Acceptable Use Policy

Last updated: 7 August 2026

Open World makes publicly available information easier to find. That is useful for security research, fraud prevention, and understanding your own digital footprint — and it can be misused to harm people. This policy sets out what you may and may not do with the Service. It forms part of our Terms of Service and applies to the web app, the API, and anything built on top of them.

1. Permitted use

The Service is intended for lawful purposes, including cybersecurity and threat intelligence research, incident response, brand and trademark protection, fraud and account-takeover prevention, journalistic and academic research, due diligence and anti-money-laundering checks where permitted by law, lawful investigations, and letting people see what is publicly visible about themselves.

Whatever your purpose, you must comply with applicable law. If you process results about identifiable people, you act as an independent controller and you need your own lawful basis under the GDPR, the CCPA, or the equivalent law where you operate.

2. Prohibited purposes

Decisions regulated by the Fair Credit Reporting Act. Open World is not a consumer reporting agency and its output is not a consumer report. You may not use the Service, in whole or in part, to decide or help decide a person's eligibility for employment, promotion, retention, or reassignment; for credit or loans; for insurance; for housing or tenancy; for professional licensing; or for any other purpose covered by the FCRA (15 U.S.C. § 1681 et seq.) or an equivalent law elsewhere.

Stalking, harassment, and doxxing. You may not use the Service to track, follow, intimidate, threaten, or harass anyone; to locate a person who does not want to be found, including a survivor of domestic abuse or a witness; or to compile and publish a person's private details in order to expose them to harassment or danger.

Unlawful surveillance. You may not use the Service to monitor a partner, family member, employee, or any other person without the legal authority to do so, or to conduct state or corporate surveillance that violates human-rights or data-protection law.

Discrimination. You may not use the Service to treat people differently on the basis of race, ethnicity, national origin, religion, sex, gender identity, sexual orientation, disability, age, health status, political opinion, trade-union membership, or any other protected characteristic.

Crime and deception. You may not use the Service to plan or carry out identity theft, social engineering, phishing, extortion, blackmail, credential stuffing, unauthorised access to systems, or any other criminal act, or to build target lists for such activity.

Bulk automated collection beyond your plan. You may not run automated enumeration, mass harvesting, or bulk collection that exceeds the quota and rate limit of your plan, and you may not use the Service to construct a standing database or index of people.

Circumventing limits. You may not evade quotas or rate limits by creating multiple accounts, rotating API keys, distributing requests across IP addresses or proxies, sharing credentials, or scripting against the web interface instead of the API.

Reselling raw results. You may not resell, sublicense, syndicate, or redistribute raw results or bulk output, or use them to create a competing search, data-broker, or people-search product. You may use results within your own organisation and include findings in reports you produce for your clients.

Training and derived datasets. You may not use output from the Service to build, train, or fine-tune a model or dataset intended to identify, profile, or score people.

Attacking the Service or its sources. You may not probe, overload, or disrupt Open World or the public sources it queries, attempt to bypass authentication, reverse engineer the Service, or interfere with other users.

3. Sensitive searches

Some searches carry a high risk of harm even when the underlying information is public — for example searches concerning minors, survivors of abuse, protected witnesses, or people whose safety depends on not being found. Do not run them unless you have a clear legal basis and authority. We may decline or block such queries.

4. Reporting abuse

If you believe the Service is being misused, tell us at security@openworld.io with as much detail as you can share. If you are the subject of a search and want to be excluded from future results, use our opt-out form.

5. Enforcement

We monitor for abuse through rate limiting, automated anomaly detection, and review of reports we receive. Depending on the severity and whether the behaviour is repeated, we may warn you, throttle or suspend your account or API keys, remove access to specific features, terminate your account, or refuse future service. Serious cases — in particular those involving stalking, threats, or crime — may be suspended immediately without warning and reported to law enforcement or the relevant regulator.

Where we terminate an account for a breach of this policy, prepaid fees for the current period are not refunded. If you believe we acted in error, email hello@openworld.io and we will review the decision.

6. Changes

We may update this policy as new forms of misuse appear. The date at the top of the page reflects the current version, and we will notify account holders of material changes before they take effect.