Scope and roles
This policy explains how datafetch.wtf ("datafetch", "we", "us") handles personal data when you visit this site, create an account, and use the investigation console and API.
Two distinct roles apply, and the difference matters:
- Your account data
- We are the controller — signup, billing metadata, usage and security logs
- Your query inputs
- You are an independent controller — you choose the selector and the lawful basis
We do not decide who you investigate and we do not review your case rationale. Running a lawful query is your responsibility under the Acceptable Use Policy.
What we collect
We keep the set of data small and tied to a purpose.
- Account
- First and last name, username (optional), email, password hash
- Billing
- Plan, amount, currency and provider transaction reference
- Usage
- Module queried, timestamp, credit cost, success or failure
- Technical
- IP address, user agent, rate-limit and bot-protection signals
- Query inputs
- The selector you submit, for the lifetime of the request and its cache entry
We do not ask for government identifiers, and we do not hold full payment card numbers — those go directly to the payment provider at checkout.
Why we process it, and on what basis
Under GDPR every purpose needs a lawful basis. Ours are:
- Provide the service
- Contract — Art. 6(1)(b)
- Billing and records
- Contract and legal obligation — Art. 6(1)(b), 6(1)(c)
- Abuse, fraud and rate limiting
- Legitimate interest — Art. 6(1)(f)
- Security logging
- Legitimate interest — Art. 6(1)(f)
- Newsletter
- Consent — Art. 6(1)(a), withdrawable at any time
We do not sell personal data, we do not run behavioural advertising, and we do not use your query history to build profiles for marketing.
Your queries and third-party data
The console returns information about people who are not our customers. That data reaches you because you asked for it, so a few rules follow from that:
- You must have a lawful basis and, where required, a mandate or authorization before you query a selector.
- You are responsible for informing data subjects where the law requires it.
- Results are not verified facts. Treat them as leads to corroborate, not conclusions.
- Breach and stealer-log corpora are historical. Presence in a corpus is not evidence of current compromise or of wrongdoing.
If you are a member of the public and want identifiers reviewed or delisted, use Data removal — requests are processed manually.
Processors and third parties
We use a short list of providers. Each receives only what it needs to do its job:
- Console access
- Authentication and session issuance — receives the key we issue to your account
- Cloudflare
- CDN, WAF and Turnstile bot protection — receives IP and request metadata
- coresint
- Upstream OSINT API — receives the selector you submit
- ipwho.is
- Keyless IP geolocation for the map — receives the IP being plotted
- Payment provider
- Checkout and receipts — receives billing details directly
We disclose data to authorities only where we are legally compelled, and we push back on requests that are overbroad or lack legal footing.
International transfers
Infrastructure and providers may operate outside your country, including outside the EEA and the UK. Where a transfer occurs we rely on an adequacy decision where one exists, and otherwise on Standard Contractual Clauses together with technical measures such as encryption in transit and data minimisation.
How long we keep it
- Account data
- While your seat is active, then a limited period for abuse prevention
- Billing records
- As required by tax and accounting law
- Usage and security logs
- A rolling window sized for abuse investigation
- Query result cache
- Short-lived; evicted automatically
- Data removal tickets
- Kept as a record that the request was actioned
Lifetime plans mean your entitlement does not expire. It does not mean logs are kept forever.
Security
There is no password login to leak: access is a rotatable key we issue to your account, and every request is HTTPS only, rate limited and counted against your own ledger. The full posture, and how to report a flaw, is on the Security page.
Your rights
You can request access, rectification, erasure, restriction, objection and portability for the data we hold about you, and you can complain to your supervisory authority. The mechanics, including what we can and cannot erase, are set out on the GDPR page.
Changes to this policy
When this policy changes materially we update this page and, for changes that affect how we use your data, notify account holders in the console. Continuing to use the service after a change means you accept the updated policy.
Contact
Reach us through the Telegram help desk or a console ticket. Privacy and data-removal requests are handled manually, so include enough detail to identify the records in question.
Registered operator details: the legal entity name, registered address and, where one is appointed, the data protection officer or Art. 27 representative must be published here before this policy is relied upon.
