1. Who is responsible for your information

OSINT Digest is operated by Unkra Inc., a corporation incorporated in Ontario, Canada. Unkra is the organization accountable for your personal information under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), the “controller” under the EU and UK GDPR, and the “business” under the California Consumer Privacy Act.

2. What we collect

Your account

We do not ask for your name, and there is no field for one.

Sign-in information

Authentication is handled by a separate service that we build and run ourselves on the same infrastructure. It holds your email address, the one-time codes we send you (briefly), the public-key credentials for any passkeys you register together with basic details like the device label and when it was added, and records of your active sign-in sessions.

We never create or store a password for you.

Your subscription settings

For each topic you subscribe to, we store:

Technical information

What we store in your browser

We do not use cookies. We store three things in your browser's local storage, all strictly necessary and none of them shared with anyone:

Signing out clears the tokens. Clearing your browser data clears all three.

3. What we don't collect

Stated plainly, because these absences are deliberate:

4. Where the information comes from

5. Information about people who aren't users

This section is about people who never signed up for anything: the authors of the posts we monitor. Their information deserves the same disclosure as yours.

To operate the Service we retrieve public posts from a set of accounts on X chosen by us. We obtain them through twitterapi.io, a third-party provider. For each post we store the author's handle and display name, the text of the post, the text of any quoted post, the link, when it was posted, and whether it contained an image or video.

We use this only to:

We delete the stored post text after 30 days. We never send the text of a post to subscribers — digests carry only our agent's own summary, the author's handle, and a link to the original. Our email system is built so that it never receives post text at all, and an automated test enforces that.

We rely on our legitimate interest in operating a news-monitoring service, applied to material its authors chose to publish publicly. If you are the author of a monitored account and you object, write to privacy@osintdigest.com and we will consider your request and can stop monitoring your account.

6. Why we use it, and our legal basis

Under PIPEDA, your consent to these purposes is given expressly when you create an account and choose your subscriptions, and you may withdraw it at any time as described in section 11.

7. Who else processes it

Exactly one company besides us:

Cloudflare acts as our processor: it handles this information to provide services to us, under contract, and is not permitted to use it for its own purposes. Our sign-in service is our own software running on the same Cloudflare account, so it is covered here rather than listed separately.

twitterapi.io, which supplies the public posts we monitor, is deliberately not in this table: we send it no information about you. We ask it for posts from accounts we watch, and nothing in that request identifies any subscriber.

Beyond this, we disclose personal information only where the law requires it — a valid court order, warrant, or comparable legal process — or where it is necessary to investigate a credible threat to someone's safety. If we were ever acquired or merged, personal information could transfer as part of the business, and we would tell you before it became subject to a different privacy policy.

We do not sell your personal information, and we never have.

8. Where it is stored, and cross-border access

Our database and application run on Cloudflare's infrastructure, with primary storage in the United States. Cloudflare operates a global network, so requests may be served from, and technical logs may be processed at, locations elsewhere in the world.

For transfers of personal information out of the EEA and the UK, we rely on the European Commission's Standard Contractual Clauses, and the UK International Data Transfer Addendum, as incorporated in our data processing agreement with Cloudflare.

9. How long we keep it

When you delete your account we remove your identity record, your account row, and every subscription attached to it. This is a real deletion, not a flag — the rows are gone. Copies may persist briefly in routine infrastructure backups before ageing out, and we may retain the minimum necessary to meet a legal obligation or to keep an unsubscribe request honoured.

10. How we protect it

No system is perfectly secure, and we will not claim otherwise. If you find a vulnerability, please report it to privacy@osintdigest.com.

11. Your rights, and how to use them

You can do most of this yourself, immediately, without asking us or waiting for a reply:

For anything else — a copy of your information, a correction, a restriction, an objection, or a question about any of this — write to privacy@osintdigest.com. We will respond within 30 days, and will tell you if we need longer and why. We may need to confirm you control the email address in question before acting on a request. Exercising any of these rights costs nothing and we will not treat you differently for it.

12. If you are in the EU or the UK

You have the rights to access your personal data, to have it corrected, to have it erased, to restrict or object to how we use it, to receive it in a portable machine-readable form, and to withdraw consent at any time without affecting what we did before you withdrew it. Section 11 explains how to exercise each of these.

Where we rely on legitimate interests, you have the right to object, and we will stop unless we have compelling grounds that override your interests.

Automated decision-making. Our AI agents score news items, not people. Nothing in the Service evaluates, profiles, or makes decisions about you, and there is no automated decision producing legal or similarly significant effects concerning you within the meaning of Article 22.

EU representative. To be straightforward with you: Unkra has not appointed a representative in the EU under Article 27 of the GDPR. You can reach us directly at the address and email in section 1, and we will handle your request the same way.

You have the right to complain to your national data protection authority, or to the UK Information Commissioner's Office at ico.org.uk. We would appreciate the chance to put things right first.

13. If you are in California

In the twelve months before the date of this policy we have collected:

We collect these for the purposes in section 6, from the sources in section 4, and disclose them only to the processor in section 7. We do not collect sensitive personal information as the CCPA defines it.

We have not sold personal information, and we have not shared it for cross-context behavioural advertising. We do not do either of those things, so there is no opt-out to offer you — but if you would like this confirmed in writing, ask us.

You have the right to know what we have collected, to receive a copy, to have it deleted, to have it corrected, and not to be discriminated against for exercising any of those rights. Use the methods in section 11. An authorised agent may make a request on your behalf with written proof of authority.

14. Automated processing and AI

The summaries and importance scores in your digests are written by a large language model running on Cloudflare Workers AI, within Cloudflare's infrastructure.

Which items reach you is decided by arithmetic on the settings you chose: an item is sent if its score meets the threshold you set, at the cadence you set, outside the quiet hours you set. There is no profiling of you and no model of your interests beyond the topics you explicitly subscribed to.

For what the summaries are worth as information — and their limits — see section 7 of the Terms of Service.

15. Children

The Service is not intended for anyone under 16, and you must be at least 16 to hold an account. We do not knowingly collect personal information from children. If you believe a child has given us information, tell us at privacy@osintdigest.com and we will delete the account and its data.

16. If something goes wrong

If a breach of security creates a real risk of significant harm to you, we will notify you and report to the Office of the Privacy Commissioner of Canada as PIPEDA requires, and we will keep records of breaches as required. Where the GDPR applies, we will notify the relevant supervisory authority within 72 hours of becoming aware of a reportable breach, and notify you directly where the risk to you is high.

17. Changes to this policy

If we change this policy we will update the “last updated” date above. If a change materially affects how we handle your information, we will tell you by email before it takes effect, so that you can object or delete your account. We will not apply a materially different use to information already collected without a fresh legal basis for it.

18. Contact us, or complain

For any privacy question or request, or to complain about how we have handled your information, contact our Privacy Officer:

We take complaints seriously and will investigate and respond. If you are not satisfied with our response, you can escalate: