Your data
What the product keeps, how long it keeps it, and how to take it out.
#What is stored
Your account — email, password hash, plan, and the settings you change.
Your lookups — for every lookup you run: the subject you submitted and the provider's full response, attached to your account. From those responses a structured record is derived — subjects, the individual facts observed about each, and the links between them — which is what makes a profile accumulate instead of becoming a pile of transcripts.
Your conversations — assistant threads, lookup sessions, Telegram sessions.
Your Telegram session, if you connect one — encrypted at rest, with a masked phone number and the connection status. Destroyed on disconnect.
Your sign-ins — active sessions with the device and address they were created from, listed and revocable under /account → Security.
#Who can see it
Only the account that collected it. Every read is scoped to your own user id; there is no parameter that widens it. Results are not pooled between customers, not sold, and not published.
#Retention
Your OSINT history is deleted automatically after 90 days by default.
Change it under /account → Security → OSINT history retention: 30 days, 90 days, 365 days, or Always — which keeps results until you delete them or close the account.
When results age out, every fact derived from them goes too. The setting applies to the lookup history and everything traced to it, not to your account itself.
#Export
/account → Usage → Export my data. Four things can be exported:
| What | Contains |
|---|---|
| OSINT history | Every lookup this account has run |
| Profile (one subject) | One subject's findings, links and timeline |
| Telegram channels | Your linked channels and their stored messages |
| AI sessions | Your assistant conversations, in full |
In JSON or CSV (CSV where the data has a tabular form; conversations do not, and will ask for JSON).
An export is a read of what you already hold — nothing is looked up again, so no lookup quota is spent. It draws on the separate Dataset exports meter: 10 a month on Free, unlimited on paid plans, and at most three downloads a minute in all cases.
A very large export can hit a delivery ceiling. When it does, the download still arrives and the file records itself as truncated — you will not get a silently partial file.
#Deleting things
- A conversation — /account → Sessions, individually.
- Your lookup history — set a retention window and it clears itself, or ask support.
- Your Telegram connection — disconnect in the Telegram panel; it is revoked with Telegram and deleted here immediately.
- Your account — write to support@exointel.watch from the account's address.
#Who else sees it
Some things necessarily leave our servers to be done at all:
- The lookup providers. Running a DNS, WHOIS, certificate, threat or routing lookup means asking that provider about your subject.
- The model provider. Assistant questions, and the data they touch, go to Google (Gemini) to be answered.
- Paddle, for payments — they are the merchant of record and they hold the card details, not us.
- Telegram, when you use the Telegram tool with your own account.
The privacy policy lists every processor, what it receives, and the legal basis for each.
#Data about other people
The lookup tools return information about whoever or whatever you look up, and that is often personal data belonging to someone who is not our customer.
The Acceptable Use Policy permits these tools only against systems, domains and individuals you own or have explicit authorisation to investigate. Where you use exo[intel] to process personal data about third parties, you are responsible for having a lawful basis and for meeting your own obligations to those people. We provide the tool and store the results on your behalf.
We do not use that material for advertising, do not enrich it from our own sources, and do not build a cross-customer profile of anyone.
If you are not a customer and believe we hold data about you, write to support@exointel.watch. You have the same access, correction, deletion and objection rights as anyone else. Because these records sit inside individual customers' accounts, we may need enough detail to find them, and we may have to notify the customer concerned in order to act.