security / data boundaries
Security and privacy boundaries
UsernameLookup checks public profile addresses only. It never logs in, never reads private content and never collects real names, emails, phone numbers or addresses. This page explains what we check, what we store, how long we keep it and how people can opt out.
Public profile addresses and nothing behind them
A lookup takes one username and asks each of 300+ sites whether a public profile answers at the address that site uses for its members. The answer is read the way a browser reads it: a profile page, a not found page, or something in between that we mark as unknown instead of guessing.
That is the whole scope. We do not sign in to platforms, we do not hold accounts on them to see more, and we do not scrape anything that requires authentication, a follow request or an accepted friendship. If a profile is private, the only thing the result says is that an address exists.
Our requests identify themselves honestly and respect the platform's own rate limits. Adult and explicit categories are excluded from the site list, so a lookup never sends anyone to that kind of content.
- Public profile URL checked
- HTTP status and page title checked
- Display name and avatar on the public page compared
- Logins or sessions on the platform never
- Content behind authentication never
- Adult and explicit sites excluded
Data we do not collect about the people you search
A username lookup answers a narrow question: where does this handle exist in public. It is not a people search, and it is built so that it cannot become one.
-
Real names
We never resolve a handle to a legal name or try to match it against records.
-
Email addresses
No email discovery, no guessing of addresses from handles.
-
Phone numbers
No phone lookups and no reverse search from a number.
-
Home or work addresses
No location data, no maps, no address history.
-
Private posts and messages
Nothing behind a login, a follow request or a privacy setting.
-
Enrichment from third parties
We do not buy, merge or append data from brokers or other databases.
What we store and for how long
The service stores what it needs to run your account and to give you the history of your own work. Lookup history and evidence belong to the workspace that created them and are visible only to its members.
| Data category | Stored | Purpose | Retention |
|---|---|---|---|
| Account (email, hashed password, name you enter) | yes | sign in, security codes, billing notices | while the account exists |
| Workspace and team roles | yes | access control between members | while the workspace exists |
| Lookup history per workspace | yes | history, diff between runs, exports | until you delete it or close the account |
| Results (site, status, profile URL, response time) | yes | show and compare results | with the lookup they belong to |
| Evidence snapshots (URL, timestamp, HTTP status, page title) | yes, Investigator and up | case notes and PDF reports | until you delete them or close the account |
| API keys | hash only | authenticate API calls | until you revoke the key |
| Card numbers | no | handled by the payment processor | never on our servers |
| Demo visitor marker (cookie and hashed IP) | yes | enforce the one-time demo | IP hash counted for 30 days |
| Opt-out requests | hash of username and email | suppress the username in every lookup | while the opt-out is active |
When you close an account, the workspace data is deleted from the live system and disappears from backups as they rotate. Invoices are kept for the period tax law requires.
How accounts and API access are protected
Hashed passwords
Passwords are stored only as salted hashes with a slow algorithm. Nobody on our side can read them, and we never send them by email.
Email code at signup
A new account is confirmed with a one-time code sent to the address, so nobody can open an account in someone else's name.
API keys stored as hashes
A key is shown once when you create it. We keep only its hash, so a copy of our database would not give anyone working keys. Revoke a key in one click.
Rate limits per account and IP
Each plan has monthly quotas and per minute limits, enforced per account and per IP address. Bulk abuse hits a 429 response long before it becomes a problem.
Roles inside a workspace
Administrators manage billing, keys and members. Editors run lookups and work on cases. Members see only the workspaces they belong to.
Encrypted connections
Every page and API endpoint is served over HTTPS only.
Payments are handled by a payment processor on its own secure checkout page with 3D Secure on every card payment. Card numbers never reach our servers. We receive the plan, the subscription status and invoice references, which is all the account needs. Plan details are on the username lookup pricing page.
The opt-out list is checked before every lookup
Anyone can ask us to stop returning results for their username. The request is confirmed with a code sent to an email address, and once confirmed the username goes on a suppression list.
Every lookup, every API call and every monitoring run checks that list first. A suppressed username returns no sites at all, on every plan, including Enterprise. Customers cannot switch this off.
We store only a hash of the username and a hash of the email. That is enough to recognise the name when someone searches it, and it means the list itself does not expose who asked to be removed. Start on the username opt-out page.
-
step 1
Enter the username and an email
The email is used only to send the confirmation code.
-
step 2
Confirm the code
The code expires after a short time. Unconfirmed requests are not applied.
-
step 3
Suppression is active
From that moment, lookups of that username return no results.
How we handle misuse
UsernameLookup is built for brand protection, fraud prevention, trust and safety and security research. Using it to stalk, harass, dox or profile private people is forbidden by the acceptable use policy, and every account accepts that policy at signup.
Report misuse to [email protected] with the username concerned, the date and a short description. We review each report, and accounts that break the policy are suspended without a refund. Where the law requires it, we cooperate with competent authorities.
Teams that need a structured workflow for impersonation cases can read how brand impersonation monitoring keeps a case board and report links for each finding.
Site detection data includes the open WhatsMyName dataset, CC BY-SA 4.0.
Questions about security and privacy
Does UsernameLookup log in to any platform or read private posts?
No. Every check requests the public profile address of a username, the same page anyone can open in a browser without an account. We never sign in, never use your credentials or ours on a platform, and never read anything that sits behind a login.
Can I find someone's real name, email or phone number with UsernameLookup?
No. The service reports whether a public profile exists at an address, with a link, a response time and simple public signals such as the display name shown on that profile. It does not enrich results with personal contact data and does not search data broker sources.
How do I stop my username from appearing in results?
Use the opt-out page. You confirm the request with a code sent to your email, and from then on every lookup checks the suppression list first and returns nothing for that username. We keep only a hash of the username and of the email, not the plain values.
Where is my card data stored?
Not on our servers. Checkout runs on the payment processor's secure page with 3D Secure. We keep the subscription status, the plan and the invoice references the processor sends back, nothing more.
How do I report misuse of the service?
Write to [email protected] with the username, the date and what happened. We review every report, and accounts that break the Acceptable Use policy are suspended.
Run a public profile lookup
One username across 300+ public sites. Found, free or unknown, with links and nothing behind a login.