IntelBase

Privacy Policy

Last updated: March 26, 2026.

1. Introduction

IntelBase respects the privacy of our users and is committed to protecting it through our compliance with this Privacy Policy. This Privacy Policy describes the types of information we may collect from you or that you may provide when you visit our website, IntelBase, and our practices for collecting, using, maintaining, protecting, and disclosing that information.

2. Information We Collect

We collect the following categories of information:

Account information

  • Email address and hashed password (Argon2)
  • Company name (if provided)
  • Google account identifier (if you sign in via Google)
  • IntelBase API key assigned to your account
  • IP address whitelists you configure for API access

Search and lookup data

  • Search queries you submit (such as email addresses)
  • Full lookup results returned by the Service, including linked social accounts, data-breach information, and related metadata. For the information these results may contain about the individual searched, and where it comes from, see Section 6.
  • Date, time, and daily count of each lookup

Network and device information

  • IP address at registration and at each login
  • IP address associated with each request (used for rate limiting)

Billing information

  • Stripe customer and subscription identifiers, invoice records (payment method, status, price, coupon codes, and invoice download URLs). Full payment card details are handled exclusively by Stripe and are never stored on our servers.

Communications

  • Name, email, and message content submitted through our contact or enterprise inquiry forms

Authentication tokens

  • A signed JWT session cookie containing your user ID and expiration time, set on login and cleared on logout

3. How We Use Your Information

We use the collected information for the following purposes:

  • To provide, operate, and maintain the Service and its features
  • To authenticate your identity and manage your account
  • To process lookups and return search results
  • To store your search history so you can review past lookups
  • To enforce plan limits, rate limits, and usage quotas
  • To process payments, manage subscriptions, and generate invoices
  • To detect and prevent fraud, abuse, and unauthorized access
  • To send transactional emails such as account verification, password resets, and important service notices
  • To respond to contact and enterprise inquiries
  • To improve, analyze, and secure the Service
  • To comply with legal obligations and enforce our Terms of Service

4. Accessing, Updating, or Deleting Your Information

You may access and update your personal information through your account settings. You may delete your account at any time using the Delete Account button on your account page.

When you delete your account, your personal account information (such as email, password, and IP addresses) and your user-linked search history are removed. However, lookup results may be retained separately in a de-identified form that is not linked to you as a user. These de-identified results may be kept indefinitely to operate and improve the Service.

Deleting your account does not remove an email address from search results. If you want an address to stop appearing in lookups, see Data Removal Requests below.

5. Data Removal Requests

Removal requests are handled entirely through our claim portal. The process is self-service and verified by email, so we can confirm that the request comes from the owner of the address:

  1. Submit the email address you want removed at intelbase.is/claim.
  2. We send a confirmation link to that address. The link is valid for one hour and proves control of the mailbox.
  3. Opening the link deletes the stored lookup history for that address and adds it to our blacklist, so it can no longer be searched on IntelBase.

IntelBase aggregates information from third-party and public sources. Blocking an address on IntelBase stops it from being returned by our Service, but it does not delete the underlying records held by the original source. To have that information taken down, you must contact the originating data source directly.

We do not process removal requests sent by email. Due to the volume of spam and unverifiable requests, removal is available only through the claim portal. Requests emailed to support or any other address will not be actioned and will not receive a reply.

If you run into a technical problem with the form itself — an error, a confirmation link that will not load, or a verification email that never arrives — you may write to [email protected] for technical assistance only. That address cannot accept or process removal requests; the form must be used to submit one.

6. Individuals Appearing in Search Results (EU/UK GDPR)

Sections 2 through 4 describe information about you, the account holder. This section concerns a different group: the individuals whose details may appear in a lookup performed by someone else. If you have never used IntelBase but believe an address of yours can be searched on it, this section is written for you.

Our role

IntelBase does not scrape, harvest, or maintain its own catalogue of personal information about the general public, and it does not compile profiles in advance of anyone asking for one. When a user submits an address, the Service queries third-party data providers and publicly reachable platform endpoints at that moment and relays what they return. We are not the origin of that information. Consequently, blocking or correcting a record with us changes what IntelBase returns but has no effect on the records held by the originating source, which must be contacted directly. Results produced by a lookup may be retained by us as described under Data Retention.

Notice under Article 14 and the disproportionate-effort exemption

Article 14 of the GDPR applies where personal data is obtained from a source other than the individual concerned, and ordinarily requires the controller to provide that individual with prescribed information within one month. Article 14(5)(b) removes that obligation where providing the information proves impossible or would involve a disproportionate effort, and requires instead that the information be made publicly available.

We rely on Article 14(5)(b). IntelBase holds no verified contact details for, and no relationship with, the individuals who may appear in a lookup; there is no roster of identified people to notify, because results are assembled on demand rather than held as a standing population. Any attempt at individual notification would require us to contact addresses solely in order to tell their owners that those addresses can be searched, which would enlarge the processing rather than reduce it and would itself be an unsolicited disclosure. We consider individual notice disproportionate on that basis. This Privacy Policy, published and kept permanently accessible at intelbase.is/privacy-policy, is the public information required by Article 14(5)(b), and the section you are reading carries the disclosures Article 14(1) and 14(2) would otherwise require.

Categories of data that may be returned

  • Whether an email address is registered on a given platform, and where the platform exposes it, associated profile data such as usernames, display names, avatars, profile URLs, and account creation or last-activity dates
  • Records of data breaches in which the address appears, including the name and date of the breach and the fields exposed in it
  • Dates on which the address was observed, used to construct an activity timeline

Categories of sources

  • Publicly reachable endpoints of consumer platforms, queried to determine whether an address is registered with them
  • Publicly visible profile information exposed by those platforms

Purposes and legal basis

We process this information under Article 6(1)(f) on the basis of legitimate interests, namely enabling fraud investigation, account-takeover and breach-exposure assessment, security research, anti-abuse work, and identity and counterparty verification by our users, together with our own interest in operating the Service. We have weighed those interests against the rights of the individuals concerned, which is why access is tiered and redacted, why the Service is restricted to authenticated and rate-limited services, and why any individual may have an address blocked through the process in Section 5. Where our processing rests on legitimate interests, you have an unqualified right to object to it under Article 21, and you may do so through that same process.

Recipients

Lookup results are disclosed to the user who requested them and, on team plans, to other members of that user's team. They are not published, listed, or made browsable, and they are not sold. The processors we rely on to operate the Service are listed in Section 7.

Your rights

Subject to the conditions in the GDPR, you have the right to request access to personal data we hold about you, to have it rectified or erased, to have its processing restricted, to object to processing as described above, and to lodge a complaint with your national data protection authority. The route for all of these is the claim portal, which verifies by email that the request comes from the person controlling the address; a completed request deletes the stored results for that address and blocks it from further lookups. We do not process these requests by email, for the reasons given in Section 5.

Establishment and applicable law

IntelBase is established in the United States, is operated from the United States, and is not directed at individuals in the European Union or the United Kingdom. This section is provided so that the information required by Article 14 is publicly available, and without prejudice to the question of whether the GDPR applies to our processing.

7. Third-Party Service Providers

We do not sell your personal information. We share limited data with the following categories of third-party providers solely to operate the Service:

  • Payment processing: Stripe receives your email and payment details to process transactions and manage subscriptions
  • Email delivery: Resend receives your email address to deliver transactional messages such as verification codes and password resets
  • Authentication: Google receives an authorization code during OAuth sign-in and returns your email and account identifier
  • Bot protection: Cloudflare Turnstile processes captcha tokens to verify that requests originate from humans
  • Customer support: Freshdesk receives your name, email, and message when you submit a contact form
  • Data-breach lookups: third-party data providers receive the email address you search in order to return breach results

Each provider is bound by its own terms and privacy policy. We require providers to use your data only for the purposes described above.

8. Data Security

We employ technical and organizational measures to protect your data, including VPN-protected infrastructure, TLS/SSL encryption in transit, Argon2 password hashing, and firewall and network-level access restrictions. While we strive to protect your information, no method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Data Retention

We retain your personal data for as long as your account is active or as reasonably necessary to provide the Service, comply with legal obligations, enforce our Terms, and resolve disputes. Lookup results may be stored separately in de-identified form, unlinked from your account, and retained indefinitely even after account deletion. You may delete your account at any time through your account settings or by contacting us at [email protected].

10. Children's Privacy

The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without appropriate consent, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact us at [email protected].

11. Contact Information

If you have any questions or concerns regarding this Privacy Policy or our privacy practices, please contact us at [email protected].

This Privacy Policy is incorporated into and subject to our Terms of Service. By creating an account or using the Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.