S/U

Splashbot

Utilities
← Return Home

Privacy Policy

EFFECTIVE DATE: August 2026 LEGISLATION: UK GDPR / DPA 2018

Operator & Data Controller

This Privacy Policy governs the operation of Splashbot Utilities ("the Service"), a suite of automated and manual OSINT (Open Source Intelligence) auditing tools provided as a service. For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018), the data operator can be contacted directly via:

  • Email: developer@splashbot.online (Preferred channel for GDPR and formal legal communications)
  • Platform: Direct message / support ticket via the official Splashbot Utilities Discord Server

Operational Architecture & Execution Model

Splashbot Utilities operates on a Human-in-the-Loop (HitL) execution framework. No automated public searches or continuous tracking passes are conducted without manual verification and human execution.

The standard processing lifecycle for an OSINT Audit is strictly defined as follows:

  1. Ticket Initialization: The requesting user creates a private support channel ("Ticket") inside the official Discord Server.
  2. Account Authentication: The user provides verification of their identity by adding an ephemeral, unique token string provided by the Splashbot Discord Bot to their designated X (formerly Twitter) profile bio for the duration of the search.
  3. Target Parameterization: The operator manually triggers open-source intelligence searches using explicit parameters voluntarily provided by the user. If no additional identifiers are specified, the search is constrained strictly to the user's provided Discord and/or verified X username.
  4. Manual Data Analysis & Pruning: All retrieved raw data is manually inspected by the operator to eliminate false positives, redact irrelevant third-party records, and compile the valid findings into a compiled PDF audit report.
  5. Delivery & Ephemeral Lifecycle: The completed PDF report is uploaded directly into the user's private Discord Ticket Channel. The output report and raw execution files reside exclusively on the host VPS while the ticket channel remains active.

Data Retention & Purge Protocol

Splashbot Utilities is engineered with an ephemeral-first, zero-retention architecture:

  • Standard Purge: Upon completion of the audit and receipt of the PDF report, the user activates the Close & Purge function inside the Discord channel.
  • FileSystem Deletion: Activating the purge immediately issues system commands (e.g., rm) to permanently scrub all raw tool outputs (including outputs generated by external scripts such as Maigret or Holehe) and PDF reports from the dedicated VPS file system.
  • Channel Liquidation: The Discord ticket channel and its chat history are permanently deleted. No logs, databases, or secondary copies are retained by the operator under normal operating conditions.
Exception: Serious Issues & Legal Compliance

In the event that a "Serious Issue" arises during service delivery—defined specifically as any circumstance requiring the direct involvement of, or formal notification from, a Law Enforcement Agency (LEA)—the operator reserves the right to preserve relevant raw data and session metadata within a secure, isolated storage environment. Under applicable statutory provisions, the operator reserves the right to withhold notification to the user and suspend report delivery while required to do so by an active law enforcement order or legal obligation.

Web Storage & Client Cookies

The Splashbot Utilities web interface does not track visitors, host third-party advertising cookies, or deploy session monitoring telemetry. Browser storage is restricted strictly to necessary functional consent flags:

  • localStorage (Privacy Policy Consent): Stores a single boolean flag confirming that the user has reviewed and accepted this Privacy Policy.
  • localStorage (Terms of Service Consent): Stores a single boolean flag confirming acceptance of the Service Terms.

While browsing the informational website does not require accepting these items, accessing off-platform functionality—including generating official invites to the Discord server—requires explicit consent to both policies stored locally in your browser.

Server Infrastructure

All core script execution, manual verification processing, and temporary file rendering take place within a hardened, dedicated virtual private server (VPS) configured as follows:

  • Operating System: Debian GNU/Linux 13 (Trixie) x86_64
  • Kernel: Linux 6.12 (Debian amd64)
  • Hosting Provider: KVM/QEMU Hardware Virtualization Host
  • Security Posture: Ephemeral local execution with non-persisted application memory buffers.

Third-Party Utilities & External Integrations

To execute open-source footprint analysis, the operator utilizes specialized Command-Line Interface (CLI) reconnaissance utilities and third-party APIs. Data transmitted to these services is restricted solely to the public handle, domain, or email address undergoing audit.

Where third-party web domains or self-hosted web servers are submitted by a user for footprint verification, the user must insert a designated verification string into their website's robots.txt file to demonstrate administrative control prior to scanning.

Third-party platforms and utilities utilized during operations include, but are not limited to:

Discord API Bot interface & ticket delivery platform
X (formerly Twitter) Identity authentication verification
ProjectDiscovery Nuclei & dnsx network probes
Holehe Email endpoint verification
Maigret Public profile cross-referencing
h8mail Breach data exposure checking
GHunt Public account footprint auditing
Sherlock Social media username lookup

Your Legal Rights (UK GDPR)

Under the UK General Data Protection Regulation and the Data Protection Act 2018, you possess explicit rights regarding any personal data processed by the Service:

  • Right of Access: Request a copy of any personal data held about you prior to system purging.
  • Right to Erasure (Right to be Forgotten): Demand the immediate deletion of active ticket files prior to standard ticket closure.
  • Right to Rectification: Request correction of inaccurate findings prior to report compilation.
  • Right to Restrict Processing: Request the temporary suspension of processing activities.

To exercise any of these rights, contact developer@splashbot.online. Because our core system model relies on immediate ephemerality and file purging, most processing records are permanently erased as soon as a ticket is closed.

Jurisdiction & Governing Law

This Privacy Policy, its interpretation, and any disputes arising from or in connection with the operation of Splashbot Utilities shall be governed exclusively by the laws of England and Wales, under the regulatory framework of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. The courts of England shall have exclusive jurisdiction over any legal proceedings.