Legal

Privacy Policy

Last updated: September 26, 2026

Do you appear in a PeopleSearch.im search result and not a customer? You can request removal of your information, no account needed, honored immediately.

1. Who we are and what this covers

PeopleSearch.im ("we", "us") is a people-search service for professional (business-to-business) use: you describe the professionals you are looking for, and we return matching profiles, verified work email addresses and related company information. You can use it on our website, through our API, and through our MCP server from AI assistants such as Claude and ChatGPT. PeopleSearch.im is the controller of the personal information described here.

This policy covers two groups of people:

  • Customers and visitors: anyone who visits our website, creates an account, or uses our API or MCP server.
  • Professionals who appear in our results: people whose business profiles our customers can find.

You can reach us about anything in this policy by email at hello@peoplesearch.im.

2. Information about customers and visitors

Your account. Your name and email address, and your password, which our sign-in system stores only in hashed form. Each sign-in creates a session that records a session token and the IP address and browser it came from. A session lasts 7 days and is deleted within a day after it expires.

Credits and payments. Your credit balance and a ledger of the credits granted, bought, spent and refunded. Payments are handled on a Stripe-hosted checkout page. We send Stripe your account ID, email address and the credit pack you chose, and receive a payment reference back. We never see or store your card details.

What you do in the product. The searches you run (the text you type and the filters we understood), the profiles you unlock, which are saved to your contacts, and the email addresses you look up. For the other lookup tools (reverse email lookup, LinkedIn lookups, company lookups, email verification) we record the credit charge, not what you looked up or what came back.

API keys and connected apps. API keys are stored only as a one-way hash; we show a key once, when you create it. If you connect an AI assistant, see section 4.

Emails we send you. Account emails such as a welcome message and password resets. We keep a log of each one (recipient, subject and delivery status).

Messages you send us, such as support requests.

Visitors without an account. A random identifier in a cookie (sift_anon, kept up to 180 days) counts your free searches, and we store the searches you run under that identifier. Your IP address is used for a daily limit on free searches and is deleted 30 days later. We do not link these searches to your IP address or to your identity.

Analytics. We measure page views and a few product events with our own first-party, cookieless analytics. A visitor is counted with a hash of the IP address and browser mixed with a secret that changes every day and is then deleted, so a visitor cannot be recognized from one day to the next or traced back to an IP address. We never store the raw IP address or browser string for analytics, and we keep analytics events for 180 days. We use no third-party analytics, advertising or tracking scripts.

Referrals. If you arrive through a referral link, a cookie (ps_ref, up to 60 days) remembers who referred you so both accounts can receive the referral bonus.

Free tools. The email verifier and the MX, SPF and DMARC checkers look up the domain or address you enter in public DNS. We do not store what you check; like any web request, it can appear briefly in our hosting provider's request logs.

3. Information about professionals who appear in our results

Where it comes from. Our results come from Icypeas, a licensed business-to-business data provider that compiles professional information. We do not scrape websites ourselves.

What it is. Business information only: name, job title, headline and profile summary, current role and employer with details about that company, general location (such as the city), the professional profile URL (such as LinkedIn), and a work email address with its verification status when one can be found. We look for work addresses only, never personal ones, and we do not provide phone numbers, home addresses or information about family, health, finances or other sensitive matters.

How it is used. Searching shows masked previews. When a customer unlocks a person, we charge the customer a credit, show them the full profile, and save a copy to that customer's contacts. When a customer asks for a person's work email, we look it up live through Icypeas at that moment.

Why we are allowed to. We rely on legitimate interests: our customers' and our interest in professional networking, sales prospecting, recruiting and research, using business information only, with a simple and immediate way to opt out.

Removing yourself. Anyone can ask us to remove their profile at peoplesearch.im/opt-out, with no account needed. It takes effect immediately for everything from that moment on: your profile no longer appears in searches and can no longer be unlocked, looked up or have its email looked up through PeopleSearch.im, on our website, API or MCP server. A customer who unlocked your profile before your request keeps the copy they already received. We keep the removal request itself (the name, company and profile URL you gave us, plus your email address and message if you added them) so that we can keep honoring it. You can also contact us to ask what we hold about you or to exercise your other rights (section 9). Removal applies to PeopleSearch.im; to ask Icypeas about its own database, contact Icypeas directly.

4. AI assistant connections (MCP)

You can connect PeopleSearch.im to an AI assistant that supports the Model Context Protocol, such as Claude, ChatGPT or an AI coding tool. The assistant then calls our tools on your behalf, using your PeopleSearch.im account and credits.

  • What we receive: for each tool call, only the tool's name and the inputs the assistant sends, for example the search text, a name and company domain, or an email address to verify. We never receive your conversation, your chat history, the assistant's memory or your files, and we do not ask for them.
  • How we use it: exactly like the same action on our website. Searches are recorded in your account, profiles you unlock are saved to your contacts, and credits are charged and refunded under the same rules. We do not use tool inputs or results to train AI models or for advertising.
  • Connecting: you approve each connection on a PeopleSearch.im consent screen that shows which app is asking. Apps that identify themselves with a public metadata document (Claude and ChatGPT do) are verified by fetching that document when you connect.
  • Tokens: we store the access and refresh tokens issued to an app only as one-way hashes. An access token expires after 1 hour; a refresh token expires 90 days after it was last used.
  • Disconnecting: you can see and disconnect every connected app at any time under Connected apps on the Developers page. Disconnecting revokes the app's access immediately.

5. How we use information

We use the information above to:

  • provide the service: searches, profile unlocks, email lookups, credits, the API and the MCP server;
  • process payments and keep an accurate credit ledger;
  • keep the service secure and prevent abuse, for example with rate limits on free searches and on opt-out requests;
  • send account and service emails;
  • answer support requests;
  • understand, in aggregate, how the service is used so we can improve it;
  • comply with the law and enforce our Terms of Service.

We interpret plain-English searches with our own software. If we enable an AI model to help interpret search text, only the text of the search is sent to the model provider (Anthropic), never your account details.

We do not sell customer information, we do not show advertising, and we do not make decisions with legal or similarly significant effects about anyone based solely on automated processing.

6. Who we share information with

We share information only with the service providers that run PeopleSearch.im, each of which may use it only to provide its service to us:

  • Icypeas (business data provider): receives the search filters and lookup inputs needed to answer a request, such as a job title and location, a person's name and company domain, an email address or a profile URL.
  • Stripe (payments): receives your account ID, email address and the pack you are buying.
  • Vercel (website hosting) and Neon (database hosting).
  • Founden, the platform that PeopleSearch.im is built and operated on: it delivers our emails through its email provider and checks new sign-up addresses against a list of disposable email domains.
  • Anthropic, only if AI search interpretation is enabled, and only the search text (see section 5).

Professional profile information is disclosed to the customers who unlock it; that is the service we provide. We may also disclose information when the law requires it, to protect our rights or the safety of others, or as part of a merger, acquisition or sale of assets.

7. How long we keep information

  • Account, search history, contacts, credit ledger and email logs: for as long as your account is open. When you ask us to close your account, we delete or anonymize its data within 30 days. Stripe keeps its own record of each payment for as long as tax and accounting law requires.
  • Sign-in sessions: 7 days, deleted within a day after they expire.
  • AI assistant tokens: access tokens expire after 1 hour and refresh tokens 90 days after their last use; authorization codes expire after 10 minutes and work only once.
  • IP addresses used for rate limits: 30 days.
  • Analytics events: 180 days. The daily secret used for visitor counting is deleted after a day.
  • Searches run without an account: kept under a random identifier that is not linked to an IP address or identity.
  • Removal requests: kept for as long as we honor them.
  • Error logs: only the most recent 1,000 entries.
  • Hosting request logs: our hosting provider keeps short-lived logs of web requests, including IP addresses, for security and troubleshooting.

8. Security

All traffic to PeopleSearch.im is encrypted in transit (HTTPS). Passwords, API keys and AI assistant tokens are stored only as one-way hashes. Access to data is limited by database access rules, and the operator back office is restricted to our own operators. No system is perfectly secure, so please keep your password and API keys private and tell us promptly by email at hello@peoplesearch.im if you think your account has been misused.

9. Your rights

Depending on where you live, you can ask us to:

  • tell you whether we hold information about you and give you a copy;
  • correct information that is wrong;
  • delete your information, or close your account;
  • give you your information in a portable format;
  • restrict or object to how we use it, including use based on legitimate interests;
  • withdraw any consent you gave.

To use these rights, contact us by email at hello@peoplesearch.im. To close your account, write from the email address on the account. We may need to confirm your identity first, and we answer within one month (or within the time your local law sets). If you are in the European Economic Area or the United Kingdom, you can also complain to your data protection authority, although we would appreciate the chance to resolve your concern first.

California residents. You have the rights to know, access, correct and delete your personal information, and not to be treated differently for using them. We do not sell customer information or share it for cross-context behavioral advertising. If you are a professional who appears in our results, you can stop us from disclosing your information to customers at any time at peoplesearch.im/opt-out.

10. International transfers

Our service providers process information in the United States and the European Union, so your information may be handled outside the country where you live. Where the law requires it, we rely on appropriate safeguards for these transfers, such as the European Commission's standard contractual clauses.

11. Children

PeopleSearch.im is a professional tool for adults. It is not directed to children, and we do not knowingly collect information from children. If you believe a child has given us information, contact us and we will delete it.

12. Changes to this policy

When we change how we handle information, we update this policy and the date at the top of the page before the change takes effect. If a change is significant, we will also tell account holders by email.

13. Contact us

Questions, requests or concerns about privacy: contact PeopleSearch.im by email at hello@peoplesearch.im.

Privacy Policy | PeopleSearch.im