Privacy Policy — Umbra
Status: Published for transparency · Effective 2026-08-16
Contact: [email protected] · [email protected]
This policy describes the hosted service at umbra-osint.com. The open-source CLI and wiki corpus you run yourself are under your control; this policy does not apply to self-hosted installs.
1. Who we are
The Service is operated by the operator of Umbra (contact: [email protected]). There is no separate corporate entity named in this policy yet; if that changes, this page will be updated.
2. No accounts
Umbra has no user accounts and no passwords. When you run a search or reputation check, your browser receives a signed cookie with an opaque owner id so you can see your own cases. We do not ask for your name or email to use the product.
3. Data we process
| Category | Examples | Purpose |
|---|---|---|
| Session | Signed owner cookie, optional operator cookie | Show you your cases; protect the operator console |
| Investigation data | Domains, IPs, emails, usernames, notes you submit; graph entities and evidence produced by collectors | Provide the Service you requested |
| Technical | IP address (via Cloudflare), User-Agent, timestamps, rate-limit keys | Security, abuse prevention, reliability |
| Analytics | Privacy-preserving page views (salted visitor hash, no raw IP stored in app analytics) | Understand usage of the public site |
| Security observations | The IP address of hosts that scan or probe the Service — bot crawlers, and requests for paths a scanner would ask for. Never the address of a person browsing the site. | Identify and characterise automated traffic against our own infrastructure |
| Email you send us | Messages to privacy@ / legal@ / abuse@ / support@ | Respond to requests |
We do not sell personal information.
4. Investigation targets
When you look up a domain, IP, or person-related identifier, collectors query public sources and store what they return. People or organizations that appear in results are not “users” of the Service; they may still be data subjects under privacy law. You are responsible for having a lawful basis to investigate. See the Acceptable Use Policy.
5. Cookies
| Cookie | Purpose |
|---|---|
| Owner session (signed) | Associate cases with your browser |
| Operator cookie | Operator console only, after token login |
6. Processors / infrastructure
- Cloudflare — DNS, CDN, tunnel, DDoS protection
- Hosting provider — application and database host
- Email — messages you send to our contact addresses
Subprocessor details may change; material changes will be reflected here.
7. Retention
| Data | Retention |
|---|---|
| Cases and graph data | 90 days from creation, then deleted automatically; you can delete sooner |
| Watches (domains you asked us to monitor) | Belong to their case; checked every 6 h and removed with it |
| Phone numbers looked up | E.164 only, 30 days unless reported; never tied to who looked it up |
| Security observations (scanning IPs) | 14 days; any resulting case follows the 90-day case window |
| Rate-limit counters | In-memory; reset on deploy |
| Server logs | Short operational windows unless needed for security |
| Email to us | As needed to handle the request |
Deletion is self-service: open the case and use Delete this case. That removes the case, its graph, its evidence and the raw collector responses stored on disk. We keep only a record that a case with that id was deleted and when.
Because there are no accounts, we cannot reliably re-identify “your” cases after you clear cookies — without the cookie there is nothing tying a case to you, and we cannot verify a deletion request for one. Delete it while you still have the link, or write to [email protected] with the case id and we will do what we can.
7a. Phone number pages
/phone validates a number against its country's numbering plan and, in a later
release, will show reports the community has left about it.
- We store the number in E.164 form only. We do not store who looked it up.
- A number looked up and never reported is deleted after 30 days — a search is not a record, and we do not want a log of every number people typed.
- Result pages are
noindexand are keyed by an opaque id, so the number is not carried into search engines, browser history or referrer headers. - We do not perform reverse lookup. We do not hold, buy or display the name, address or identity of whoever a number belongs to.
- We will not host a page for emergency numbers or short codes.
If a page concerns your number and you want it reviewed or removed, write to [email protected] with the number. Community reporting is not open yet; when it is, reports will be shown as one person's allegation, never as a finding by us, and a dispute route will ship with it.
8. Your choices
- Delete any case you still hold the link to, from its own page
- Export a case as JSON before deleting it
- Stop using the Service and clear cookies
- Contact [email protected] for questions or deletion requests we can honor with the identifiers you provide
- Do not submit data you are not authorized to process
9. International visitors
The Service may be hosted in the United States. If you access it from elsewhere, you understand data may be processed in the US. Counsel review of GDPR/CCPA applicability is ongoing as the Service grows.
10. Children
The Service is not directed at children under 16.
11. Security
We use transport encryption (HTTPS), an operator gate on console routes, SSRF guards on collector egress, and rate limits on expensive paths. No method is perfect; see SECURITY.md in the project repository for disclosure contact.
12. Changes
We may update this policy. The effective date at the top will change; material updates may also be noted on the site.