Skip to main content
FrontlinePrivacy

Trust

We pull your personal information off the data-broker market and keep checking that it stays off. We don't sell your data, share it, or use it for anything except running the removals you signed up for. We collect only what the job needs. Here is what that means in practice.

What we do and don't do with your data

We don't sell your data. We don't share it with advertisers or marketing partners. We don't repackage an "anonymized" or "aggregated" copy of it for any purpose beyond running your removals. If a security incident ever touches your data, we'll tell you promptly, even when the law doesn't require it.

Audits and attestations

We are a small team. We have not completed a formal SOC 2 or ISO 27001 audit yet. Those are independent security reviews that large vendors often carry. We'll pursue them when our customer base calls for it, and we'll list the auditor and date here once that's done. If your department or organization needs vendor approval before signing, we'll walk through our practices on a call.

Who we share data with to run the service

We use Google Cloud Platform to host the site and store your scan data. Delist (delist.ai) runs the scans and files the broker removals. Mailgun sends our transactional email. If you use the iOS app, Apple handles sign-in, subscription billing, and push notifications. That is the full list. No other vendors touch your data, and we don't use third-party analytics, tracking pixels, or session-replay tools.

Compliance

California's privacy law (the CCPA, as strengthened by the CPRA) lets residents tell a company to delete the personal data it holds about them. We honor those deletion requests, along with equivalent requests from residents of other states with similar laws. We are also working toward formal HIPAA compliance, the federal health-privacy standard, for healthcare-organization customers. If you're a hospital evaluating us, ask and we'll share where we stand. We don't claim certifications we don't have.