09 // LEGAL

Privacy Policy

Last updated: 7 August 2026

This policy explains what personal data Open World collects, why we collect it, how long we keep it, and what rights you have. We built the Service to hold as little personal data as possible, and this policy describes exactly what that means in practice.

1. The short version

We store an account for you, the searches you choose to run, hashed API keys, and the billing identifiers our payment processor gives us. We do not maintain, compile, license, buy, or sell a database of personal data about the people you search for. Search results are fetched live from public websites at the moment of your query and are not retained by us as a dataset. We do not sell personal data and we do not use advertising trackers.

2. Who is responsible for your data

Open World is the controller of the personal data described in this policy. Open World is operated by a registered legal entity whose registered name, address, and company details are available on request via our contact page. For any privacy question or request, write to privacy@openworld.io.

3. What we collect

Account data. Your email address, your name, and either a password hash (we use bcrypt; we never store passwords in plaintext) or, if you sign in with Google, the identifier that links your account to your Google profile, plus the email address and name Google returns.

Search history. The query text you submit, the search type, the timestamp, and a JSON snapshot of the results that were returned. We store this so that you can revisit your own searches; it is visible only to you and to the small number of staff who need access to operate the Service.

API keys. Keys are stored only as hashes, together with a short non-secret prefix so you can tell your keys apart, their creation date, and their last-used date. We cannot recover the full key after it is issued.

Billing data. We accept cryptocurrency only, processed by our payment provider NOWPayments. We receive a payment identifier, the plan purchased, and its status. We never see a credit card, bank account, or your wallet's private keys; payment is made on NOWPayments' hosted checkout.

Technical and security data. Server and request logs containing IP address, user agent, timestamps, requested routes, and rate-limit counters, plus error reports (which may include a stack trace and the account identifier associated with the failing request).

Support correspondence. If you email us or use the opt-out form, we keep the message and our reply.

4. Data about people who appear in results

When you run a search, we send live requests to public websites and public APIs and pass what they return back to you. That output can contain personal data about the person searched for. We do not store that output independently of your account: it exists in the result snapshot attached to your own search history and nowhere else, and it is deleted when that history entry is deleted. We do not enrich it with purchased data, do not build profiles, and do not share it with anyone other than you.

Any person can ask to be excluded from future results using our opt-out form. Because we hold no source database, an exclusion prevents our Service from surfacing that identifier in future queries; it cannot delete anything from the underlying public websites, which must be contacted directly. To honour an exclusion we have to remember it, so we keep the excluded identifier in an irreversibly hashed suppression list for as long as the exclusion stands.

5. Why we use your data, and our lawful bases

To provide the Service (performance of a contract). Creating and authenticating your account, running your searches, storing your history, issuing API keys, applying plan quotas, and sending transactional email such as password resets and receipts.

To take payment (performance of a contract).Processing fixed-duration plan purchases paid in cryptocurrency through NOWPayments.

To keep the Service secure and prevent abuse (legitimate interests). Rate limiting, fraud and abuse detection, debugging, error monitoring, and enforcing our Acceptable Use Policy. Our interest is in running a stable service that is not used to harm people; we have weighed this against your rights and limit ourselves to the data needed for that purpose.

To process searches involving third parties (legitimate interests). Making publicly available information findable supports security research, fraud prevention, and people's awareness of their own digital footprint. We balance this against the interests of the people searched for by querying only public sources, never retaining a database, and offering an unconditional opt-out.

For non-essential cookies and analytics (consent). These load only after you accept them, and you can withdraw consent at any time. See our Cookie Policy.

To meet legal obligations (legal obligation). Keeping tax and accounting records and responding to valid legal requests.

6. How long we keep data

Search history: 90 days from the date of the search, after which it is deleted automatically. You can delete any entry, or your whole history, sooner from your account.

Account data: for as long as your account exists. When you delete your account we remove it and its associated history and API keys immediately, and purge it from encrypted backups within 30 days.

API keys: until you revoke them or delete your account.

Billing records: invoices and related accounting records are kept for as long as tax and company law requires, typically seven years from the end of the financial year, even after your account is closed.

Server and security logs: 30 days. Error reports: 90 days.

Support correspondence: 24 months.

Opt-out suppression records: kept in hashed form for as long as the exclusion is in place, because deleting them would undo the exclusion.

7. Who we share data with

We do not sell personal data and we do not share it for advertising. We use a small number of processors who handle data on our instructions and under a data-processing agreement:

  • NOWPayments — cryptocurrency payment processing.
  • Resend — delivery of transactional email such as sign-in, password reset, and billing notifications.
  • Sentry — application error and performance monitoring.
  • Our cloud hosting and managed database providers — running the application and storing its data. The current list of providers and their locations is available on request.

We may also disclose data where we are legally required to, or where it is necessary to establish, exercise, or defend legal claims. If Open World is ever involved in a merger or acquisition, data may transfer to the acquirer, subject to this policy.

Separately, running a search necessarily sends the identifier you typed to the public websites and APIs being checked, because that is how the check is performed. Those sites are independent controllers of their own logs. We do not send them your account details.

8. International transfers

Our processors may store or process data outside the country where you live, including in the United States. Where data leaves the European Economic Area or the United Kingdom, we rely on an adequacy decision where one applies, and otherwise on the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant), combined with technical measures such as encryption in transit and at rest. You can request a copy of the safeguards we use by writing to privacy@openworld.io.

9. Security

Traffic is encrypted with TLS, passwords are hashed with bcrypt, API keys are stored only as hashes, and access to production systems is restricted to the staff who need it and protected by multi-factor authentication. No system is perfectly secure, but if a breach affects your personal data and is likely to result in a risk to your rights, we will notify you and the relevant supervisory authority without undue delay and within the time limits the law requires.

10. Your rights

Subject to the conditions in applicable law, you have the right to access the personal data we hold about you; to have inaccurate data rectified; to have your data erased; to receive your data in a portable, machine-readable format; to object to processing based on our legitimate interests; to ask us to restrict processing while a dispute is resolved; and to withdraw consent at any time where processing is based on consent, without affecting processing that already took place.

You can export your data and delete your account yourself from the settings page of your account, which is usually the fastest route. For anything else, email privacy@openworld.io. We respond within 30 days and may ask you to confirm your identity before acting on a request. We do not charge for these requests unless they are manifestly unfounded or excessive.

If you are unhappy with how we handled your request, you may complain to the data protection supervisory authority in your country of residence, place of work, or the place where you believe the problem occurred. In the United Kingdom this is the Information Commissioner's Office. We would appreciate the chance to resolve the issue first.

If you are a California resident, you have equivalent rights to know, delete, correct, and to opt out of the sale or sharing of personal information. We do not sell or share personal information as those terms are defined by the CCPA, and we will not discriminate against you for exercising your rights.

11. Automated decision-making

We do not make decisions producing legal or similarly significant effects about you by automated means alone. Search results are generated automatically, but they are information presented to you, not a decision about you, and Open World does not score, rank, or grade people.

12. Cookies

We use strictly necessary cookies to keep you signed in and to protect forms against cross-site request forgery, and preference cookies to remember your language and your cookie choice. Analytics and error monitoring that rely on non-essential storage load only after you accept them. Full details, including how to change your choice, are in our Cookie Policy.

13. Children

The Service is not directed at children. You must be at least 16 years old (or the minimum age of digital consent in your country, if higher) to create an account. We do not knowingly collect personal data from children below that age; if you believe a child has given us data, contact privacy@openworld.io and we will delete it.

14. Changes to this policy

We may update this policy as the Service changes. The date at the top of the page always reflects the current version, and for material changes we will notify account holders by email or in the app before the change takes effect.

15. Contact

Privacy and data-protection requests: privacy@openworld.io. Security reports: security@openworld.io. Everything else: hello@openworld.io.