
Articles
The Future of Osintly
We have been heads down for the past few weeks, talking through what Osintly looks like next. This post is the result of those conversations.

OSINT can surface information people did not expect to see in one place.
An email can lead to old accounts. A username can connect profiles across different platforms. Historical leaks can contain addresses, passwords, phone numbers, or other information that has been circulating for years.
So asking how an OSINT platform handles that data is reasonable.
Osintly is a search engine and aggregator. It searches across public sources, third-party databases, APIs, public records, and supported leak sources, then brings those results into one interface.
We do not create most of the information returned by a search. But we do operate the platform that brings it together, and that comes with responsibilities around storage, access, deletion, accuracy, and abuse.
This is how it works today.
Osintly is not a no-storage service.
Some OSINT platforms deliberately avoid keeping any search history. There are legitimate privacy reasons for designing a product that way, but it also means that once you leave a result, keeping the investigation becomes your responsibility. If you need the same information again later, you may have to run another search.
We chose a different approach.
Your searches can remain available in your Osintly history. You can come back to a result tomorrow or weeks later without running the same lookup again just to see information you already retrieved.
That matters on a credit-based product. Opening an existing result does not require you to spend another search credit.
It also means a search can become part of an actual investigation instead of behaving like a disposable lookup. Results can stay alongside Projects, notes, files, and other research you have collected.
Of course, keeping an investigation history creates another responsibility: giving you control over when it disappears.
That is why the storage is not permanent by design.
You can delete a search from the Osintly website or API.
When you do, the deletion covers the data associated with that search, including stored results, leak payloads, BYOK outputs, and other linked search artifacts.
Deletion normally happens close to immediately, although it is processed asynchronously and can take longer during periods of high infrastructure load.
Once complete, those search payloads are removed from our database and storage systems.
Limited technical metadata may remain where necessary for rate limiting, abuse prevention, security, or service integrity. That metadata can record that a search occurred, but it does not contain the deleted search payload itself.
Deleting a Project removes its related files, notes, and searches. Account deletion can also be requested from account settings.
We think this is a better trade-off than pretending that privacy has only one possible implementation.
For some investigators, having no history at all may be preferable. For others, being able to reopen previous research without paying for or repeating the same investigation is considerably more useful.
Our infrastructure is distributed rather than hosted in one place.
The main database is hosted in London, R2 storage is located in Europe, and search servers operate across Europe, notably in Finland. Cloudflare Workers provide part of the network layer globally.
We also rely on external services to run different parts of Osintly, including Supabase, Cloudflare, Amplitude, Google Analytics, Resend, Stripe, Plisio, and AI providers.
Some of these providers operate globally, which means certain processing may take place outside the European Economic Area. Where applicable, our Privacy Policy describes the safeguards used for those transfers.
We prefer to be specific about the services involved and where processing takes place rather than relying on broad privacy or security claims.
You can read the current infrastructure and provider list in our Privacy Policy.
What happens when you are not the person running the search, but the person appearing in it?
Osintly provides a removal process for personal information appearing through our search index and API.
You can contact contact@osint.ly and request that specific results concerning you are blacklisted. We may request identification documents so the request can be verified.
Osintly is an aggregator. We can control what appears through Osintly, but we cannot delete information from an independent source that we do not operate.
More information is available under the OSINT Data Rights & Removal section of our Privacy Policy.
Running Osintly requires external infrastructure.
Supabase provides database and authentication services. Cloudflare is used for hosting, networking, security, and content delivery. Resend handles transactional emails. Stripe processes supported subscription and credit payments, while Plisio is used for cryptocurrency payments.
Amplitude and Google Analytics are used for product and usage analytics.
This means using Osintly does not mean your data only ever touches a server directly operated by us. The providers involved and their roles are listed publicly in the Privacy Policy rather than grouped under a generic reference to unnamed infrastructure partners.
Our mapping services, on the other hand, are self-hosted.
Osintly includes AI features for things such as summaries and chat.
Running a normal search does not automatically mean sending that research to an AI provider.
Research data is sent to an AI service when you explicitly trigger an AI feature that needs it. That provider can then process the relevant input to return the requested output.
There is also an accuracy issue with AI.
An AI-generated summary can misunderstand a relationship between two findings, miss context, or produce information that is not supported by the underlying results.
For that reason, our Terms require AI-generated information to be checked against the original sources.
The result comes first. The AI explanation around it should not be treated as evidence on its own.
You will sometimes see OSINT products advertised with claims of perfect accuracy or zero false positives. We do not make that claim.
It would be difficult to reconcile with how OSINT actually works.
Most results shown by Osintly originate somewhere else. A public platform can return outdated information. Historical leak data can be years old. An account can change after it was indexed. A third-party provider can be unavailable or return incomplete data.
Even a technically correct result can be interpreted incorrectly.
Finding the same username on two platforms does not prove the accounts have the same owner.
Finding an email address in a leaked dataset proves that the address appears in that dataset. It does not automatically prove every conclusion someone might draw from the surrounding record.
A platform can make its modules more reliable, reduce false positives, validate data, and improve source attribution. We work on all of those things.
That still is not the same thing as saying every result will always be 100% correct.
Our Ethics Policy asks users to distinguish facts from inference and corroborate important findings across independent sources before reaching a conclusion.
For serious investigations, understanding where a result comes from and being able to verify it matters more than any headline accuracy claim.
The amount of information accessible through OSINT makes abuse controls necessary.
Osintly permits legitimate uses such as security research, checking your own exposure, defensive security, threat intelligence, auditing, and authorized investigations.
Harassment, doxxing, stalking, and illegal activity are prohibited.
The Ethics Policy also draws a line between OSINT research and offensive activity. Using Osintly to prepare an unauthorized intrusion, cyberattack, or malicious social engineering campaign is not an acceptable use of the platform.
The same applies to automation.
The API cannot be used for indiscriminate bulk collection or to bypass safeguards, rate limits, and other anti-abuse systems. API keys and webhook secrets also have to be kept private.
Accounts and API access can be restricted or terminated when those rules are violated.
"Public" does not mean "use it however you want."
Our Ethics Policy asks users to collect only the information needed for a legitimate investigation and avoid gathering sensitive personal data that has no purpose in that investigation.
It also asks investigators to consider context before sharing a finding.
Something can technically be accessible online and still cause unnecessary harm when republished to a much larger audience without a legitimate reason.
The same principle applies after an investigation.
Research data should not be kept indefinitely simply because storage is available. Once it is no longer needed, it should be deleted.
History is there because investigations often need continuity. Auto Delete and manual deletion are there because that continuity should not remove your control over retention.
No online service can honestly make that guarantee.
Our Privacy Policy explicitly recognizes that no method of internet transmission or electronic storage is 100% secure.
Osintly uses security measures intended to protect personal and research data from unauthorized access, disclosure, alteration, or destruction, but that should not be interpreted as a promise that a security incident could never happen.
Users have responsibilities here too.
Account credentials should be protected. API keys should never be publicly exposed or shared, and should be rotated or revoked if exposure is suspected.
Security is shared between the platform, the infrastructure it relies on, and the way an account is used.
There is no useful way to answer that with a simple "100% safe" claim.
Osintly stores your searches because having an investigation history is useful. You can reopen previous results without running the same search again, and you can delete those results when you no longer need them.
We document the third-party services involved in operating the platform instead of pretending everything happens inside a black box.
People whose information appears through Osintly can request removal from our search index and API.
We restrict abusive uses of the platform.
And we do not tell investigators that every result they see is infallible.
OSINT deals with uncertain, changing, and sometimes sensitive information. A platform built for it should acknowledge that.
You can read the current rules directly in our Privacy Policy, Terms of Use, and Ethics Policy.
On this page

Articles
We have been heads down for the past few weeks, talking through what Osintly looks like next. This post is the result of those conversations.

Announcements
Osintly now offers more than 50 published email OSINT modules. See how Google, Flickr, Garmin Connect, Microsoft Teams, NPM, and more enrich an email address.

Announcements
We now have two major gaming tools live on Osintly, Epic Games and Xbox. Here's why that matters more than it looks.

Announcements
Ask OSINT questions, browse breach intelligence, and run module lookups — directly inside ChatGPT.
1,550+ ready-to-use OSINT modules covering people, companies, domains, emails, and more.
Everything you need to integrate Osintly into your workflow, from quick start to advanced APIs.
Connect with thousands of OSINT investigators. Share techniques, ask questions, collaborate.
Tutorials, case studies, and insights from our team of open source intelligence specialists.
1,550+ OSINT modules. AI analyst built-in. Real-time data. Everything you need in one place.