1. Who Can Access This Platform

csint.baby is strictly invite-only. Access requires a valid invite code issued by an administrator. We do not accept public registrations and do not sell or distribute access. All users have been individually granted access.

2. Data We Collect

We collect the minimum data necessary to operate the platform securely:

  • Account data — your username and a securely hashed copy of your password. Your password is never stored in plain text.
  • Session data — a randomly generated session token and basic connection information used to keep you signed in. Sessions expire after 7 days.
  • Security logs — limited event data retained for abuse prevention and account security purposes.
  • Usage counts — how many times each tool is used per account, used solely to display your personal usage statistics. The content of your lookups is never stored.
  • Invite codes — which code was used to register your account.
  • Announcements — platform-wide messages posted by the owner are stored and visible to all authenticated users. These contain no personal user data.
  • Profile picture — if you choose to upload a profile picture, the image is stored in our database as a re-encoded PNG. All metadata (EXIF, GPS, camera info, etc.) is stripped client-side before upload. Uploading an avatar is entirely optional. You may remove your avatar at any time from your account settings.

We do not log or store the subjects of your lookups — for example the usernames, IDs, or addresses you search for. Query content is forwarded to third-party APIs in real time and is not retained by us.

3. How We Use Your Data

  • To authenticate you and maintain your session.
  • To enforce access control and invite-only registration.
  • To detect and respond to abuse or unauthorised access attempts.
  • To display your personal usage statistics on your account page.
  • To display your chosen profile picture across the platform interface.

We do not use your data for advertising, profiling, or sale to third parties.

4. Third-Party APIs

When you use a tool, your query is forwarded to one or more external services to retrieve results. Each query is subject to that service's own privacy policy. The categories of services we use include social platform APIs, network intelligence services, domain and DNS data providers, and gaming platform APIs.

We do not share your account credentials, session data, or identity with any of these services. Queries are made server-side and are not attributed to individual users by the third-party providers.

5. Cookies and Sessions

We use a single session cookie to keep you signed in. This cookie is:

  • HttpOnly — not accessible to JavaScript, preventing theft via XSS.
  • Secure — only transmitted over HTTPS.
  • SameSite=Strict — not sent on cross-site requests, preventing CSRF attacks.
  • Expires after 7 days.

We do not use tracking cookies, analytics cookies, or third-party cookies of any kind.

6. Data Retention

  • Sessions — deleted automatically after 7 days, or immediately on sign-out or password change.
  • Security logs — retained for a reasonable period for security purposes. Accessible only to the platform owner.
  • Usage counts — retained for the lifetime of your account.
  • Profile picture — retained until you remove it or your account is deleted. You can delete your avatar at any time from your account settings.
  • Account data — retained until your account is deleted by an administrator.

7. Data Security

We implement the following technical measures to protect your data:

  • Passwords are hashed using a strong, modern algorithm with a unique random salt per account.
  • All database queries use parameterised statements to prevent injection attacks.
  • All data in transit is encrypted via TLS.
  • Connections from known anonymisation networks are blocked at the application level.
  • Privileged access is re-verified from the database on every request.
  • Standard web security headers are applied to all responses.

8. Your Rights

As a user of this platform you may:

  • Change your username or password at any time via your account settings.
  • Sign out of all active sessions by changing your password — all other sessions are invalidated automatically.
  • Request deletion of your account by contacting a platform administrator.
  • View your own usage statistics on your account page.
  • Upload, change, or remove your profile picture at any time from account settings.

9. Changes to This Policy

We may update this policy from time to time. The "Last updated" date at the top of this page will reflect any changes. Continued use of the platform after an update constitutes acceptance of the revised policy.

© 2026 csint.baby. All rights reserved.