The ethics and the line you don’t cross
Everything described in how OSINT techniques work is technically legal to look up in most places, most of the time, in isolation. That is exactly why the ethics matter more here than in fields where the bright line is "did you break in." With OSINT, the bright line is mostly about what you do with what you find, and who you do it to.
Consent is the starting question
The single most useful question to ask before running any OSINT technique on another person is whether they would reasonably expect you to be doing it. Looking up a business you are about to sign a contract with, or checking a seller's public reviews before a purchase, sits comfortably inside normal expectations. Building a profile of a specific private individual — an ex-partner, a coworker, someone you met once — without their knowledge, in order to track, contact, or influence them, does not, even though every individual step might use a source that is technically public.
Research versus stalking and harassment
The difference between legitimate research and stalking or harassment is rarely about which tool was used — it is about the target, the purpose, and the pattern. Verifying a claim, checking a company's history, or auditing your own exposure are purpose-limited and aimed either at organisations or at yourself. Repeatedly gathering information about one private individual, especially when it is used to locate, contact, intimidate, or expose them against their wishes, is the pattern that turns research into harassment regardless of how the information was obtained. If you find yourself building a file on a specific person without a clear, defensible reason they would accept, that is the signal to stop.
The tools are dual-use — on purpose
Nearly every technique and tool this site describes has a legitimate defensive or research use and a harmful one, using the exact same capability. A username-pivoting tool that helps you see your own scattered accounts is the same tool that lets someone else map a stranger's identity across platforms. A metadata viewer that helps a journalist verify a photo's origin is the same one that can pull a location out of a photo someone posted without realising it was attached. This site marks tools as dual-use where that applies, but the marking is a caution, not a guarantee — the same is true of any tool that is not marked, and the responsibility for how a tool is used sits with the person using it, not the tool itself.
The law depends on where you are
Laws that touch OSINT activity generally fall into a few broad areas: rules against unauthorised access to computer systems, rules against stalking and harassment, and data protection or privacy laws that govern how personal information can be collected, stored, and used. All three exist in some form in most jurisdictions, but the specifics — what counts as unauthorised access, what counts as a pattern of harassment, what counts as personal data and what obligations attach to handling it — vary significantly by country and even by region within a country, and they change over time as new legislation and case law are decided.
This site does not attempt to summarise those specifics, because a general summary written for a global audience would be wrong somewhere. If you are planning to use OSINT techniques for anything beyond looking at your own footprint, check the current law that applies in your own jurisdiction and the target's, ideally with a qualified local source, rather than relying on a general guide.
A simple default
When in doubt, point the technique at yourself first. That is both the safest way to learn it and the most directly useful — it shows you exactly what an outside observer could piece together about you, without raising any of the consent or legal questions above. The next guide, getting started responsibly, walks through how to do that.