Privacy Policy

Last updated: February 21, 2026

userdata ("we," "us," or "our") is built on the principle that your data belongs to you. This Privacy Policy explains what information we collect, why we collect it, and how we protect it.

1. Information We Collect

Information you provide

  • Account information — email address and password when you create an account.
  • Imported data — files you upload from providers like Google, Meta, Microsoft, Amazon, and TikTok. These are processed to extract profile and activity summaries, then the raw files are deleted from our servers.
  • Inquiry messages — if you contact us through our contact form.

Information collected automatically

  • Session data — we use a session cookie to keep you signed in. Sessions expire after 15 minutes of inactivity or 1 hour, whichever comes first.
  • Breach monitoring data — when you run a privacy scan, we check your email address against the Have I Been Pwned database to identify past data breaches.

2. How We Use Your Information

  • To provide and maintain your account and dashboard.
  • To process and display your imported data inventory.
  • To monitor for data breaches associated with your email.
  • To respond to your inquiries and support requests.
  • To send account-related notifications (e.g., password reset codes).

We do not sell your personal information. We do not use your data for advertising. We do not share your data with third parties except as described below.

3. Data Storage and Security

Your data is stored using Amazon Web Services (AWS) infrastructure in the United States. We use industry-standard security measures including:

  • Encrypted data at rest in DynamoDB and S3.
  • HTTPS for all data in transit.
  • Authentication via AWS Cognito with secure password hashing.
  • Session tokens signed with a secret key and short expiration windows.

4. Third-Party Services

We use the following third-party services:

  • Amazon Web Services — hosting, database, storage, email delivery, and authentication.
  • Have I Been Pwned — breach monitoring (only your email address is sent to their API).

We do not use analytics trackers, advertising pixels, or social media tracking scripts.

5. Data Retention and Deletion

You can delete your imported data at any time from your dashboard — either per provider or all at once. Raw uploaded files are automatically deleted from our servers after processing. When you request data deletion, the records are permanently removed from our database.

To delete your account entirely, contact us at support@userdata.io.

6. Your Rights

You have the right to:

  • Access your data — export everything from your dashboard at any time.
  • Delete your data — remove individual provider data or all records.
  • Portability — export your data as JSON for use elsewhere.
  • Correction — re-import data to update your records.

7. Children's Privacy

userdata is not intended for use by anyone under the age of 16. We do not knowingly collect personal information from children.

8. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page with a revised "Last updated" date.

9. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at support@userdata.io.