Privacy Policy
Last updated: May 21, 2026
In plain English
We collect only the information we need to provide, secure, support, and improve Encrata. We treat your information, and your customers' information, with the same care we apply to our own customer data: we do not sell it, we do not use it for unrelated purposes, and we protect it with appropriate technical and organizational safeguards. If you have questions, contact us.
1. Introduction
Encrata ("we", "our", "us") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our API, website, dashboard, and related services (the "Service").
2. Information We Collect
Account Information
When you create an account, we collect your email address, name, and authentication credentials. If you sign in via Google or GitHub OAuth, we receive your profile information from those providers.
Usage Data
We collect information about your use of the Service, including API calls made, endpoints accessed, timestamps, IP addresses, and credit consumption.
Lookup Data
When you perform lookups, we process the query input (email addresses, domains, IPs) to return results. We cache results temporarily to improve performance but do not permanently store lookup results.
3. How We Use Your Information
- To provide, maintain, and improve the Service
- To process your API requests and deliver lookup results
- To manage your account and billing
- To communicate with you about updates, security alerts, and support
- To monitor usage patterns and prevent abuse
- To comply with legal obligations
4. Data Sources
Lookup results are aggregated from publicly available information, including public social media profiles, WHOIS records, DNS data, published breach databases, and search engine results. We do not access private or protected data.
5. Data Retention
Account data is retained for as long as your account is active. Lookup results are cached with a time-to-live (TTL) and automatically purged. API usage logs are retained for 90 days for analytics and abuse prevention.
6. Data Sharing
We do not sell your personal information. We may share data with:
- Infrastructure providers (hosting, CDN) to operate the Service
- Payment processors to handle billing
- Law enforcement when required by law
7. Security
We implement industry-standard security measures including encryption in transit (TLS), encrypted storage, secure API key management, and regular security audits. However, no method of transmission over the internet is 100% secure.
8. Your Rights (GDPR)
If you are in the EU/EEA, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict processing
- Data portability
- Withdraw consent at any time
To exercise these rights, contact us at support@encrata.com.
9. Cookies
We use essential cookies for authentication (session tokens) and security (CSRF/OAuth state). We do not use tracking cookies or third-party advertising cookies.
10. Children's Privacy
The Service is not directed to individuals under 18. We do not knowingly collect personal information from children. If we learn we have collected data from a child, we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service. Your continued use after changes constitutes acceptance.
12. Contact Us
For privacy-related questions or requests, contact us at support@encrata.com or visit our Contact page.