LONG GLASS
Privacy policy

LONG GLASS — Privacy Policy

Effective: [[DATE]] Last updated: 25 August 2026


1. Who we are

LONG GLASS is operated by [[LEGAL ENTITY NAME]] ("we", "us"), the data controller for the information described in this policy.

If you are in the EU or UK and believe we have handled your information improperly, you may complain to your national supervisory authority. We would rather you came to us first.


2. What LONG GLASS is

LONG GLASS is a private, invite-only research bench for open-source intelligence work. It is not a consumer service and it is not open to public registration. An account exists only where an administrator has issued a single-use invite.

The bench queries publicly available and commercially licensed sources, and records the results so an analyst can work with them.


3. This policy covers two different groups of people

Most privacy policies describe only the people who signed up. Because of what LONG GLASS does, this one has to cover two groups:

Sections 4 and 5 deal with each in turn. Section 10 explains what rights each group has, and where those rights are limited.


4. Information about analysts

What we holdWhyHow long
Username, display name, roleIdentify you, apply permissionsLife of the account
PasswordSign-inStored only as a scrypt hash; never in plaintext
Two-factor secret, recovery-code hashesProtect the accountLife of the account; codes are single-use
Session records — IP address, browser user-agent, timestampsKeep you signed in, spot session theftExpire after 12 hours, or 4 hours idle; deleted on expiry or sign-out
Sign-in attempts — username, IP, success/failureRate-limiting and lockout30 days, then deleted
Invite recordsTrack who was invited by whomUnused invites expire after 14 days
Audit log — who ran which query, in which module, against which selector, from which IP, and the resultAccountability. This is a deliberate control: the bench records what it was used for.Retained indefinitely and append-only. See section 10.

We do not collect analytics about how you use the bench, we do not profile you, and we do not sell or share any of this with anyone.


5. Information about subjects

When an analyst runs a query, the bench collects whatever the queried sources return about the person or entity named. Depending on the module and the source, that can include:

Two of those categories deserve to be called out plainly. Criminal-offence data is subject to additional restrictions under Article 10 UK/EU GDPR, and breach data concerns information that was disclosed without the subject's consent in the first place. Both are handled under section 9.

Source. We do not obtain this information from the subject. It comes from public records, publicly accessible websites, and third-party data providers (section 6).

Retention. Query results and case records are held until the analyst who owns them deletes them. When an analyst's account is deleted, their case records are not destroyed with it — they become administrator-only until reassigned, because silently destroying investigative records is not a decision an account deletion should make. Audit-log entries referencing a query persist regardless.


6. Where information goes

The bench sends query terms to third-party sources in order to retrieve results. It transmits only what is needed to run the query — typically the selector the analyst entered. Those providers operate under their own privacy policies and will generally log the request.

Roughly 160 distinct upstream sources are reachable across the bench. The ones that receive personal data about a subject fall into these groups:

GroupExamples
Identity and people-search providersPeople Data Labs, Endato, ThatsThem, TruePeopleSearch, Whitepages, Influencers.club
Breach and credential-exposure dataHave I Been Pwned, DeHashed, LeakCheck, XposedOrNot, Hudson Rock, IntelX, ProxyNova
Reverse-image and face searchTinEye, FaceCheck.ID, PimEyes, Lenso, Google Lens, Yandex, Baidu
Search-engine accessSerper, SerpAPI, Brave Search, DuckDuckGo, Bing, Mojeek, Marginalia
Social and messaging platformsLinkedIn, Facebook, TikTok, Reddit, Bluesky, Mastodon, Telegram (t.me, TGStat, Telemetr), Keybase, Gravatar, Linktree
Courts, corrections and sanctionsCourtListener, Federal Bureau of Prisons, FBI, NSOPW, state court systems (AL, CT, OK, TX, WI), OpenSanctions, UN, OFAC/OFSI
Regulatory and financial disclosureSEC EDGAR, FEC, GLEIF, ProPublica, ICIJ Offshore Leaks
Indicator and infrastructure reputationVirusTotal, urlscan.io, GreyNoise, GitHub, DNS resolvers
Web archivesInternet Archive Wayback Machine

One disclosure deserves its own paragraph. The reverse-image search feature in Glass Eye works by uploading the supplied image to litterbox.catbox.moe, a third-party temporary file host, so that image-search engines can fetch it by URL. The image is placed on a public host with a self-expiring link. Do not use that feature with an image you are not willing to have leave our infrastructure.

The remaining upstream sources — market data, mapping and geospatial layers, weather and seismic feeds, aircraft and vessel tracking, blockchain nodes, malware feeds and news — receive no personal data about subjects.

International transfers. Most of these providers are in the United States. [[CONFIRM TRANSFER MECHANISM — SCCs / UK IDTA / adequacy, per provider.]]


7. Cookies

LONG GLASS sets two cookies, both strictly necessary:

There are no analytics cookies, no advertising cookies, and no third-party tracking. Every stylesheet, font and script the bench serves is hosted by us; no page loads assets from a content-delivery network or any other external origin, so browsing the bench does not disclose your IP address to a third party.


8. Legal bases (UK/EU GDPR)

For analysts: performance of a contract (providing your account), our legitimate interests in securing the service (sign-in logging, rate limiting, audit), and legal obligation where one applies.

For subjects: our legitimate interests, and those of our clients, in conducting lawful investigation, due diligence, fraud prevention and security research — balanced against the subject's rights and freedoms. Criminal-offence data is processed only where a lawful condition under Article 10 and applicable national law is met. [[CONFIRM THE ARTICLE 10 CONDITION FOR YOUR JURISDICTION AND USE CASE WITH COUNSEL.]]

Notice to subjects. Article 14 normally requires that we tell a person when we obtain their data from somewhere other than them. We rely on the exemptions in Article 14(5) — that direct notice would be impossible or involve disproportionate effort, and that notice would defeat the purpose of a legitimate investigation — and we publish this policy in their place. This is a deliberate position, not an oversight. [[REVIEW WITH COUNSEL; document the balancing test.]]


9. What LONG GLASS must not be used for

Analysts agree, as a condition of holding an account, that they will not use the bench or anything it produces:

These prohibitions are enforced by contract and recorded against each query in the audit log. Breaching them ends the account.


10. Your rights

If you are an analyst, you may ask us to access, correct, export or delete your account information, or to restrict or object to processing.

If you are a subject, you have the same rights in respect of information we hold about you, subject to the limits below. Contact us at the address in section 1. We will ask for enough information to be confident of your identity, and we will respond within one month.

Three honest limits:

  1. We will not erase the audit log. It is append-only evidence of what the bench was used for, and an account being deleted is exactly when its history matters most. This is a retention we consider necessary for accountability and the establishment or defence of legal claims.
  2. Deleting an analyst account does not delete their casework. Those records become administrator-only. If you are a subject and ask us to erase information about you, that request reaches the case records themselves.
  3. A right to erasure may be restricted where processing is necessary for the establishment, exercise or defence of legal claims, or where an investigation is ongoing and disclosure would prejudice it.

If you are a California resident, you may also request disclosure of the categories of personal information collected and the categories of third parties it was disclosed to, and you may request deletion, subject to the same limits. We do not sell personal information and we do not share it for cross-context behavioural advertising.


11. Security

Access requires a password and, where enabled, a second factor. Sessions are short. Records are owned per-analyst and access is denied by default rather than granted by default. Every query is logged with the account that ran it. Our security posture is documented in the repository's SECURITY.md and enforced by an automated test suite that fails the build when a control is missing.

No system is perfect. If you find a vulnerability, tell us at the address in section 1 and we will not pursue you for reporting it in good faith.


12. Changes

We will update the "last updated" date above when this policy changes. Where a change materially affects how we handle your information, we will tell account holders directly.


13. Contact

[[LEGAL ENTITY NAME]] [[BUSINESS ADDRESS]] [[privacy@longglass.xyz]]

You are reading this on a private, invite-only service. Sign in if you hold an account.