Privacy Policy

Last updated 27 August 2026

This service processes personal data about two different groups of people: our customers, and the people our customers look up. The second group did not sign up with us, so this policy is explicit about what happens to their data and how it can be removed.

1. Who we are

Digital Footprint is operated by CSA APPS, the data controller for the purposes described below. For questions about this policy, or to make a request about your data, write to sales@digifootprint.dev.

2. Two roles, depending on whose data it is

For our customers’ own data: your account, your billing, your usage. We are the controller, and we decide what to collect and why, and this policy explains it.

For the data in a lookup: the email address, phone number, or username that a customer submits, and everything we find about it. The customer is the controller and we are their processor. They choose who to look up and why; we act on their instruction. That means we cannot decide on our own to look someone up, and it also means a customer’s lawful basis is theirs to have, not ours to supply.

3. What we collect from account holders

  • — Email address and a password, stored only in hashed form. We never store the password itself.
  • — The use case you declare at signup, and any detail you add to it.
  • — The API keys we issue you, retained only in hashed form. A key is shown once when created and cannot be recovered afterwards, by you or by us.
  • — Your lookup history: the queries you ran and when. Visible only inside your own session; never shown to another customer.
  • — Subscription and plan status. Card details are handled entirely by our payment provider and never reach our servers.
  • — Server logs of API requests, for security, abuse detection, and debugging.

4. What we process about the people looked up

When a customer submits an identifier, we check public platform surfaces and third-party sources and record what came back. That can include:

  • — The identifier itself: an email address, phone number, or username.
  • — Whether an account appears to exist on each platform checked, the method used to establish it, and the time it was checked.
  • — Historic data-breach records associated with an email address.
  • — Publicly indexed web pages mentioning the identifier.
  • — For phone numbers: carrier, line type, country, and whether the number is valid.
  • — For email addresses: which provider hosts the domain’s mail, derived from public MX records.

All of it comes from publicly accessible surfaces or from the categories of third-party source described in section 7. We do not buy personal data, we do not sell it, and we do not use it to build a profile of our own or to train models. A result we cannot confirm is reported as unconfirmed rather than guessed.

5. Why we process it

  • — To provide the service our customer has asked for. Their instruction is the basis for lookup processing, and their own lawful basis governs whether the query should have been run.
  • — To perform our contract with an account holder: authentication, plan limits, billing, support.
  • — For our legitimate interests in operating the service securely: rate limiting, abuse detection, fraud prevention, and diagnosing failures.
  • — To comply with legal obligations, including tax and accounting records.

6. How long we keep it

We will be straightforward about this, because it is the part most policies are vague on.

  • — Lookup records are retained indefinitely unless deleted on request. There is no automatic expiry. A customer’s lifetime free allowance is counted from these records, so deleting them would reset an allowance that is meant not to reset.
  • — Cached platform results are refreshed, not deleted. Each stored result has a freshness window: 48 hours for a confirmed account, 12 hours for a not-found, 14 days for a breach record, 7 days for phone and mail-provider data. When that window passes we re-check and update the record. The window governs how long we trust an answer, not how long we keep it.
  • — A short-lived hot cache in Redis holds a full response for 5 minutes to absorb repeat queries, then expires by itself.
  • — Account data is kept while the account is open, and for up to 90 days after closure so it can be restored if the closure was a mistake.
  • — Billing records are kept for as long as tax law requires, typically six to seven years.

We are working toward automatic expiry of lookup records. Until it exists, deletion is on request and we do it by hand, see section 9.

7. Who else processes the data

We use a small number of specialist providers, each receiving only what it needs for its own function and none of them permitted to use it for their own purposes. They fall into these categories:

  • — Data-breach and account-intelligence providers, which answer queries about a single identifier.
  • — A web search provider, for publicly indexed pages mentioning an identifier.
  • — A telephone numbering provider, for line validity and carrier.
  • — A transactional email provider, used only for password resets. We send no marketing email.
  • — Paddle.com Market Ltd, our merchant of record for payments. Card details go to them and never to us.
  • — Cloud infrastructure providers, for application hosting, database, and cache.

Some checks are performed by our own systems, which query a platform directly and share nothing with any party other than that platform.

Some of these operate outside your country, so data may be transferred internationally. Where that involves the UK or EEA, transfers rely on the UK Addendum or the EU Standard Contractual Clauses.

8. Cookies

One cookie: an httpOnly, same-site session token set when you sign in, which the browser cannot read from JavaScript. It exists so you stay signed in. There is no analytics, advertising, or third-party tracking cookie anywhere on this site, and nothing to opt out of. Paddle sets its own cookies inside the checkout overlay when you open it, governed by their policy.

9. Your rights, including if you were looked up

Depending on where you live you may have the right to access the personal data we hold about you, correct it, have it deleted, object to or restrict its processing, receive a portable copy, and complain to your data protection authority.

If you believe you have been looked up and want your data removed, write to sales@digifootprint.dev with the identifier concerned. We will delete every stored result for it. Two honest limits: where we hold the data as a processor we may need to pass the request to the customer who is its controller, and deleting a record does not stop the same identifier being checked again later. The underlying information is on the platforms, not with us. We respond within 30 days and do not charge for this.

10. Security

Passwords, API keys, and password-reset tokens are stored only in hashed form using current industry-standard algorithms, and are unrecoverable once issued. Session tokens are held in cookies that browser JavaScript cannot read. All connections use TLS. Access to production data is limited to those who need it.

No system is perfectly secure. If a breach affects your personal data and the law requires notification, we will notify you and the relevant authority within the required time.

11. Children

The service is for business use and is not directed at anyone under 18. We do not knowingly create accounts for children. Customers must not use the service to investigate minors.

12. Changes

If we change this policy materially we will email account holders and update the date above. See also our terms of service, which govern what customers may use the service for.