OrionEye v4.0 & facelive.net — Full GDPR / Datenschutz Compliance
Last updated: April 9, 2026 | Version 2.0 | Data Controller: Samuel La Manna
OrionEye v4.0 is a Cyber Intelligence, Geospatial Analysis and Space Technology platform accessible at https://facelive.net/orioneye/. It is developed and operated as a legitimate, non-commercial, educational and research-oriented service in full compliance with:
Data Controller (Titolare del trattamento / Verantwortlicher)
Name: Samuel La Manna
Role: Software Engineer & Intelligence Architect
Email: privacy@facelive.net
Website: https://facelive.net/orioneye/
Domain: facelive.net
This Privacy Policy applies to the entire facelive.net domain, including the OrionEye web application, landing pages, API endpoints, and all subpages. By using any part of the service, you acknowledge this policy.
OrionEye follows the principle of data minimization (Art. 5(1)(c) GDPR). We process only what is strictly necessary for service functionality.
| Data | When Collected | Purpose | Required? |
|---|---|---|---|
| Username | Account registration | Authentication, UI personalization | Yes (if registering) |
| Email address | Account registration | Authentication, account recovery | Yes (if registering) |
| Password (hashed) | Account registration | Authentication | Yes (if registering) |
| AI chat messages | When using Gemini AI panel | AI-assisted intelligence analysis | No — optional feature |
| Console commands | When using the command console | Executing platform functions | No — optional feature |
Note: Registration is optional. The vast majority of OrionEye features are accessible without any account, without submitting any personal data.
| Data | Source | Purpose | Retention |
|---|---|---|---|
| IP address | HTTP request | Security logs, abuse prevention | 30 days |
| Browser User-Agent | HTTP header | Compatibility, security analytics | 30 days |
| Device type / screen size | HTTP header / CSS media | Responsive design | Not stored |
| Referrer URL | HTTP header | Traffic source analysis | 30 days (in logs) |
| Timestamp of access | Server log | Audit trail, security | 30 days |
| Approximate geolocation | IP-based lookup (ip-api.com) | Map centering, local weather | Session only — not persisted |
| Page views / events | Google Analytics 4 (if consented) | Aggregate usage statistics | 14 months (anonymized) |
OrionEye does not upload, store, or process user-uploaded images, videos, or audio files. The platform displays:
No user-generated multimedia content is collected, processed, or retained.
Each category of data is processed for a specific, documented purpose with a corresponding legal basis.
| Purpose | Data Involved | Legal Basis | Consent? |
|---|---|---|---|
| User authentication | Username, email, hashed password | Art. 6(1)(b) — Contract performance | No (necessary) |
| Platform functionality | Console commands, map interactions, AI chat | Art. 6(1)(b) — Contract performance | No (core service) |
| Security & abuse prevention | IP, User-Agent, timestamps, access logs | Art. 6(1)(f) — Legitimate interest | No (overriding) |
| Infrastructure protection | Rate-limit counters, error logs | Art. 6(1)(f) — Legitimate interest | No |
| Traffic analytics | Anonymized page views (GA4) | Art. 6(1)(a) — Consent | Yes |
| Map centering / weather | IP-based approximate geolocation | Art. 6(1)(a) / Art. 6(1)(f) | Implicit |
| Language preference | Language code (EN/IT cookie) | Art. 6(1)(f) — Legitimate interest | No (essential) |
| OSINT data aggregation | Public API queries (no personal data) | Art. 6(1)(f) — Legitimate interest | No (public data) |
Legitimate Interest Assessment (LIA): For all processing based on Art. 6(1)(f), we have conducted a balancing test confirming that our legitimate interest (security, service delivery, OSINT research) does not override the data subject's rights. Full LIA documentation is available upon request at privacy@facelive.net.
We retain data only for as long as necessary to fulfil the purpose for which it was collected.
| Data Category | Retention Period | After Expiry | Criteria |
|---|---|---|---|
| Server access logs (IP, UA, timestamp) |
30 days | Automatically deleted (log rotation) | Industry-standard security period |
| User account data (username, email, hash) |
Until account deletion | Permanently erased within 30 days of request | User-controlled — Art. 17 |
| Google Analytics 4 data | 14 months | Auto-anonymized/deleted by Google | GA4 default retention; anonymized at collection |
| AI chat messages (Gemini) | Session only | Discarded on tab close | No server-side persistence — in-memory |
| Console command history | Browser session only | Cleared on tab close | Client-side only — never sent to server |
| Cached API responses (RSS, Charging, Facebook) |
5–15 minutes | Evicted from server memory | Performance cache — RAM only, zero disk |
| Language preference cookie | 1 year | Expires naturally | Standard UX preference duration |
| Authentication token (JWT) | 24 hours | Automatically invalidated | Short-lived for security |
No long-term personal data storage: OrionEye maintains no permanent database of user behavior, browsing history, search queries, or personal profiles. The longest retention period for identifiable data is 30 days (server logs).
OrionEye integrates public APIs for intelligence data. All backend queries are executed server-side, meaning your IP address and identity are never exposed to third-party API providers.
| Service | Data Sent | NOT Sent | Location | Privacy |
|---|---|---|---|---|
| Google Maps | Viewport coordinates | User IP, PII | US (DPF) | Link |
| Google Gemini AI | Chat text | User IP, name, email | US (DPF) | Link |
| Google Analytics 4 | Pseudonymized events | Real IP (masked) | US (DPF) | Link |
| OpenChargeMap | Country code | Any PII | UK/EU | Link |
| OpenSky Network | Bounding box | Any PII | EU (CH) | Link |
| ACLED | Region/date filters | Any PII | US/EU | Link |
| GDELT Project | Keyword queries | Any PII | US | Link |
| NASA EONET / GIBS | Event type queries | Any PII | US (gov) | Link |
| RIPE Atlas / RIPEstat | Public IP / ASN | User PII | EU (NL) | Link |
| Windy.com | Map coordinates | Any PII | EU (CZ) | Link |
| CelesTrak | Satellite catalog query | Any PII | US | N/A — public |
| Launch Library 2 | Launch schedule query | Any PII | US | Link |
| ip-api.com | User IP (server-side) | Name, email, account | EU | Link |
| NewsAPI.org | Keyword queries | Any PII | UK | Link |
Transfers to the US are covered by the EU-US Data Privacy Framework (DPF) — Commission Decision (EU) 2023/1795. Google LLC is a certified DPF participant. For all other APIs, no personal data is transmitted — only functional query parameters.
OrionEye never sells, rents, trades, or shares personal data with third parties for commercial, marketing, or advertising purposes. This is an absolute, unconditional commitment.
| Cookie | Type | Purpose | Duration | Consent? |
|---|---|---|---|---|
_ga | Analytics | GA4 — distinguishes users | 14 months | Yes |
_ga_* | Analytics | GA4 — session state | 14 months | Yes |
lang | Functional | Language preference (EN/IT) | 1 year | No (essential) |
gn_token | Auth | JWT session token (localStorage) | 24 hours | No (essential) |
OrionEye was architected from inception with privacy as a core principle:
| Right | Article | Description |
|---|---|---|
| Access | Art. 15 | Obtain a copy of all personal data we hold about you |
| Rectification | Art. 16 | Correct any inaccurate personal data |
| Erasure | Art. 17 | Request deletion ("right to be forgotten") |
| Restriction | Art. 18 | Limit processing of your data |
| Portability | Art. 20 | Receive data in structured, machine-readable format (JSON/CSV) |
| Objection | Art. 21 | Object to processing based on legitimate interest |
| Withdraw Consent | Art. 7(3) | Withdraw consent at any time without affecting prior processing |
To exercise any right: privacy@facelive.net. Response within 30 days (Art. 12(3)). Free of charge unless manifestly unfounded.
Email privacy@facelive.net to delete your account. Within 30 days: username, email, and password hash are permanently erased. Tokens are immediately invalidated. No backups with your data are kept.
Clear statement: OrionEye does NOT collect, process, store, or analyze biometric data in any form.
OrionEye displays publicly available traffic camera feeds operated by government transportation agencies. These streams are:
The Facebook OSINT module uses the public Facebook Graph API to search for public pages. It:
Should OrionEye ever introduce any biometric processing feature in the future (which is not planned):
OrionEye is designed for professional, educational, and research use. It is not directed at children under 16 (or under 13 where that threshold applies). We do not knowingly collect data from minors. If you believe a child has provided personal data, contact privacy@facelive.net for immediate removal.
As Data Controller, Samuel La Manna commits to:
Request via: privacy@facelive.net
We may update this policy to reflect changes in practices, features, or legal requirements. The "Last updated" date and version number at the top indicate the latest revision. For significant changes, we will provide prominent notice. Continued use after changes constitutes acceptance.
Version history:
For any privacy-related requests, questions, data subject rights, or complaints:
Data Controller: Samuel La Manna
Email: privacy@facelive.net
Website: https://facelive.net/orioneye/
Response time: Within 30 days (Art. 12(3) GDPR)
Languages: English, Italian, Deutsch
No. OrionEye non effettua alcuna forma di riconoscimento facciale, face detection o analisi biometrica. Nessuna foto degli utenti viene raccolta, elaborata o conservata.
No. La piattaforma non genera, modifica o manipola immagini, video o audio. Mostra solo dati reali e pubblicamente disponibili.
No. Le funzionalità principali sono accessibili senza registrazione. La creazione dell'account è opzionale.
Username, email e hash della password vengono eliminati permanentemente entro 30 giorni. I token di autenticazione sono invalidati immediatamente. Nessun backup con i tuoi dati viene conservato.
No. Non usiamo cross-site tracking, fingerprinting, retargeting o tracker pubblicitari. Google Analytics (opzionale, previa consenso) traccia solo visite anonimizzate su OrionEye.
No. Tutte le chiamate API esterne vengono effettuate dal nostro server (proxy server-side). Il tuo IP non viene mai trasmesso ai provider di API terze.
OrionEye è ospitato su infrastruttura europea conforme al GDPR.
Assolutamente no. Non abbiamo mai venduto e non venderemo mai dati personali. OrionEye è una piattaforma gratuita, non commerciale, per la ricerca e l'educazione.
OSINT (Open-Source Intelligence) è la raccolta e analisi di dati pubblicamente disponibili da fonti aperte. È pienamente legale ai sensi del diritto UE, basata sul legittimo interesse all'accesso alle informazioni pubbliche (Art. 6(1)(f) GDPR), e ampiamente utilizzata da giornalisti, ricercatori, forze dell'ordine e professionisti della sicurezza.
Sì. Ai sensi dell'Art. 15 GDPR, hai il diritto di richiedere una copia di tutti i dati personali che conserviamo su di te. Scrivi a privacy@facelive.net e risponderemo entro 30 giorni.
Cancella i cookie del browser per facelive.net oppure usa le impostazioni di gestione cookie del tuo browser. Gli script analytics non si ricaricheranno senza il tuo consenso esplicito.
No. La funzionalità Facebook OSINT utilizza solo l'API pubblica ufficiale di Facebook e restituisce esclusivamente informazioni accessibili pubblicamente. Non accede a profili privati, messaggi o contenuti riservati.
© 2026 OrionEye v4.0 — Created by Samuel La Manna. All rights reserved.
Terms of Service ·
Versione Semplice ·
Mobile Version