OSINT Digest needs remarkably little about you: an email address to send digests to, and the settings that say what to send and when. This policy explains exactly what we hold, where it lives, and how to get rid of it.
The short version. We collect your email address and your subscription settings. We use no cookies, no analytics, no tracking pixels, and no advertising. We never sell or share your information. Cloudflare is the only outside company that processes it. Your personal information is never sent to the AI model that writes the summaries, and none of your data is used to train any model. You can delete everything yourself, at any time, from your account settings.
1. Who is responsible for your information
OSINT Digest is operated by Unkra Inc., a corporation incorporated in Ontario, Canada. Unkra is the organization accountable for your personal information under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), the “controller” under the EU and UK GDPR, and the “business” under the California Consumer Privacy Act.
Unkra Inc. — Privacy Officer
400 Walmer Rd. #1809
Toronto, Ontario M5P 2X7
Canada
2. What we collect
Your account
- Email address — so we can sign you in and send you digests.
- An internal account identifier — a random ID that links your settings to you.
- Timestamps for when your account was created and last updated.
- An administrator flag, which is off for everyone except our own staff accounts.
We do not ask for your name, and there is no field for one.
Sign-in information
Authentication is handled by a separate service that we build and run ourselves on the same infrastructure. It holds your email address, the one-time codes we send you (briefly), the public-key credentials for any passkeys you register together with basic details like the device label and when it was added, and records of your active sign-in sessions.
We never create or store a password for you.
Your subscription settings
For each topic you subscribe to, we store:
- which topic it is, and whether the subscription is active;
- your importance threshold (1–10);
- your cadence in minutes;
- your quiet hours, if you set any;
- your time zone. We need this to apply quiet hours correctly. It is worth being explicit that a time zone is a rough indication of where in the world you are, so we are treating it as information about you rather than as a mere setting;
- a random unsubscribe token that makes the one-click unsubscribe links in your emails work;
- internal scheduling bookkeeping — when your next digest is due, and how far through the item history we have already sent.
Technical information
- Your IP address. It reaches our servers with every request, as it must for the internet to work. We pass it to our own sign-in service so that it can rate-limit abuse. We do not use it to profile you or to infer your location for any product feature.
- Request logs and performance metrics, retained by our hosting provider and used for debugging and reliability. These can include IP address, the URL requested, timing, and error details.
What we store in your browser
We do not use cookies. We store three things in your browser's local storage, all strictly necessary and none of them shared with anyone:
| What | Why |
|---|---|
| Access token | Keeps you signed in between page loads |
| Refresh token | Renews your session without making you sign in again |
| Theme preference | Remembers whether you chose light or dark |
Signing out clears the tokens. Clearing your browser data clears all three.
3. What we don't collect
Stated plainly, because these absences are deliberate:
- No cookies.
- No analytics of any kind — no Google Analytics, no Plausible, no page-view counting, no session recording, no heatmaps.
- No tracking pixels, in the website or in our emails. We do not know whether you opened a digest or clicked anything in it.
- No advertising, no ad networks, no marketing or attribution trackers.
- No third-party fonts or scripts. Everything the site needs is served from our own domain, so loading a page tells no one else that you visited.
- No payment information — the service is free and we have no payment system.
- No name, phone number, address, contacts, or location beyond the time zone described above.
- No sale or sharing of personal information, ever, in any sense of those words.
4. Where the information comes from
- From you — your email address when you sign up, and your settings when you choose them.
- From our sign-in service — your verified email address and account identifier, when you sign in.
- Automatically from your browser and network — your IP address and the technical details of each request.
5. Information about people who aren't users
This section is about people who never signed up for anything: the authors of the posts we monitor. Their information deserves the same disclosure as yours.
To operate the Service we retrieve public posts from a set of accounts on X chosen by us. We obtain them through twitterapi.io, a third-party provider. For each post we store the author's handle and display name, the text of the post, the text of any quoted post, the link, when it was posted, and whether it contained an image or video.
We use this only to:
- give the scoring agent the context it needs to rate a development and write a summary; and
- populate an internal review feed used by our own staff to check the system is working.
We delete the stored post text after 30 days. We never send the text of a post to subscribers — digests carry only our agent's own summary, the author's handle, and a link to the original. Our email system is built so that it never receives post text at all, and an automated test enforces that.
We rely on our legitimate interest in operating a news-monitoring service, applied to material its authors chose to publish publicly. If you are the author of a monitored account and you object, write to privacy@osintdigest.com and we will consider your request and can stop monitoring your account.
6. Why we use it, and our legal basis
| Purpose | Information used | Legal basis (GDPR) |
|---|---|---|
| Send you the digests and alerts you asked for | Email address, subscription settings, time zone | Performance of our contract with you |
| Sign you in and keep your session | Email, account ID, one-time codes, passkeys, sessions | Performance of our contract with you |
| Honour your unsubscribe requests | Unsubscribe token, subscription record | Legal obligation; and our legitimate interest in not emailing people who asked us to stop |
| Keep the service secure and prevent abuse | IP address, account ID, request logs | Our legitimate interest in protecting the service |
| Diagnose faults and keep the service running | Request logs and metrics | Our legitimate interest in operating a working service |
| Monitor public posts and score them | Third-party post content (not your information) | Our legitimate interest in operating a news-monitoring service |
| Comply with the law | Whatever a valid legal requirement covers | Legal obligation |
Under PIPEDA, your consent to these purposes is given expressly when you create an account and choose your subscriptions, and you may withdraw it at any time as described in section 11.
7. Who else processes it
Exactly one company besides us:
| Provider | What it does for us | What it can access |
|---|---|---|
| Cloudflare, Inc. United States |
Hosting and running the application; the database; the email-sending queue; the AI model that writes summaries; sending our email; DNS and content delivery; request logging | Everything we store, since it is stored on Cloudflare's infrastructure — your email address, settings, and technical logs |
Cloudflare acts as our processor: it handles this information to provide services to us, under contract, and is not permitted to use it for its own purposes. Our sign-in service is our own software running on the same Cloudflare account, so it is covered here rather than listed separately.
twitterapi.io, which supplies the public posts we monitor, is deliberately not in this table: we send it no information about you. We ask it for posts from accounts we watch, and nothing in that request identifies any subscriber.
Beyond this, we disclose personal information only where the law requires it — a valid court order, warrant, or comparable legal process — or where it is necessary to investigate a credible threat to someone's safety. If we were ever acquired or merged, personal information could transfer as part of the business, and we would tell you before it became subject to a different privacy policy.
We do not sell your personal information, and we never have.
8. Where it is stored, and cross-border access
Our database and application run on Cloudflare's infrastructure, with primary storage in the United States. Cloudflare operates a global network, so requests may be served from, and technical logs may be processed at, locations elsewhere in the world.
We are required to tell you this clearly: because your personal information is stored and processed outside Canada, and because Cloudflare is a company based in the United States, your information may be accessible to foreign courts, law-enforcement agencies, and government authorities under the laws of those countries — including laws that differ from Canadian law and that may not give you the same protections.
For transfers of personal information out of the EEA and the UK, we rely on the European Commission's Standard Contractual Clauses, and the UK International Data Transfer Addendum, as incorporated in our data processing agreement with Cloudflare.
9. How long we keep it
| Information | Kept for |
|---|---|
| Your account and subscription settings | Until you delete your account — then removed immediately |
| Sign-in sessions | About 12 hours; the refresh credential up to 30 days, or until you sign out |
| One-time sign-in codes | Minutes — they expire shortly after being sent |
| Passkey credentials | Until you remove the passkey or delete your account |
| Third-party post text (not your information) | 30 days, then automatically purged |
| Request logs and metrics | Per our hosting provider's retention period, typically days to a few weeks |
When you delete your account we remove your identity record, your account row, and every subscription attached to it. This is a real deletion, not a flag — the rows are gone. Copies may persist briefly in routine infrastructure backups before ageing out, and we may retain the minimum necessary to meet a legal obligation or to keep an unsubscribe request honoured.
10. How we protect it
- All traffic is encrypted in transit with TLS.
- There are no passwords to steal — we sign you in with one-time codes or passkeys.
- Passkeys use WebAuthn, so the secret never leaves your device and we only ever hold a public key.
- Every request to our API is verified against a cryptographic signature before it is served.
- Requests are rate-limited per account to limit the damage any single account can do.
- Credentials for our own services are held server-side and are never exposed to your browser.
- Administrative access is restricted to specific accounts and is off by default.
- We minimise what we collect in the first place, which is the most reliable protection available.
No system is perfectly secure, and we will not claim otherwise. If you find a vulnerability, please report it to privacy@osintdigest.com.
11. Your rights, and how to use them
You can do most of this yourself, immediately, without asking us or waiting for a reply:
| What you want | How |
|---|---|
| Stop emails about one topic | The unsubscribe link for that topic at the foot of any digest, or your subscription settings |
| Stop all emails | Turn off every subscription in your settings, or use one-click unsubscribe in your email client |
| Change your settings or time zone | Your subscription settings |
| Change your email address | Account settings |
| Remove a passkey or sign out other devices | Account settings |
| Delete everything | Account settings → delete account. Immediate and permanent. |
For anything else — a copy of your information, a correction, a restriction, an objection, or a question about any of this — write to privacy@osintdigest.com. We will respond within 30 days, and will tell you if we need longer and why. We may need to confirm you control the email address in question before acting on a request. Exercising any of these rights costs nothing and we will not treat you differently for it.
12. If you are in the EU or the UK
You have the rights to access your personal data, to have it corrected, to have it erased, to restrict or object to how we use it, to receive it in a portable machine-readable form, and to withdraw consent at any time without affecting what we did before you withdrew it. Section 11 explains how to exercise each of these.
Where we rely on legitimate interests, you have the right to object, and we will stop unless we have compelling grounds that override your interests.
Automated decision-making. Our AI agents score news items, not people. Nothing in the Service evaluates, profiles, or makes decisions about you, and there is no automated decision producing legal or similarly significant effects concerning you within the meaning of Article 22.
EU representative. To be straightforward with you: Unkra has not appointed a representative in the EU under Article 27 of the GDPR. You can reach us directly at the address and email in section 1, and we will handle your request the same way.
You have the right to complain to your national data protection authority, or to the UK Information Commissioner's Office at ico.org.uk. We would appreciate the chance to put things right first.
13. If you are in California
In the twelve months before the date of this policy we have collected:
- Identifiers — your email address, an internal account identifier, and your IP address.
- Internet or network activity — request logs relating to your use of the site.
We collect these for the purposes in section 6, from the sources in section 4, and disclose them only to the processor in section 7. We do not collect sensitive personal information as the CCPA defines it.
We have not sold personal information, and we have not shared it for cross-context behavioural advertising. We do not do either of those things, so there is no opt-out to offer you — but if you would like this confirmed in writing, ask us.
You have the right to know what we have collected, to receive a copy, to have it deleted, to have it corrected, and not to be discriminated against for exercising any of those rights. Use the methods in section 11. An authorised agent may make a request on your behalf with written proof of authority.
14. Automated processing and AI
The summaries and importance scores in your digests are written by a large language model running on Cloudflare Workers AI, within Cloudflare's infrastructure.
Your personal information is never sent to the model. What the model receives is the text of public posts and the standing instructions for that topic. Your email address, your identity, your settings, and your reading habits are not in the prompt — the system has no way to make them part of it. Nothing about you is used to train, fine-tune, or improve any AI model, by us or by anyone else.
Which items reach you is decided by arithmetic on the settings you chose: an item is sent if its score meets the threshold you set, at the cadence you set, outside the quiet hours you set. There is no profiling of you and no model of your interests beyond the topics you explicitly subscribed to.
For what the summaries are worth as information — and their limits — see section 7 of the Terms of Service.
15. Children
The Service is not intended for anyone under 16, and you must be at least 16 to hold an account. We do not knowingly collect personal information from children. If you believe a child has given us information, tell us at privacy@osintdigest.com and we will delete the account and its data.
16. If something goes wrong
If a breach of security creates a real risk of significant harm to you, we will notify you and report to the Office of the Privacy Commissioner of Canada as PIPEDA requires, and we will keep records of breaches as required. Where the GDPR applies, we will notify the relevant supervisory authority within 72 hours of becoming aware of a reportable breach, and notify you directly where the risk to you is high.
17. Changes to this policy
If we change this policy we will update the “last updated” date above. If a change materially affects how we handle your information, we will tell you by email before it takes effect, so that you can object or delete your account. We will not apply a materially different use to information already collected without a fresh legal basis for it.
18. Contact us, or complain
For any privacy question or request, or to complain about how we have handled your information, contact our Privacy Officer:
Privacy Officer, Unkra Inc.
400 Walmer Rd. #1809, Toronto, Ontario M5P 2X7, Canada
We take complaints seriously and will investigate and respond. If you are not satisfied with our response, you can escalate:
- Canada — the Office of the Privacy Commissioner of Canada, 30 Victoria Street, Gatineau, Quebec K1A 1H3, priv.gc.ca
- United Kingdom — the Information Commissioner's Office, ico.org.uk
- European Union — the data protection authority for the country you live in
OSINT Digest · Terms of Service
© 2026 Unkra Inc.