Skip to main content
FrontlinePrivacy

Security

You give us your name, address, phone, and email so we can find your listings on data broker sites and file to get them taken down. The fewer hands those fields touch, the better — for you and for the family that shares your address. Here's how we handle them.

Data at rest

Your data lives in a managed Postgres database on Google Cloud SQL. Cloud SQL encrypts stored data by default with AES-256, and Google manages and rotates the keys. Backups are encrypted the same way.

Data in transit

Every connection to the site runs over HTTPS with current TLS, so your data is encrypted between your device and us. Broker opt-out submissions go out over HTTPS. Verification emails route through a managed provider secured with TLS.

Access control

We keep internal access to your data on a need-to-know basis. Staff who file opt-out requests work from the fields those filings need, not your full record. Database access is limited to the engineers who run the service.

Retention

We keep your data only as long as we need it to run the service for you, plus a short window afterward in case of a dispute or reactivation. After that it is deleted from our primary systems, and from backups as they cycle out. You can ask us to delete your data at any time. See our privacy policy for the current retention details.

What we don't collect

We don't ask for your Social Security number, date of birth, driver's license number, or medical information. We don't take bank or credit card details on the website — it never handles payments. Broker opt-outs don't require any of it. Your name, address, phone, and email are enough.

Reporting a vulnerability

Report security problems to security@frontlineprivacy.com. We aim to acknowledge reports quickly, weekends included. We don't run a paid bug bounty, but we will credit researchers who report responsibly.