Skip to content
UsernameLookup

security / data boundaries

Security and privacy boundaries

UsernameLookup checks public profile addresses only. It never logs in, never reads private content and never collects real names, emails, phone numbers or addresses. This page explains what we check, what we store, how long we keep it and how people can opt out.

01 what we check

Public profile addresses and nothing behind them

A lookup takes one username and asks each of 300+ sites whether a public profile answers at the address that site uses for its members. The answer is read the way a browser reads it: a profile page, a not found page, or something in between that we mark as unknown instead of guessing.

That is the whole scope. We do not sign in to platforms, we do not hold accounts on them to see more, and we do not scrape anything that requires authentication, a follow request or an accepted friendship. If a profile is private, the only thing the result says is that an address exists.

Our requests identify themselves honestly and respect the platform's own rate limits. Adult and explicit categories are excluded from the site list, so a lookup never sends anyone to that kind of content.

scope of a check
  • Public profile URL checked
  • HTTP status and page title checked
  • Display name and avatar on the public page compared
  • Logins or sessions on the platform never
  • Content behind authentication never
  • Adult and explicit sites excluded
02 what we never collect

Data we do not collect about the people you search

A username lookup answers a narrow question: where does this handle exist in public. It is not a people search, and it is built so that it cannot become one.

  • Real names

    We never resolve a handle to a legal name or try to match it against records.

  • Email addresses

    No email discovery, no guessing of addresses from handles.

  • Phone numbers

    No phone lookups and no reverse search from a number.

  • Home or work addresses

    No location data, no maps, no address history.

  • Private posts and messages

    Nothing behind a login, a follow request or a privacy setting.

  • Enrichment from third parties

    We do not buy, merge or append data from brokers or other databases.

03 data and retention

What we store and for how long

The service stores what it needs to run your account and to give you the history of your own work. Lookup history and evidence belong to the workspace that created them and are visible only to its members.

Data category, whether it is stored, purpose and retention
Data category Stored Purpose Retention
Account (email, hashed password, name you enter) yes sign in, security codes, billing notices while the account exists
Workspace and team roles yes access control between members while the workspace exists
Lookup history per workspace yes history, diff between runs, exports until you delete it or close the account
Results (site, status, profile URL, response time) yes show and compare results with the lookup they belong to
Evidence snapshots (URL, timestamp, HTTP status, page title) yes, Investigator and up case notes and PDF reports until you delete them or close the account
API keys hash only authenticate API calls until you revoke the key
Card numbers no handled by the payment processor never on our servers
Demo visitor marker (cookie and hashed IP) yes enforce the one-time demo IP hash counted for 30 days
Opt-out requests hash of username and email suppress the username in every lookup while the opt-out is active

When you close an account, the workspace data is deleted from the live system and disappears from backups as they rotate. Invoices are kept for the period tax law requires.

04 account security

How accounts and API access are protected

Hashed passwords

Passwords are stored only as salted hashes with a slow algorithm. Nobody on our side can read them, and we never send them by email.

Email code at signup

A new account is confirmed with a one-time code sent to the address, so nobody can open an account in someone else's name.

API keys stored as hashes

A key is shown once when you create it. We keep only its hash, so a copy of our database would not give anyone working keys. Revoke a key in one click.

Rate limits per account and IP

Each plan has monthly quotas and per minute limits, enforced per account and per IP address. Bulk abuse hits a 429 response long before it becomes a problem.

Roles inside a workspace

Administrators manage billing, keys and members. Editors run lookups and work on cases. Members see only the workspaces they belong to.

Encrypted connections

Every page and API endpoint is served over HTTPS only.

Payments are handled by a payment processor on its own secure checkout page with 3D Secure on every card payment. Card numbers never reach our servers. We receive the plan, the subscription status and invoice references, which is all the account needs. Plan details are on the username lookup pricing page.

05 opt-out

The opt-out list is checked before every lookup

Anyone can ask us to stop returning results for their username. The request is confirmed with a code sent to an email address, and once confirmed the username goes on a suppression list.

Every lookup, every API call and every monitoring run checks that list first. A suppressed username returns no sites at all, on every plan, including Enterprise. Customers cannot switch this off.

We store only a hash of the username and a hash of the email. That is enough to recognise the name when someone searches it, and it means the list itself does not expose who asked to be removed. Start on the username opt-out page.

  1. step 1

    Enter the username and an email

    The email is used only to send the confirmation code.

  2. step 2

    Confirm the code

    The code expires after a short time. Unconfirmed requests are not applied.

  3. step 3

    Suppression is active

    From that moment, lookups of that username return no results.

06 abuse handling

How we handle misuse

UsernameLookup is built for brand protection, fraud prevention, trust and safety and security research. Using it to stalk, harass, dox or profile private people is forbidden by the acceptable use policy, and every account accepts that policy at signup.

Report misuse to [email protected] with the username concerned, the date and a short description. We review each report, and accounts that break the policy are suspended without a refund. Where the law requires it, we cooperate with competent authorities.

Teams that need a structured workflow for impersonation cases can read how brand impersonation monitoring keeps a case board and report links for each finding.

open data credit

Site detection data includes the open WhatsMyName dataset, CC BY-SA 4.0.

07 faq

Questions about security and privacy

Does UsernameLookup log in to any platform or read private posts?

No. Every check requests the public profile address of a username, the same page anyone can open in a browser without an account. We never sign in, never use your credentials or ours on a platform, and never read anything that sits behind a login.

Can I find someone's real name, email or phone number with UsernameLookup?

No. The service reports whether a public profile exists at an address, with a link, a response time and simple public signals such as the display name shown on that profile. It does not enrich results with personal contact data and does not search data broker sources.

How do I stop my username from appearing in results?

Use the opt-out page. You confirm the request with a code sent to your email, and from then on every lookup checks the suppression list first and returns nothing for that username. We keep only a hash of the username and of the email, not the plain values.

Where is my card data stored?

Not on our servers. Checkout runs on the payment processor's secure page with 3D Secure. We keep the subscription status, the plan and the invoice references the processor sends back, nothing more.

How do I report misuse of the service?

Write to [email protected] with the username, the date and what happened. We review every report, and accounts that break the Acceptable Use policy are suspended.

Run a public profile lookup

One username across 300+ public sites. Found, free or unknown, with links and nothing behind a login.