Privacy & Data Protection

Privacy Policy

Learn how we collect, use, and protect your personal data.

SEARCHHUB OÜ

Registry: 16896671 | VAT: EE102698323

Effective Date

September 27, 2025

Address

Tartu mnt 25-46, Tallinn, 10117, Estonia

Contact

+372 5638 5997

1. Introduction

This Privacy Policy explains how SEARCHHUB OÜ ("SearchHub", "we", "us", "our") collects, uses, discloses, and protects Personal Data when you access or use the SearchHub services (the "Service").

We operate searchhub.vip and related mirror domains. Our policy is written to satisfy applicable data protection laws, including the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), and to be transparent about our practices.

2. Scope and Purpose

This Policy applies to all Personal Data processed by SearchHub in connection with the Service, whether collected through the website, APIs, forms, or via user submissions and public dataset indexing.

Purpose: We index and provide searchable access to publicly available information for legitimate OSINT, research, historical archiving, and analytics purposes. We also provide user accounts and optional paid services.

3. Data We Collect

Minimal Account Data

Only collected when you register

  • Username (provided by you)
  • Password hash (we store a salted, strong hash; we do not store plaintext passwords)
  • We do NOT require or collect email addresses at signup unless you voluntarily provide one

Authentication & Logs

  • Connection logs (timestamps, IP addresses, user-agent string, login attempts)
  • Session identifiers necessary to operate the Service

Activity Data

  • All searches you perform within the Service (queries, timestamps, filters)
  • Actions performed within your account (bookmarks, saved items, API key usage)

Publicly Indexed Content

We index publicly available data from external sources

  • Public Discord channels
  • Public forum posts
  • Public logs (FiveM and similar)
  • Publicly posted files
What we do NOT collect: Private Discord messages behind authentication, private account emails, any data requiring unauthorized access to third-party systems, or payment details (processed by third-party providers).

5. How We Use Your Data

  • Providing, maintaining, and improving the Service
  • Account creation, authentication, and security monitoring
  • Indexing and search functionality, ranking algorithms, and deriving analytics
  • Fraud prevention, abuse detection, and enforcement of our Terms of Service
  • Responding to legal requests and court orders where properly compelled
  • Communicating with users when you have provided contact details (password resets, notifications)

6. Data Retention and Deletion

Retention Principles: We retain Personal Data only as long as necessary for the purposes described, or as required by law.

Account data (username, password hash)While account exists + 5 years after termination
Authentication logs and connection logsUp to 2 years
Search history and activity logsUp to 3 years (unless deleted earlier)
Publicly indexed contentIndefinitely (unless removed via deletion process)

Deletion Requests: To request deletion, contact [email protected] with identification details. We will verify your request and respond within statutory timeframes (GDPR: one month; may be extended by two months for complex requests).

7. Fee-Based Data Wipe vs Legal Rights

SearchHub offers an optional Fee-Based Data Wipe service for expedited, administrative removal of indexed references under SearchHub's control.

Important clarifications:
  • The Fee-Based Data Wipe does not guarantee removal from third-party sites, archives, or caches beyond our control (e.g., Internet Archive)
  • Under GDPR and similar laws, data subjects retain the right to request deletion (the 'right to be forgotten') free of charge when legal conditions are met
  • We will process free deletion requests where applicable and required by law
  • The Fee-Based Data Wipe is an optional paid service for expedited handling or for cases not covered by statutory deletion rights

8. Account Registration and No-Email Policy

Registration: You may create an account without providing an email address. We collect only the username and store a salted hash of your password.

Account recovery: Without an email, account recovery options are limited. If you did not provide an email, account recovery may require identity verification and support assistance.

Minimal data principle: We deliberately avoid requiring unnecessary personal identifiers at signup. If you voluntarily provide an email, we will process it only for purposes you consent to (notifications, recovery).

9. Security Measures

We implement organizational and technical measures to protect Personal Data, including:

Password Hashing

Strong, modern algorithms with salting

TLS Encryption

All data transfers encrypted in transit

Access Controls

Role-based permissions for staff and processors

Security Monitoring

Regular testing, logging, and intrusion detection

Despite these measures, no system is completely secure. We cannot guarantee absolute security; in the event of a breach we will follow the notification procedures described in Section 16.

10. Third-Party Processors and Transfers

We may use third-party processors to provide hosting, analytics, payments, and other services. Processors are contractually bound to act only on our instructions and to implement appropriate safeguards.

Cross-border transfers: Data may be transferred outside the EEA. Where transfers occur to jurisdictions without an adequacy decision, we use appropriate safeguards (e.g., Standard Contractual Clauses) or obtain consent where required.

Processor categories: Cloud hosting providers, CDN providers, payment processors, email/notification providers, analytics platforms.

11. Data Subject Rights (GDPR & CCPA)

EU (GDPR) Rights

Access, rectification, erasure, restriction of processing, objection, data portability, and the right to withdraw consent. Contact [email protected] to exercise these rights.

California (CCPA) Rights

Consumers have rights to know categories of personal information collected, request disclosure, deletion, and opt-out of sale. We do not sell personal information as defined under CCPA.

Verification and timing: We will respond to verifiable requests within legal timeframes (typically 30 days under GDPR, 45 days under CCPA).

12. Children's Data

The Service is not directed at children under 16. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child in violation of law, we will delete that data promptly and take remedial steps.

13. Cookies and Tracking

We use cookies and similar technologies for essential site functions, analytics, security, and preferences.

Essential Cookies

Session cookies required for the site to function

Performance/Analytics

Help us understand how visitors use our site

Functional Cookies

Remember your preferences and settings

You can control cookie preferences via your browser settings and via any in-site cookie controls we provide.

14. Automated Decision-Making and Profiling

We may use automated systems to provide features such as search ranking, anomaly detection, and abuse detection. These processes do not generally produce legally binding automated decisions about individuals.

Where automated profiling significantly affects individuals, we will provide meaningful information about the logic involved and provide mechanisms to request human review where required by law.

16. Data Breach Notification

In the event of a personal data breach we will:

  • Notify the relevant data protection authority where required by law, without undue delay and, where feasible, within 72 hours of becoming aware of the breach
  • Notify affected individuals if the breach is likely to result in a high risk to their rights and freedoms
  • Take steps to contain and remediate the breach and review security practices

17. Data Protection Impact Assessment (DPIA)

Where processing is likely to result in high risk to individuals' rights (e.g., large-scale processing of sensitive personal data), we will conduct a DPIA to evaluate risks and implement mitigating measures.

We will document DPIA outcomes and make them available to supervisory authorities upon request.

18. Contact Information and DPO

Controller Information

Company: SEARCHHUB OÜ (Registry code: 16896671)

Address: Tartu mnt 25-46, Kesklinna linnaosa, Harju maakond, Tallinn, 10117, Estonia

Privacy Contact

[email protected]

For data protection requests

Legal Contact

[email protected]

For law enforcement requests

If you are an EU resident, you may also lodge a complaint with your local supervisory authority.

19. Changes to this Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will post the updated policy with a new effective date on the Service and, where appropriate, provide notice to registered users.

Continued use after changes constitutes acceptance of the updated policy.

20. Appendix: Sample Data Deletion Request

To help you make verifiable deletion requests, provide the following information when contacting [email protected]:

Required Information

  • Full username or identifier used on SearchHub
  • Description of the data to be deleted (links, search entries, references)
  • Proof of identity (government-issued ID or equivalent) when required
  • Preferred contact method and any timeframe considerations

We will acknowledge receipt and provide an estimated timeline for processing. For standard GDPR erasure requests we will act free of charge when conditions are met.

Executed on behalf of SEARCHHUB OÜ — Authorized Signatory: Legal & Privacy Team, SEARCHHUB OÜ — Date: September 27, 2025

© SEARCHHUB OÜ — This Privacy Policy was last updated on September 27, 2025.