Privacy Policy
What Orelys collects, why, who it is shared with, and what you can ask us to do about it.
On this page
1Who is responsible
Orelys is responsible for the personal data described here. For any question about it, write to support@orelys.io.
2On the website
- 2.1
Only essential cookies, set when you sign up, log in or pass a security check. orelys_session keeps you signed in: it stops working after 30 days at most if you tick “Keep me signed in” — counted from when you log in, never extended — otherwise after 24 hours or when you close your browser. It also stops working after 7 days without use, as soon as it is used from a different browser or operating system than the one you logged in with, when you log out, and on your other browsers when you change your password or ask to change your email address (the one you make the change in stays signed in). For this, your session keeps the name of your browser and operating system (such as “Chrome on Windows”, never the full browser details) and when it was last used. orelys_human lasts 15 minutes: it is set when you pass the security check before a dashboard search, holds only your account ID, an identifier of your current session and an expiry, and is removed when you log out. orelys_device lasts one year: it is set when you log in, and lets that browser log in to your account while logins to your email address are locked for everyone else after many failed attempts. It holds a one-way fingerprint of your account ID, a keyed one-way tag of your email address and a signature — never the ID or the address themselves. It stays when you log out, and is removed when you delete your account from that browser. No analytics, no advertising trackers.
- 2.2
Your IP address is used to limit how often sign-ups, logins, requests for a new confirmation link, email confirmations, email changes, checkouts and security checks can be made from it, each counted over one minute to one hour, and API calls, counted over one minute. Login attempts are also counted against the email address typed, alone over one hour and together with the IP address over 15 minutes; password checks, email changes, link codes, API key regenerations and security checks before dashboard searches against your account. An IPv6 address is counted together with the other addresses of its /64 network. These counters are kept only in server memory, never on disk, and they are gone when the server restarts.
- 2.3
Sign-up, login, requests for a new confirmation link and dashboard searches are protected against bots by ALTCHA, a proof-of-work check we host ourselves: your browser solves a small computation and our server checks the answer. No third party is involved, the check sets no cookie of its own, and nothing about it is sent anywhere else. In the dashboard, one check covers your searches and raw file downloads for 15 minutes.
3Your account
- 3.1
Your username, your email address and your password.
- 3.2
Passwords are stored as a one-way hash, never in readable form.
- 3.3
When you last logged in. No IP address is kept with it.
- 3.4
When you sign up: whether your email address has been confirmed and when; a one-way hash of the confirmation link sent to you, with when it expires — never the link itself; and the times of the confirmation emails sent to your address in the last 24 hours, which limit how many can be sent. When you ask to change your email address: the new address and a one-way hash of the link sent to it, with when it expires, until that link is used — then only its hash and the date. When you ask to reset your password: a one-way hash of the reset link, with when it expires or when it was used, and the times of the reset emails sent in the last 24 hours, which limit how many can be sent.
- 3.5
Your API key, stored encrypted so it can be shown to you again, with a one-way hash of it and the date it was created or last regenerated. It is created the first time you open the API page of your dashboard.
- 3.6
While you are logged in, a session cookie that holds a random token linked to your account — not your name, email or password.
- 3.7
When your account was created.
4Searches and quota
- 4.1
Your plan, its start and end dates, the orders that granted it, and a log of your last 20 plan changes.
- 4.2
How many requests you made today and in total, and when you last made one.
- 4.3
We do not keep the content of your searches. A search is sent to our search API provider, which queries Intelligence X, and the results are shown to you on the website, or returned to your program when you use the API. A username or email search is sent instead to the sites it checks, through the Tor network.
5Emails we send
- 5.1
Orelys sends automatic emails to the address of your account: the link to confirm your address when you sign up, and again if you ask for a new one. When you ask to change your email address, the link to confirm it goes to the new address, and a notice without the link or the new address goes to the current one. When you ask to reset your password, a reset link goes to the address of your account, and once the new password is set, a notice without a link. When you send a data removal request, a receipt, then its outcome. The site does not keep a copy of these emails.
- 5.2
Our team may also answer your emails, or write to the email address of your account about your account. Emails exchanged with our team stay in our support mailbox until we delete them.
- 5.3
Emails are sent through Resend, which receives your email address and the message, including any confirmation or reset link.
6The contact form
The contact form is not connected: nothing typed in it is sent or stored. Write to support@orelys.io instead.
7Data removal requests
- 7.1
When you send a request from the data removal page, we keep: its reference, what you asked to remove (an email address, phone number, username or domain, and any Intelligence X system IDs), where you saw it, your note, the profile link you gave, how it was checked and when, its status, and your account's ID and email address, to answer you.
- 7.2
A screenshot you add as proof (required for a phone number, optional for a username) is redrawn in your browser before it is sent, which removes its metadata such as location. Only our team sees it. It is deleted when the request is closed, and at the latest 30 days after it was sent.
- 7.3
Each request is also sent to our support mailbox as a ticket, with its screenshot. You get emails about it at the address of your account, naming the request by its reference only.
- 7.4
For a domain, we read its public DNS records through Cloudflare's DNS service, over the Tor network.
8Payments
- 8.1
The plan, billing period, amount, payment method, the coin for crypto payments, the payment status and dates, and the payment reference returned by the provider.
- 8.2
Your email address is not saved on the order, and Orelys does not pass it to the payment provider.
- 8.3
Orders are linked to your account, so that a confirmed payment activates the plan on it.
- 8.4
Payments are made by card, through Paylio and the licensed card provider you pick on its page, or in cryptocurrency, through Plisio. Orelys never receives card details.
9Why we use it
- 9.1
Account, plan, order and request data: to provide the service you signed up for and to take payments.
- 9.2
Rate limits, security checks, the session and trusted-device cookies and the server logs: to keep accounts and the service secure.
- 9.3
Your email address: to let you log in with it, to confirm it is yours when you sign up or change it, and to write to you about your account.
- 9.4
Emails you send us: to answer you.
11How long we keep it
- 11.1
Your account — username, email address, password hash, creation and last login dates — is kept until the account is deleted. You can delete it yourself from the Account page of your dashboard.
- 11.2
When an account is deleted, its username, email address, password hash, last login date, API key, plan, request counters and plan changes are erased straight away, and every device is signed out.
- 11.3
Kept after deletion: the orders (plan, amount, dates, payment reference), for accounting, without your username or email address; the emails exchanged with our team, until they are deleted from our mailbox; and internal records that refer to the account by its ID only — its sign-up and deletion dates, and the actions our team took on it.
- 11.4
Data removal requests are kept as the record of each block, also after the account is deleted — then without its email address. Their screenshots are deleted when the request is closed, at the latest 30 days after they were sent. Emails about them stay in our support mailbox until we delete them.
- 11.5
Your API key is kept until you regenerate it, change your password or delete your account, or until it is sent in a web address, where it is refused and revoked: the old key is then erased.
- 11.6
An account whose email address is not confirmed within 48 hours of sign-up, and that nothing has been attached to yet (no sign-in, plan, credits or API key), is deleted with everything it holds. Until then, signing up again with the same address replaces it. A confirmation link works for up to 24 hours — never beyond those 48 — and stops working once it is used or when a new one is sent. Once your address is confirmed, the account keeps the date and the one-way hash of the link that was used, until the account is deleted.
- 11.7
Your plan, its dates, your request counters and your last 20 plan changes are kept for as long as the account exists. The daily counter starts again every day at 02:00 Paris time.
- 11.8
Orders are kept as the record of each payment: the site never deletes them, even when the account is deleted.
- 11.9
A link to confirm a new email address works for 24 hours, and stops working when it is used, when a new change is asked for, or when your password is changed. Until the link is used, the account keeps its current address.
- 11.10
The login cookie stops working after 30 days at most with “Keep me signed in” (without it, after 24 hours or when you close your browser), after 7 days without use, when it is used from another browser, or when you log out; the security check cookie after 15 minutes; the trusted-device cookie after one year, or when you delete your account from that browser.
- 11.11
Rate-limit counters, including IP addresses, stay only in server memory and are gone when the server restarts. The one exception is the times of the confirmation emails sent to an address (see above): they are stored with the account and only the last 24 hours count.
- 11.12
The content of your searches is not stored.
- 11.13
Server logs. The reverse proxy on our server records each request to the site and the API: the date, the address of the page or route requested, including anything after “?” in it (such as the token of a confirmation link), the browser's user agent and the page the request came from. It does not record your IP address, only Cloudflare's. These records are kept about five weeks. The Orelys services also log their own events, such as a sign-up or a request answered, naming accounts by an internal ID — never a password, a key, your email address or what you searched — in the server's system log, until its size limit pushes them out.
- 11.14
The status page keeps 90 days of service checks, which contain no personal data.
12Your rights
- 12.1
From your account page you can change your email address and password, regenerate your API key and delete your account.
- 12.2
To get a copy of your data, have it corrected or deleted — including the emails you sent us — or object to how it is used, write to support@orelys.io.
- 12.3
If you are in the European Union, the EEA or the United Kingdom, these rights come from the GDPR, and you can also complain to your data protection authority.
13Changes
We will update this page if what we collect changes. The date at the top shows the latest version.
