Legal
OMNIntel is a public link-safety scanner for URLs, QR codes and email links. This page explains what data we collect and, importantly, that the links you scan are logged and shown publicly.
OMNIntel is a public safety tool. When you scan a URL, the result is saved and published to a public scan page at /scan/{domain}. These pages are indexable by search engines and can be viewed by anyone with the link.
Scanned domains and their scores also appear in the public "Recently Scanned" feed on the homepage and in the global Threat Intel statistics.
For every scan we store: the submitted URL and domain, the scan status and overall score, detected threats, SSL/TLS certificate details, HTTP security headers, hosting location and network footprint (country and resolving IPs), on-page risk findings, category and verdict, and the time of the scan. Some scans also cache a short plain-English summary of the result.
We do not require an account to scan, and we do not ask for personal information to use the scanner.
OMNIntel can also pull links out of a QR-code image or a pasted email. When you upload a QR image or paste email text, we process it only to extract the web links inside — the image and the pasted text are used in memory for that request and are not stored on our servers.
Only the specific links you then choose to scan are logged and published like any other scan, so the same "scans are public" rules apply. Don't scan links that contain private tokens or personal information.
Because standard scans are public, you should not submit URLs that contain private tokens, session identifiers, password-reset links, unlisted document links, or any other information you would not want visible to others.
If you need to check a link privately, OMNIntel Pro offers Private Scans (see below). If a public scan page contains information that should be removed, contact us and we will review the request.
Two features are part of the paid OMNIntel Pro plan (£3.49/month): DMARC monitoring (analysing the aggregate email-authentication reports your domain's providers send to your OMNIntel reporting address) and Private Scans.
Private Scans are never made public. A scan you mark as private is visible only to your account — it is NOT added to the public "Recently Scanned" feed, it does NOT appear on the public /scan/{domain} pages, and it is excluded from the global Threat Intel statistics. It is stored solely so you can review it in your own dashboard.
For DMARC monitoring we store the aggregate reports sent to your reporting address (sending sources, IPs, pass/fail counts and policy) so we can render your dashboard and, if you enable it, email you spoofing alerts and a weekly digest. You can turn alerts and the weekly digest off at any time in your DMARC settings.
We use privacy-focused product analytics (PostHog) in a cookieless mode by default — no analytics cookies and no browser storage are used unless you explicitly opt in from the footer. Until then, analytics data is kept only in memory for the current page and is not persisted on your device.
If you opt in to analytics cookies from the footer toggle, PostHog stores a pseudonymous identifier so we can see aggregate usage; you can switch it back off at any time and we'll clear it.
Your light/dark theme preference is stored locally in your browser and is never sent to our servers.
If you create an API key, we store a hashed version of the key along with the email you provide and any webhook URL you configure. We use this to authenticate requests, enforce rate limits, and deliver webhook notifications.
For privacy questions, data removal requests, or any concerns about a published scan, reach us through our contact page. We aim to respond promptly.