You confirm the request with a code sent to your email. After confirmation the username is placed on a suppression list that every lookup, API call and monitoring run checks first, and the service returns no results for it. We store only a hash of the username and a hash of the email address used for the request.

6. Purposes and legal bases

  • Providing the service under your contract, including your account, lookups, monitoring and billing (performance of a contract).
  • Issuing invoices and keeping accounting records (legal obligation).
  • Security, fraud and abuse prevention, rate limiting, the one-time demo and handling of legal claims (legitimate interests).
  • Processing public profile signals about searched usernames for brand protection, fraud prevention, trust and safety and security research by our customers (legitimate interests, balanced by the opt-out list, the exclusion of private data and the acceptable use policy).
  • Transactional emails such as signup codes, alerts you configure and billing notices (performance of a contract).

7. Recipients of data

We share personal data only with providers that help us run the service, under contracts that bind them to confidentiality and data protection. These are a hosting provider, a payment processor and a transactional email provider. We do not sell personal data and do not share it with advertisers. Authorities receive data only where the law requires it.

8. International transfers

Where a provider processes data outside the European Economic Area, the transfer relies on an adequacy decision or on standard contractual clauses approved by the European Commission.

9. Retention

  • Account and workspace data are kept while the account exists. Lookup history and evidence can be deleted by you at any time.
  • After you close the account, its data is deleted from the live system and disappears from backups as they rotate.
  • Invoices and accounting records are kept for the period required by tax law.
  • Demo IP hashes count for 30 days. Opt-out hashes are kept while the opt-out is active.

10. Cookies

The service uses essential cookies only: a session cookie that keeps you signed in, a security token that protects forms against cross site request forgery, and the one-time demo cookie described above. We do not use advertising pixels or tracking cookies, so no consent banner is needed.

11. Your rights

Under the GDPR and similar laws you have the right to access your data, to have it corrected, to have it erased, to restrict its processing, to data portability and to object to processing based on legitimate interests. People whose usernames are searched can object at any time, and the opt-out page is the fastest way to do that. To exercise any right, write to [email protected]. We answer within one month.

You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the country where you live, work or where you believe an infringement took place.

12. Security

Connections are encrypted, passwords and API keys are stored as hashes, access inside a workspace follows roles, and plan limits apply per account and per IP address. Card data never reaches our servers.

13. Children

The service is intended for professional use by adults and is not directed at children.

14. Changes to this policy

We update this policy when the service or the law changes. Material changes are announced to account holders by email before they take effect.