Privacy Policy
Last updated: August 4, 2026
This Privacy Policy describes how Tom Samson ("we", "us") handles personal data in connection with OrgIndex (the "Service").
1. What We Collect
- Account data: your email address and a securely hashed password (bcrypt) — we never store your password in plain text and cannot recover it if you forget it.
- Billing data: a Stripe customer ID and subscription status. Card details are handled entirely by Stripe; they never pass through our servers.
- API keys: a securely hashed API key plus a short, non-secret prefix so you can identify your own keys.
- Access and activity data: the timestamp, IP address and browser user-agent string recorded against security-relevant actions on your account — registering, signing in (successfully or not), signing out, changing or resetting your password, verifying your email, creating or revoking an API key, exporting or deleting your account, and subscription changes — together with rate-limit events triggered by any visitor, signed in or not.
- Product usage data (signed-in users only): which features of the Service your account uses — for example, that you ran a search, viewed an organisation page, looked up an IP address, CIDR block or ASN, ran a bulk lookup, or exported a CSV file — and when your account was last active. This is kept as an hourly count per account per feature, not a request-by-request log: we record that a search happened, never the search term or query text itself, and no IP address or user-agent is attached to it. Visitors who are not signed in are never included in this data at all — anonymous traffic is only ever recorded in an aggregate, per-IP-per-hour request count with no account attached to it.
2. Registry Data the Service Aggregates (Not Your Account Data)
Separately from the account data above, the Service's core dataset is built from public internet registry records — RIPE, APNIC, ARIN, LACNIC, and AFRINIC WHOIS/RDAP data, BGP routing tables, RPKI route origin authorizations, and GLEIF legal-entity records. These registry records can include personal data of individuals who register or administer IP address space — most commonly a name associated with an administrative, technical, or abuse contact — because the regional internet registries themselves publish this information as part of the public internet numbering system, independent of anything we do.
The Service is designed around organisation-level attribution — resolving which real-world company or legal entity holds a given range of IP addresses — not an individual people-search tool. Where an underlying registry record's contact information is used, it is used to help establish that organisational attribution (for example, clustering blocks that share a maintainer or contact record), not presented as a standalone personal profile.
If you are an individual whose contact details appear in a registry record reflected in our dataset and want them corrected or removed, contact hello@orgindex.io. Note that the authoritative copy of that record lives at the relevant regional internet registry, not with us — since we re-ingest from these public sources on a recurring schedule, a correction made only in our own data would not persist past the next refresh unless the source record is also corrected.
3. How We Use Account Data
To operate your account and sessions, process subscription billing, enforce usage limits and prevent abuse, and communicate with you about your account.
We keep the access and activity record described in Section 1 so that we can investigate suspicious activity, answer the question “was that really me?” if an account is compromised, and maintain an audit trail of security-relevant changes. Our lawful basis for this is legitimate interest — specifically the security of the service and of your account.
We also use the product usage data described in Section 1 — which features a signed-in account has used, and when it was last active — to understand, in aggregate, whether accounts are actively using the Service, to help decide what to build next, and to detect and prevent abuse of usage limits (for example, a single account making an unreasonable volume of exports). This does mean we can see, within the Service itself, which features your own account has used — that is not something we can honestly deny once we record it, so we are stating it plainly rather than leaving the older, now-inaccurate claim in place. What we do not do with it: we do not use it to track you across other websites, we do not use it to build an advertising profile or serve you ads, and we do not sell it or share it with any third party for their own purposes. Our lawful basis for this use is the same legitimate interest as above, extended to operating and improving the Service you use.
4. Third Parties
- Stripe — payment processing and subscription management. See Stripe's privacy policy.
- Resend — delivers account emails (verification and password-reset links), which necessarily involves sharing your email address and the relevant link with Resend so it can send the message. See Resend's privacy policy.
- Have I Been Pwned — at registration and password change, we check whether your chosen password appears in a known breach. Only the first five characters of a SHA-1 hash of the password are ever sent — never the password itself, and never enough to reconstruct it.
- Cloudflare Turnstile — a bot-detection check shown on the pages where anyone, signed in or not, can submit a form to us: registration, password reset, and the report-an-attribution-issue form (the last of these only when you are not signed in). It is there to keep automated submissions off the Service. Loading it necessarily shares your IP address and browser characteristics with Cloudflare; see Cloudflare's privacy policy.
We do not sell your personal data to third parties.
5. Cookies
The Service sets a single functional session cookie used to keep you signed in. It is not used for advertising or cross-site tracking.
6. Data Retention
Account data is retained while your account is active. You can permanently delete your account and associated data at any time from your account settings, which also cancels any active subscription.
The access and activity record described in section 1 — timestamps, IP addresses and user-agent strings — is deleted automatically 90 days after it is recorded.
The product usage data described in Section 1 (the hourly per-feature counts, and your account's last-active time) is deleted automatically 30 days after it is recorded, with one exception: the last-active timestamp itself is a single value on your account (not a growing log), so it is kept, and simply overwritten going forward, for as long as your account exists — deleting your account deletes it along with the rest of your account data.
One thing worth being explicit about: these security log entries are not erased the instant you delete your account. An entry already written may still contain the email address and IP address you used at the time, and it ages out on the same 90-day cycle rather than being removed immediately. We keep them that briefly so that deleting an account cannot be used to erase the trail of an attack. If you need an entry removed sooner, contact us at hello@orgindex.io and we will handle it individually.
7. Your Rights
Depending on your jurisdiction, you may have rights to access, correct, delete, or receive a copy of your personal data. You can exercise these directly:
- Access / portability: download your data as JSON at any time.
- Deletion: delete your account at any time.
- Correction: update your password from account settings; contact us for other corrections.
For anything not self-serviceable above, or for requests relating to registry data described in Section 2, contact hello@orgindex.io.
8. Security
Passwords are hashed with bcrypt and never stored or logged in plain text. Sessions and API keys are stored as one-way hashes, so a database copy alone cannot be used to impersonate you. We apply rate limiting and account lockout to resist automated attacks.
9. Children's Privacy
The Service is not directed at children and we do not knowingly collect personal data from children under 13 (or the relevant minimum age in your jurisdiction).
10. Changes to This Policy
We may update this Policy from time to time; material changes will be reflected by an updated date above.
11. Contact
Questions about this Policy: hello@orgindex.io.