Terms of Service — Umbra
Published for transparency · Effective 2026-08-16 · Draft pending counsel review on entity formation
Written to match how the hosted service actually works (including no user accounts). This is not a substitute for advice from a lawyer licensed in your jurisdiction. Blanks that still need a real legal entity or counsel decision are called out in §0 and at the end.
0. Blanks you must fill before publishing
These cannot be guessed. Each one changes the legal meaning of the document.
| # | Blank | Why it matters |
|---|---|---|
| 1 | the operator of Umbra (contact: [email protected]) |
There is no entity today. Absent one, you are the contracting party personally — a US sole proprietorship is not a separate legal person, so the liability cap in §12 limits contract damages but does not put a corporate shield between a claimant and your personal assets. Forming an LLC before launch is the single highest-value legal step. |
| 2 | [email protected] |
A contract needs an address for legal notice. A registered-agent or PO box address is normal; a home address is not required but something must be reachable. |
| 3 | the operator's state of residence / the operator's county of residence |
Governing law and venue. Pick where you actually are, or where the entity is formed. Choosing a state you have no connection to invites a challenge. |
| 4 | 2026-08-16 |
The date this is published. Versioned and dated — see §17. |
| 5 | Paid tier | §9 is written as inactive because no billing exists today. Do not enable it until it is true. |
1. Who these terms are between
These Terms are a binding agreement between you ("you") and the operator of Umbra (contact: [email protected])
("Umbra", "we"), covering the website at umbra-osint.com, the hosted
application, and any API we make available (together, the "Service").
The Umbra command-line tool and the umbra-wiki corpus are distributed
separately under the MIT License. Those terms govern that software; these
Terms do not restrict your rights under the MIT License, and nothing here
applies to software you run yourself on your own machine.
By using the Service you accept these Terms and the Acceptable Use Policy, which is incorporated by reference.
2. What the Service is, and what it is not
Umbra is an open-source-intelligence workbench. You give it a starting point — a domain, an email address, an IP, a username — and it queries publicly available sources, records what it finds as a graph of entities and evidence, and produces a report.
It is a research tool, not a source of truth. Specifically:
- Findings are assertions from third-party sources, not verified facts. A reputation verdict reflects what a blocklist published; a leak-site listing reflects what a criminal group claimed. Umbra records provenance so you can check; it does not vouch for accuracy.
- Absence of a finding is not evidence of absence. Sources go down, rate limit, and disagree.
- Nothing produced by the Service is a consumer report, and the Service is not a consumer reporting agency. You must not use it to make decisions about credit, insurance, employment, housing, or any other purpose regulated by the Fair Credit Reporting Act (15 U.S.C. § 1681 et seq.) or equivalent law. That restriction is a condition of use, not a suggestion.
- Nothing produced by the Service is legal advice, and we are not your lawyers.
3. No accounts, and what that means for you
The Service has no user accounts. When you run a search, your browser receives a signed cookie containing an opaque identifier, and cases you create are associated with it.
Three consequences you should understand before relying on the Service:
- Your session is the cookie. Clear your cookies, use a different browser, or use private browsing, and you lose access to the list of your prior cases. We cannot restore it — we have no email address or other identifier that would let us prove a case was yours.
- We can see everything. The operator of the Service can read every case, including yours. Access is limited to the operator by technical controls, but the Service offers you no confidentiality from us. Do not put anything into it that you cannot accept us seeing.
- A case URL is not a secret we protect on your behalf. Only you and the operator can open your case, but if you paste the link somewhere, that is your disclosure.
4. Eligibility
You must be at least 16 years old, or 13 if you are in a jurisdiction that permits it and you have parental consent where required. This threshold reflects GDPR Article 8 (16, lowerable to 13 by member states) and COPPA (15 U.S.C. §§ 6501–6506), which restricts collection from children under 13. If you are under the applicable age, do not use the Service.
5. Your responsibility for lawfulness — the core bargain
This is the most important clause in the document.
You decide whether your use is lawful, and you carry that risk. Umbra will run the queries you ask for. It does not, and cannot, determine whether you are authorized to investigate a particular target, whether your purpose is lawful in your jurisdiction, or whether a source's terms permit your use.
You represent and warrant, each time you use the Service, that:
- your investigation is lawful where you are, where the target is, and under any law that applies to you;
- you have any authorization required — from an asset owner, a client engagement, an employer, or by operation of law;
- you will comply with the Acceptable Use Policy; and
- you will not use the Service for any purpose restricted under §2 above.
5.1 Why "it is public data" is not the end of the analysis
Publicly available information can still be unlawful to collect or use. Three distinct bodies of law apply, and winning under one does not help you under another:
- Computer misuse. The Computer Fraud and Abuse Act (18 U.S.C. § 1030) turns on authorization. Van Buren v. United States, 593 U.S. 374 (2021), narrowed "exceeds authorized access" to a gates-up-or-down question, and hiQ Labs, Inc. v. LinkedIn Corp., 31 F.4th 1180 (9th Cir. 2022), held that scraping data open to the public is unlikely to be access "without authorization." That is a genuine narrowing — and it is limited to the CFAA.
- Contract. The same hiQ litigation ended with hiQ liable for breach of LinkedIn's user agreement. A source's Terms of Service can bind you even where criminal computer-misuse law does not reach. Umbra queries third-party sources on your behalf; their terms are between you and them.
- Data protection. The GDPR applies to personal data regardless of whether it was publicly available, and it reaches organisations outside the EU that offer services to people in the EU (Article 3(2)). "I found it on the open web" is not a lawful basis under Article 6.
6. How the Service makes requests — read this if you are investigating
When you run a case, our servers make the outbound requests, not your browser. DNS lookups, HTTP fetches, certificate-transparency and RDAP queries originate from Umbra's infrastructure and carry our IP address and user agent.
This has consequences you are agreeing to:
- The target may see traffic from us, not from you. If you needed the request to come from your own network, or needed it not to happen at all, do not use the hosted Service — run the MIT-licensed CLI yourself.
- Your input is transmitted to third parties — DNS resolvers, certificate transparency logs, RDAP registries, blocklists, and any keyed service you have configured. Those parties receive the domain, address, or identifier you searched, and have their own privacy practices.
- We apply rate limits and refuse requests aimed at private, loopback, and link-local addresses. You must not attempt to defeat those controls; doing so is a violation of the AUP and may be a violation of §1030.
7. Acceptable use, in brief
The Acceptable Use Policy governs. The absolute lines, repeated here because they are non-negotiable: no child sexual abuse material; no unauthorized access to systems or accounts; no participation in stolen-data markets; no use of the Service to commit stalking, harassment, or doxxing where those are unlawful; no attacks on Umbra's own infrastructure outside SECURITY.md.
8. Your data, our data
Your case data is yours. You grant us only the licence we need to operate the Service: to store, process, transmit and display that data to you, and to make backups. We do not sell it, and we do not use it to build a product for other users.
The Service is ours. The Umbra name and the hosted application are our property. The CLI and the wiki corpus are MIT-licensed — take them.
Deletion. Open the case and use Delete this case. Deletion is immediate and permanent: the case, its graph, its evidence records and the stored collector responses on disk are all removed. We keep an audit record that a case with that id was deleted and when — not its name, its subject, or its contents. There is no account and no undo, so we cannot restore a deleted case for you.
Retention. Cases on the hosted service are deleted automatically 90 days after they are created, whether or not you delete them first. Operational error records are retained for 30 days. We may retain what law requires us to retain. Self-hosted installations keep cases indefinitely unless the operator sets a retention window.
Export. Open the case and use Export JSON for a complete copy — entities, relationships, evidence and runs — at any time before deletion.
9. Fees — inactive
The Service is provided free of charge. There is no paid tier, no billing relationship, and no payment data is collected. If that changes, these Terms will be amended before any charge is made, with notice under §17, and the paid terms will not apply retroactively.
10. Availability
The Service is provided on a best-efforts basis by a single operator. There is no uptime commitment, no support commitment, and no service-level agreement. We may modify, suspend, rate-limit, or discontinue any part of the Service at any time. We will make a reasonable effort to give notice before permanent shutdown, so that you can export your data.
11. Disclaimer of warranties
THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED. TO THE FULLEST EXTENT PERMITTED BY LAW, WE DISCLAIM ALL IMPLIED WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. WE DO NOT WARRANT THAT FINDINGS ARE ACCURATE, COMPLETE, OR CURRENT, OR THAT THE SERVICE WILL BE UNINTERRUPTED OR ERROR-FREE.
(The capitals are not decoration: UCC § 2-316 and its state analogues require warranty disclaimers to be conspicuous to be effective.)
Some jurisdictions do not allow the exclusion of certain warranties. Where that is so, this section applies to the maximum extent permitted, and consumers may retain rights that cannot be waived — including under EU and UK consumer law.
12. Limitation of liability
TO THE FULLEST EXTENT PERMITTED BY LAW, WE WILL NOT BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, LOST DATA, OR BUSINESS INTERRUPTION, ARISING OUT OF OR RELATING TO THE SERVICE, EVEN IF ADVISED OF THE POSSIBILITY.
OUR TOTAL AGGREGATE LIABILITY IS LIMITED TO THE GREATER OF (A) AMOUNTS YOU PAID US IN THE TWELVE MONTHS BEFORE THE CLAIM — CURRENTLY ZERO — AND (B) ONE HUNDRED US DOLLARS ($100).
These limits do not apply to liability that cannot be limited by law, including death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or gross negligence or wilful misconduct where the applicable law prohibits their exclusion. Many US states and most of the EU treat an attempt to disclaim those as void, which is why they are carved out here rather than swept in.
13. Indemnity
You will indemnify and hold us harmless against claims, damages, and reasonable legal costs arising from your use of the Service in breach of these Terms or the AUP, your violation of law, or your infringement of a third party's rights — including claims by a party you investigated, and claims by a source whose terms you breached.
This is the clause that makes §5 real: if your investigation causes a problem, it is your problem.
14. Suspension and termination
We may rate-limit, suspend, or block access, and delete data, if we reasonably believe the Service is being used unlawfully or in breach of the AUP, or to protect the Service or third parties. Because there are no accounts, enforcement is by network and session controls.
You may stop using the Service at any time. Sections 2, 5, 8, 11, 12, 13 and 16 survive termination.
15. Sanctions and export
You may not use the Service if you are located in, ordinarily resident in, or acting on behalf of a person in a country or region subject to comprehensive US sanctions, or if you appear on a US restricted-party list (including OFAC's Specially Designated Nationals list). You are responsible for compliance with export-control and sanctions law that applies to you.
16. Governing law and disputes
These Terms are governed by the laws of the State of the operator's state of residence, without regard
to conflict-of-laws rules. The exclusive venue for disputes is the state and
federal courts located in the operator's county of residence County, the operator's state of residence, and you consent to
personal jurisdiction there.
Small claims. Either party may bring an individual claim in small-claims court.
A deliberate omission: there is no arbitration clause and no class-action waiver in this draft. Consumer arbitration is often recommended reflexively, but for a solo operator with no revenue the economics run the wrong way — under most consumer-arbitration rules the business pays the filing and arbitrator fees, so a single dispute can cost more than a lawsuit, and mass filings can be ruinous. Such clauses are also unenforceable or heavily restricted against consumers in the EU and UK. Decide this with counsel rather than by copying another company's terms.
If you are a consumer resident in the EU or UK, nothing here deprives you of the protection of mandatory local law, including the right to bring proceedings in your country of residence.
17. Changes
We may amend these Terms. The current version and its effective date appear at the top of this document, and material changes will be announced on the site before taking effect. Continued use after the effective date constitutes acceptance where permitted by law. Prior versions are retained in the project's public git history.
18. Contact
- General and legal notice: [email protected] ·
[email protected] - Security disclosure: [email protected] — see SECURITY.md
- Abuse: [email protected]
Counsel review — what an engineer cannot decide
Bring this list, not just the document:
- Entity formation before launch. Everything in §12 is weaker without it.
- Whether the FCRA disclaimer in §2 is sufficient. A tool that assembles personal information and is used for employment screening can be pulled into the FCRA by use, regardless of a disclaimer. Ask specifically whether contractual prohibition is enough or whether technical controls are needed.
- GDPR posture. Article 3(2) likely reaches a public site with EU visitors. Ask: do you need an Article 27 EU representative, a lawful basis analysis for processing third-party personal data, and a DPIA? This is the largest unquantified exposure in the product, because the targets of an investigation are data subjects who never agreed to anything.
- CCPA/CPRA applicability. The thresholds (≥$25M revenue, ≥100k California consumers, or ≥50% of revenue from selling or sharing personal information) are almost certainly not met today. Confirm, and re-check on growth.
- Arbitration — see §16. A decision, not an oversight.
- Section 230 (47 U.S.C. § 230) reach over third-party findings surfaced by collectors, and its limits (federal criminal law, IP claims).
- DMCA §512 — a designated agent registration is only worth the fee if you host user-published content. Today you do not.
- Whether §3's "we can see everything" disclosure is sufficient for the confidentiality expectations of anyone using this on client work.